Security news
Latest security news
Wed, 2 Sept 2026
- Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.
Dark ReadingMicrosoft - Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," Microsoft
The Hacker NewsMicrosoft, Windows
Mon, 31 Aug 2026
- Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.
Unit 42Microsoft
Fri, 28 Aug 2026
- Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn
More than 100 companies, including OpenAI, Anthropic, Google and Microsoft, have urged collective action to unlock the power of AI to protect critical public services
Infosecurity MagazineGoogle, Microsoft
Thu, 27 Aug 2026
- CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products
CISA added six new bugs to its Known Exploited Vulnerabilities catalog on August 26, showing signs of active exploitation in the wild
Infosecurity MagazineMicrosoft, Citrix, Linux
Wed, 26 Aug 2026
- 'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.
Dark ReadingMicrosoft
Mon, 24 Aug 2026
- Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)Rapid7 BlogMicrosoft, SharePoint
- Doubloon Dredger Abuses Notion to Harvest Authentication Tokens
Doubloon Dredger abused Notion and malicious PDFs to harvest Microsoft authentication tokens
Infosecurity MagazineMicrosoft
Sun, 23 Aug 2026
- Microsoft Entra ID Remote Code Execution VulnerabilityHacker NewsMicrosoft
Thu, 20 Aug 2026
- BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 – without exploits, vulnerabilities, or memory corruption? In this publication, we present the first full
Check Point ResearchMicrosoft
About this news
- 1,259
- Stories
- 34
- Added in the last 24 hours
- 17
- Critical in the last 7 days
- 4
- Reported by several outlets