Security news

Latest security news

102 of 1,256 storiesMicrosoftClear all

Today · Wed, 16 Sept 2026

  1. One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

    Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. Once the extension was installed, it could access each product's built-in AI with a single click. On Comet, Edge,

    The Hacker NewsMicrosoft, Chrome
  2. Microsoft says Copilot buttons still missing in classic Outlook

    Microsoft says it's still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users.

    BleepingComputerMicrosoft, Windows, Outlook
  3. Windows Server 2022 reaches end of mainstream support next month

    Microsoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031.

    BleepingComputerMicrosoft, Windows

Yesterday · Tue, 15 Sept 2026

  1. Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

    Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers.

    SecurityWeekMicrosoft
  2. Microsoft Issues Emergency Fixes After Massive Patch Tuesday

    You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.

    Dark ReadingMicrosoft
  3. Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

    Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs. The

    The Hacker NewsMicrosoft, AWS, F5
  4. Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints

    The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability.

    SecurityWeekMicrosoft
  5. Microsoft confirms KB5002914 Excel update breaks copy and paste

    Microsoft has confirmed that copy and paste may silently fail for some Excel users after installing the September 2026 KB5002914 security update.

    BleepingComputerMicrosoft
  6. Microsoft Releases Emergency Patch to Fix RDS Snafu

    Microsoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch Tuesday

    Infosecurity MagazineMicrosoft
  7. China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

    A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The

    The Hacker NewsGoogle, Microsoft, Windows

About this news

1,256
Stories
41
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets