Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Microsoft

20 articles

SecurityWeek general Microsoft Sep 14

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely. The post Chinese Hackers Exploit Critical Tencen...

SecurityWeek → Details

Schneier on Security general Microsoft Google Sep 14

Microsoft’s Patching

Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record: Microsoft’s patch for September is a doozy, with a record ...

Schneier on Security → Details

BleepingComputer general Microsoft Sep 14

Microsoft: September updates cause RDS failures on Windows Server

Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems. [.

BleepingComputer → Details

GBHackers general Microsoft Sep 14

China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor

China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencent’s Sogou Input Method for Win...

T1190 1 IOC

GBHackers → Details

BleepingComputer general Microsoft Sep 14

Microsoft: September updates break audio on some Windows PCs

Microsoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates. [.

BleepingComputer → Details

GBHackers general Microsoft Sep 14

AsyncRAT Malware Abuses AutoIt and PowerShell to Hide Inside Legitimate Windows Process

A five-stage AsyncRAT campaign that chains a socially engineered batch file, hidden PowerShell execution, AutoIt abuse and process injection to conceal a .NE...

GBHackers → Details

Help Net Security general Microsoft Sep 14

Certificate failures can cost firms over $250,000

The move toward 47-day public TLS certificates by 2029 will increase the certificate management workload for enterprises, according to DigiCert’s Certificate...

Help Net Security → Details

BleepingComputer general Microsoft Sep 13

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows ...

1 IOC

BleepingComputer → Details

The Hacker News general Microsoft Sep 13

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam m...

T1566 T1204 T1041

The Hacker News → Details

SecurityWeek general Microsoft Google Sep 12

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Wi...

T1588

SecurityWeek → Details

GBHackers general Microsoft Google Linux Sep 12

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns ta...

T1566 T1068

GBHackers → Details

GBHackers general Microsoft Intel Sep 12

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files, conduct system re...

T1566 T1592

GBHackers → Details

The Record general Microsoft Sep 11

Microsoft sees some new wrinkles in invoice-scam emails

Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, includi...

The Record → Details

BleepingComputer general Microsoft Sep 11

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks ...

T1566 T1204 T1041

BleepingComputer → Details

CSO Online enterprise Microsoft Sep 11

Update your firewall rules: Teams and Copilot are changing address

Microsoft is changing the destination address of two of its most popular services: starting this month, it will redirect M365 and Teams web users to copilot....

CSO Online → Details

CSO Online enterprise Microsoft Cloudflare Sep 11

India’s STPI serves TerminalFix-style attack via fake Cloudflare check

A website linked to India’s Software Technology Parks of India (STPI) is serving a spoofed Cloudflare verification page that silently copies a malicious stri...

CSO Online → Details

Infosecurity Magazine general Microsoft Sep 11

Hackers Favor US Eastern Business Hours in M365 Phishing Campaign

KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emails

T1566

Infosecurity Magazine → Details

CSO Online enterprise Microsoft Sep 11

Attackers use passkey-themed scams to hijack Microsoft 365 accounts

Attackers are using passkey-themed social engineering to trick employees into giving them access to their Microsoft accounts. Microsoft Security Research sai...

T1566 T1204 T1557

CSO Online → Details

BleepingComputer general Microsoft Sep 11

Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs

Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 202...

BleepingComputer → Details

Infosecurity Magazine general Microsoft Sep 11

Most Organizations Skip Permissions Reviews Before Deploying AI Tools

A new Syskit study has shown that only 43% of organizations with AI agents deployed in Microsoft 365 environments completed a permission review before doing so

Infosecurity Magazine → Details

«Previous page 1 ... 5 6 7 8 9 ... 45 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA