Security news

Latest security news

102 of 1,259 storiesMicrosoftClear all

Tue, 8 Sept 2026

  1. August updates trigger 0xc0000409 errors on Windows Server 2016

    Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled.

    BleepingComputerMicrosoft, Windows
  2. BigBear phishing crew nets thousands of Microsoft 365 credentials

    Researchers got inside the crooks' admin panel and found 5,137 stolen records tied to 461 organizations

    The RegisterMicrosoft
  3. BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials

    CloudSEK has uncovered BigBear 2.0, a new phishing-as-a-service operation targeting Microsoft 365

    Infosecurity MagazineMicrosoft

Mon, 7 Sept 2026

  1. Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

    Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff

    The Hacker NewsMicrosoft

Sun, 6 Sept 2026

  1. Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

    Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and

    The Hacker NewsMicrosoft, Windows

Fri, 4 Sept 2026

  1. Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

    Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The

    The Hacker NewsMicrosoft
  2. Microsoft says some users can’t open the Teams desktop client

    Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems.

    BleepingComputerMicrosoft, Windows
  3. Exchange Online outage causes email delays, 'Server busy' errors

    Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains.

    BleepingComputerMicrosoft, Exchange

Thu, 3 Sept 2026

  1. Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC

    A shared security 'Nightmare'

    The RegisterMicrosoft
  2. Jenkins security advisory (AV26-877)

    Serial Number: AV26-877 Date: September 3, 2026 As of September 2, 2026, Jenkins Project is affected by vulnerabilities in the following products: Jenkins ALL except 2.568.3 ALL except 2.580 Jenkins Allure Plugin Prior to or equal to 2.35.2 Jenkins Customizable Header Plugin Prior to or equal to 295.v2544b_ca_19b_97 Jenkins File Parameter Plugin Prior to or equal to 425.v3fa_801681b_5e Jenkins GitLab Plugin Prior to or equal to 1.9.16 Jenkins LDAP Plugin Prior to or equal to 807.809.vd3a_4e5e4ec98 Jenkins Microsoft Entra ID (previously Azure AD) Plugin Prior to or equal to 710.v0b_ff8e9cc2d2 Jenkins Parameterized Remote Trigger Plugin Prior to or equal to 3.2.2 Jenkins Performance Plugin Prior to or equal to 1015.v09ca_52b_3370e Jenkins Pipeline: Build Step Plugin Prior to or equal to 599.v4b_67ea_11b_152 Jenkins SAML Plugin Prior to or equal to 4.618.v441a_27fa_46d2 Jenkins Script Security Plugin Prior to or equal to 1412.v7737b_3405f86 Jenkins TICS Plugin Prior to or equal to 2025.1.1 Jenkins ThinBackup Plugin Prior to or equal to 2.1.4 Jenkins XebiaLabs XL Deploy Plugin Prior to or equal to 26.1.0 Jenkins update-center2 Prior to or equal to 3.18.3 The Cyber Centre encourages use

    Canadian Centre for Cyber SecurityMicrosoft, GitLab, Jenkins

About this news

1,259
Stories
34
Added in the last 24 hours
17
Critical in the last 7 days
4
Reported by several outlets