vulnerability 421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked one Microsoft released a Patch Tuesday update containing 421 bugs, and a group known as ‘The Norks’ has already exploited one of these vulnerabilities to launch an attack. This highlights a continuing issue with Microsoft’s… The Register · Aug 11, 2026 High CVE-2026-68820CVE-2026-62832CVE-2026-62893microsoftpatch tuesdayvulnerability
threat-intel Attacker phished way into US defense supplier's Microsoft 365 account A US defense supplier's Microsoft 365 account was compromised after an attacker successfully phished credentials. The attacker exploited a vulnerability to gain access, highlighting a continuing issue with phishing attac… The Register · Aug 7, 2026 Medium phishingmicrosoftcredential theft
threat-intel Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk Kali365 is leveraging a sophisticated phishing kit to compromise US organizations by abusing legitimate Microsoft authentication flows. The kit uses attacker-controlled device codes to trick users into approving access o… The Hacker News · Aug 5, 2026 High USphishingauthenticationmicrosoft
threat-intel PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web The Police National Legal Database (PNLD) in the UK has confirmed that contact information, including names, email addresses, and organizations, belonging to police officers, government partners, and customers was expose… The Hacker News · Aug 3, 2026 High data breachpower appsdark web
vulnerability Multiples vulnérabilités dans Microsoft Edge (03 août 2026) Multiple vulnerabilities have been discovered in Microsoft Edge. Some of these allow an attacker to cause arbitrary code execution, data confidentiality breaches, and data integrity issues. These vulnerabilities are part… CERT-FR · Aug 3, 2026 High CVE-2026-17650CVE-2026-17651CVE-2026-17652vulnerabilitysecuritymicrosoft
vulnerability Vulnérabilité dans Microsoft Office (03 août 2026) A remote code execution vulnerability has been identified in Microsoft Office, allowing attackers to execute arbitrary code. This affects various versions of Office 365, Excel, and Office LTSC, requiring immediate patchi… CERT-FR · Aug 3, 2026 High CVE-2026-62870remotecodeexecution
threat-intel Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware A sophisticated campaign, dubbed CaptiveCrunch, is leveraging hijacked hotel Wi-Fi networks to deliver surveillance malware – specifically CornFlake, a remote access trojan – to unsuspecting guests. The attacks are orche… The Hacker News · Aug 1, 2026 High USUKcaptive portaldns redirectionremote access trojan
vulnerability Critical Flaw Led to Azure Cosmos DB Pwnage A critical vulnerability, dubbed CosmosEscape, in Azure Cosmos DB allowed attackers to obtain a platform-wide key, enabling them to compromise all databases on the service. Wiz researchers exploited this flaw by bypassin… SecurityWeek · Jul 31, 2026 Critical vulnerabilitycode executiondatabase
threat-intel Word worm crawls into Copilot, spreads chaos A group of Russian hackers are impersonating Signal support to launch phishing attacks, targeting users with links to malicious websites. Simultaneously, a zero-day vulnerability in on-prem SharePoint is being exploited,… The Register · Jul 29, 2026 High RUIRphishingzero-daysharepoint
vulnerability Multiples vulnérabilités dans Microsoft Edge (29 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially allowing an attacker to cause data integrity issues and a security problem not specified by the vendor. These vulnerabilities are part of a lar… CERT-FR · Jul 29, 2026 High CVE-2026-62828CVE-2026-13282CVE-2026-13283vulnerabilitysecuritymicrosoft
vulnerability Microsoft's solution to AI security: more AI and more acronyms Microsoft is facing a zero-day vulnerability in its on-prem SharePoint system, allowing attackers to exploit the flaw. This follows a broader trend of security challenges related to Microsoft products and a wider increas… The Register · Jul 27, 2026 High USIRSWvulnerabilitysharepointzero-day
vulnerability Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update A recent update to Microsoft Defender for Endpoint introduced a vulnerability that left some Linux systems exposed to attack. The flaw stems from a misconfigured feature within the endpoint protection software, allowing… The Register · Jul 27, 2026 Medium linuxendpoint securityvulnerability
vulnerability Multiples vulnérabilités dans Microsoft Edge (27 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially allowing attackers to compromise data confidentiality and bypass security policies. These vulnerabilities are detailed in a series of security… CERT-FR · Jul 27, 2026 Medium CVE-2026-57978CVE-2026-57989CVE-2026-57990vulnerabilitymicrosoftedge
vulnerability Default Azure Automation Setting Enables Cross-Tenant Identity Takeover A critical vulnerability in Microsoft's Azure Automation service, stemming from a default public configuration for automation account identities, could have allowed attackers to take over another tenant's identity and ac… Dark Reading · Jul 24, 2026 Critical CVE-2025-29827identitycloudautomation
threat-intel AI Hack : une fuite chez Darsa AI ? A French security news outlet, ZATAZ, has reported a potential data breach at Darsa AI, a company specializing in AI security solutions. A hacker claims to have stolen 90-100GB of data, including source code, databases,… ZATAZ · Jul 24, 2026 High data breachaimicrosoft
vulnerability Multiples vulnérabilités dans Microsoft Edge (24 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, impacting versions prior to 150.0.4078.96. The exact nature of the vulnerabilities and the resulting security issue are not specified by the publisher. Use… CERT-FR · Jul 24, 2026 Medium CVE-2026-16413CVE-2026-16414CVE-2026-16415vulnerabilitypatchsecurity
vulnerability Flaws in Passkey Implementation Show Old Attacks Still Work Researchers at SpecterOps discovered several exploitable flaws in Microsoft's passkey implementation, particularly within Microsoft Entra ID, that could allow attackers to impersonate privileged users and bypass MFA. Des… Dark Reading · Jul 22, 2026 High CVE-2026-34348passkeyswebauthnmicrosoft
threat-intel Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents A vulnerability in Microsoft Azure DevOps's MCP server allows attackers to hijack AI coding agents by inserting hidden HTML comments in pull requests. These comments can then instruct the agent to perform actions – like… The Hacker News · Jul 22, 2026 High prompt-injectionai-riskmicrosoft
threat-intel New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery Kaspersky researchers have uncovered a sophisticated new module, Project CAV3RN, leveraging Outlook calendar events accessed through Microsoft Graph for C2 communication and DNS AAAA records to recover configuration data… Securelist · Jul 21, 2026 High ISc2microsoftdns
vulnerability Multiples vulnérabilités dans Microsoft Edge (20 juillet 2026) Multiple vulnerabilities have been discovered in Microsoft Edge, potentially leading to data integrity compromise and an unspecified security issue. These vulnerabilities, identified through various CVEs (2026-15764 thro… CERT-FR · Jul 20, 2026 High CVE-2026-15764CVE-2026-15765CVE-2026-15766vulnerabilitybrowsermicrosoft