-
Microsoft has expanded its incentives for security researchers focusing on Dynamics 365 and Power Platform, offering rewards ranging from $1,250 to $60,000 for qualifying vulnerabilities. The program prioritizes flaws that have a direct and demonstrabl…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Threat actors are impersonating corporate IT helpdesk staff in an active social-engineering campaign that hijacks Microsoft 365 identities, establishes MFA persistence, and systematically collects data from SharePoint, OneDrive, and Exchange Online. Mi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft disclosed CVE-2026-69449, an Important-severity vulnerability in Windows BitLocker. This issue is classified as a heap-based buffer overflow (CWE-122) and may allow remote code execution (RCE). Microsoft released details about this vulnerabil…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A human-operated intrusion campaign in which attackers abuse Microsoft Teams external collaboration to impersonate internal IT or helpdesk staff, persuade employees to grant remote control of their PCs, and then move toward critical enterprise infrastr…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Cybercriminals are using a rebranded Evilginx2 phishing-as-a-service platform dubbed BigBear 2.0 to intercept authenticated Microsoft 365 sessions, allowing them to take over accounts even after victims complete multi-factor authentication (MFA). Cloud…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Switzerland’s Federal Chancellery is advancing a sovereign digital workplace initiative following a feasibility study that demonstrated how open-source collaboration and office software can effectively support essential workflows within the federal adm…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft is developing a new security feature for Teams messaging that will obscure QR codes sent by external users. This measure aims to help organizations reduce phishing and fraud risks associated with malicious QR code campaigns. Listed under Micr…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A Microsoft 365 email security-control bypass that lets attackers submit unauthenticated messages posing as internal users by leaving one SMTP field blank. The technique targets Exchange Online’s RejectDirectSend setting and does not represent a vulner…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026. This change aims to strengthen defenses against kernel-level attacks by ensuring that only trusted ke…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
TerminalFix uses fake Cloudflare CAPTCHA pages to trick users into running PowerShell malware, creating reverse tunnels that provide access to internal systems.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


