Security news

Latest security news

102 of 1,259 storiesMicrosoftClear all

Wed, 2 Sept 2026

  1. Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users

    The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.

    Dark ReadingMicrosoft
  2. Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," Microsoft

    The Hacker NewsMicrosoft, Windows

Mon, 31 Aug 2026

  1. Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

    Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.

    Unit 42Microsoft

Fri, 28 Aug 2026

  1. Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn

    More than 100 companies, including OpenAI, Anthropic, Google and Microsoft, have urged collective action to unlock the power of AI to protect critical public services

    Infosecurity MagazineGoogle, Microsoft

Thu, 27 Aug 2026

  1. CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products

    CISA added six new bugs to its Known Exploited Vulnerabilities catalog on August 26, showing signs of active exploitation in the wild

    Infosecurity MagazineMicrosoft, Citrix, Linux

Wed, 26 Aug 2026

  1. 'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

    The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.

    Dark ReadingMicrosoft

Mon, 24 Aug 2026

  1. Doubloon Dredger Abuses Notion to Harvest Authentication Tokens

    Doubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokens

    Infosecurity MagazineMicrosoft

Sun, 23 Aug 2026

Thu, 20 Aug 2026

  1. BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive

    Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 – without exploits, vulnerabilities, or memory corruption? In this publication, we present the first full

    Check Point ResearchMicrosoft

About this news

1,259
Stories
34
Added in the last 24 hours
17
Critical in the last 7 days
4
Reported by several outlets