Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Microsoft

20 articles

CISA Advisories advisories Microsoft SonicWall Jul 14

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

4 IOCs

CISA Advisories → Details

WeLiveSecurity research Microsoft Jul 14

Forgotten UEFI shims undermining Secure Boot

ESET researchers discovered 11 vulnerable UEFI shim bootloaders signed by Microsoft that allow attackers to bypass UEFI Secure Boot by exploiting decade-old ...

WeLiveSecurity → Details

CrowdStrike Blog vendor Microsoft Jul 14

July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days

CrowdStrike Blog → Details

Microsoft Security Blog vendor Microsoft Intel Jul 13

Defending SaaS-based applications against ShinyHunters OAuth abuse

Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (v...

T1566

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft Jul 13

Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID

Microsoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare.

Microsoft Security Blog → Details

Proofpoint Blog vendor Microsoft Jul 13

Hackers find a new trick to collect Microsoft Entra user data without raising red flags

Proofpoint Blog → Details

Infosecurity Magazine general Microsoft Jul 13

Novel OAuth Client ID Spoofing Technique Targets Cloud Environments

New research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments

Infosecurity Magazine → Details

Microsoft Security Blog vendor Microsoft Jul 10

Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative

Microsoft’s latest Secure Future Initiative report outlines progress on secure foundations, AI-powered defense, and future-ready cybersecurity. The post Secu...

Microsoft Security Blog → Details

Infosecurity Magazine general Microsoft Jul 10

Microsoft Warns New 'GigaWiper' Malware Combines Espionage and Destructive Capabilities

A new multi-purpose backdoor allows cyber threat actors to conduct both quiet espionage activity and destructive wiping operations

Infosecurity Magazine → Details

Cloudflare Blog vendor Microsoft Google Amazon Oracle Jul 10

Improving Smart Tiered Cache for Public Cloud Regions

Smart Tiered Cache allows for precise upper tier selection for origins hosted on AWS, GCP, Azure, and Oracle Cloud with customer-provided cloud region hints.

Cloudflare Blog → Details

Infosecurity Magazine general Microsoft Jul 10

Microsoft Warns of Increase in Number of Security Updates

Microsoft has said the volume of Windows security updates is set to grow as it uses AI to find new bugs

Infosecurity Magazine → Details

Microsoft Security Blog vendor Microsoft Jul 9

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

GigaWiper, also tracked as BLUERABBIT, is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational pla...

Microsoft Security Blog → Details

Infosecurity Magazine general Microsoft Jul 7

UK Government Launches Cyber Resilience Pledge, Claiming 60+ Signatories

More than 60 organizations, including M&S, Microsoft UK and Vodafone, have signed the UK government's Cyber Resilience Pledge, a new initiative aimed at boos...

Infosecurity Magazine → Details

Kaspersky Securelist research Microsoft Jul 6

When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website

The OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers.

T1566

Kaspersky Securelist → Details

Exploit Database advisories Microsoft Jul 6

[local] Windows Defender (MsMpEng.exe) - Race Condition

Windows Defender (MsMpEng.

Exploit Database → Details

Rapid7 Blog vendor Microsoft Rapid7 Jul 3

Weekly Metasploit Update: Modules for SMB-to-Meterpreter, Peyara Remote Mouse RCE exploit, and more

It's Time to Upgrade Your SMB Session This week, Metasploit contributor Dean Welch has added an SMB to Meterpreter session upgrade module. It uses PsExec to ...

T1190 T1021

Rapid7 Blog → Details

Unit 42 research Microsoft Jul 2

How We Added WebAuthn to a Browser-Based RDP Client

A look inside the reverse-engineering journey of building the first RDP client outside of Windows to support WebAuthn redirection. The post How We Added WebA...

Unit 42 → Details

Infosecurity Magazine general Microsoft Jul 1

Microsoft Accelerates Quantum-Safe Push with New Timeline

Microsoft has brought forward its timelines for transitioning to post-quantum cryptography (PQC)

Infosecurity Magazine → Details

Infosecurity Magazine general Microsoft Apple Jun 30

ClickFix Now Cybercriminals' Favorite Malware Delivery Technique

ReliaQuest report warns of a surge in ClickFix social engineering attacks against Windows and macOS users

T1204

Infosecurity Magazine → Details

Infosecurity Magazine general Microsoft Jun 23

Lookalike npm Package Hides a Multi-Stage Windows RAT

JFrog found an npm package impersonating postcss-selector-parser to drop a multi-stage Windows RAT

Infosecurity Magazine → Details

«Previous page 1 ... 40 41 42 43 44 ... 46 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA