Browsing Tag
Microsoft
462 posts
Microsoft Disrupts AI-Powered EvilTokens Service Linked to 12,000 Hacked Inboxes
Microsoft disrupted EvilTokens after the AI-powered phishing service compromised 12,000 inboxes across 10,000 organisations and enabled complex financial fraud.
September 23, 2026
New GhostCode Phishing Kit Hijacks Microsoft Accounts Despite MFA
eSentire uncovers the GhostCode phishing kit abusing Microsoft OAuth to steal tokens, register attacker devices and access Microsoft 365 accounts.
September 17, 2026
Hackers Pose as IT Support, Use Fake Passkey Lures to Steal Microsoft 365 Access
Microsoft warns of fake passkey and IT support attacks targeting Microsoft 365 accounts to steal authentication tokens and access corporate cloud data.
September 15, 2026
Microsoft Patch Tuesday Fixes 966 Vulnerabilities, Including 2 Exploited 0-Days
Microsoft Patch Tuesday fixes 966 vulnerabilities, including two exploited Windows zero-days, critical RCE flaws, and bugs in Office, networking and Hyper-V.
September 9, 2026
Microsoft Warns of TerminalFix Campaign Hiding Malware in PNG Images
TerminalFix uses fake Cloudflare CAPTCHA pages to trick users into running PowerShell malware, creating reverse tunnels that provide access to internal systems.
August 31, 2026
Kali365 Exploits Microsoft Device Login to Access US Corporate Data
Learn how Kali365 has been abusing Microsoft device login to gain OAuth tokens, targeting US firms, and how SOC teams can detect, hunt, and stop these phishing attacks.
August 5, 2026
Top 10 Companies to Hire Power BI Developers in 2026
Compare 10 Power BI development companies for 2026, covering DAX, Microsoft Fabric, data engineering, security, compliance, AI, and enterprise BI project needs.
July 30, 2026
Microsoft Fixes CosmosEscape Flaw That Could Allow Any Cosmos DB Takeover
Cybersecurity researchers at Wiz found CosmosEscape in Azure's Gremlin API, exposing a master key that could access any Cosmos DB account. Microsoft fixed it, with no customer impact found.
July 30, 2026
Fake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor Infections
Fake helpdesk callers use Microsoft Teams and Quick Assist to access employee computers, where attackers install new GoGRPC backdoor in suspected ransomware operations
July 28, 2026
Microsoft Fixes Certighost Flaw That Allowed Domain Controller Impersonation
Certighost allowed a low-privilege domain user obtain a valid Domain Controller certificate through AD CS. Microsoft patched the issue in the July security updates.
July 27, 2026