Search
Find merged stories by title or summary.
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data
IEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data. IEH Corporation is a U. S. defense and aerospace manufacturer based in Brooklyn, New York. The company specializes in high-reliability electrical connectors, particularly hyperboloid connectors used in demanding military and aerospace environments. Its connectors are used in systems including rotary-wing aircraft, THAAD and Patriot missile systems, fighter aircraft, airborne radar systems, satellites and spacecraft, military radios, and torpedoes. IEH Corporation disclosed a cyberattack in an 8-K filing with the SEC. The company discovered the breach on August 4.
200 accounts compromised in Swiss government’s Microsoft SharePoint breach
Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts. On July 28, BIT’s security specialists noticed unusual activity on the SharePoint servers. Once the intrusion was confirmed, BIT blocked internet access to the platform and closed the vulnerabilities being exploited. Three days later, on July 31, security specialists discovered “that the login credentials for several accounts had … More → The post 200 accounts compromised in Swiss government’s Microsoft SharePoint breach appeared first on Help Net Security .
Microsoft, Apple Release Fresh Security Updates
Microsoft fixed critical vulnerabilities across Azure, Entra, and SharePoint, while Apple patched a high-severity authentication bypass. The post Microsoft, Apple Release Fresh Security Updates appeared first on SecurityWeek .
August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?
July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, of course, well over 600 CVEs were identified in the Security Updates Guide. Interestingly, only two CVEs were reported as exploited zero-days and only one as publicly disclosed, but we’ll get back to that later in this article. There were 405 CVEs reported against Windows 11 … More → The post August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? appeared first on Help Net Security .
July 2026 CVE Landscape
In July 2026, Insikt Group® identified 85 high-impact vulnerabilities that should be prioritized for remediation , 36 of which had a Very Critical Recorded Future Risk Score. This represents a 44% increase from last month. 26 of these vulnerabilities were surfaced through the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 55 were reported by vendors, and four were primarily surfaced through honeypot data. The 85 vulnerabilities in this report affected products from 61 vendors, with Microsoft accounting for approximately 12% of the vulnerabilities. The remaining exposure was concentrated across a range of enterprise software, security products, network infrastructure, developer tooling, and cloud platform vendors.
Practical lessons from deploying AI securely at scale
When I first started working on enterprise AI security initiatives, I expected the biggest challenges to be technical. I assumed we’d spend most of our time discussing prompt injection, model security, vector databases or the latest LLM vulnerabilities. I was wrong — or at least incomplete. The technology certainly matters, but after working with multiple enterprise AI initiatives, I’ve learned that the hardest security problems rarely come from the model itself. They emerge when AI becomes part of real business processes. An AI assistant doesn’t simply answer questions. In a single workflow, it might pull a customer record from Salesforce, open a ticket in ServiceNow and send an update through Microsoft 365 before anyone has finished reading the summary. Increasingly, it makes decisions before a human even notices, and that shift changes the threat model.
Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
As organizations adopt AI, they must secure both cloud and AI environments through a unified security control plane as their attack surface expands. Because modern applications and AI workloads are built and run in the cloud, security teams must understand which exposures matter most, prioritize what can truly be exploited, and reduce risk across cloud infrastructure, applications, identities, data, and AI systems in one place. Modern IT estates now span multiple clouds and on-premises systems, with architectures built on containers, Kubernetes, serverless functions, microservices, APIs, and AI-powered workloads. This increases both the volume and the interconnectedness of security signals.
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
In this article • Activity overview • How ClickFix works • Campaign overview • ClickFix moved from open pages to fingerprinting gates • The fingerprinting gate • Mitigation and protection guidance • Indicators of compromise (IOC) • References • Learn more Microsoft Threat Intelligence observed a macOS ClickFix campaign distributing infostealers, including MacSync and Atomic Stealer (AMOS) , through a large cluster of look-alike domains. The campaign evolved from broadly serving ClickFix lures to using a server-side browser-fingerprinting gate that shows the lure primarily to visitors whose environment appears consistent with a genuine macOS browser. This cloaking limits visibility for crawlers, sandboxes, and some automated analysis workflows.
Kali365 Exploits Microsoft Device Login to Access US Corporate Data - Hackread
Kali365 Exploits Microsoft Device Login to Access US Corporate Data Hackread
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
In this article • Attack chain overview • Mitigation and protection guidance • Indicators of compromise (IOC) • Microsoft Defender XDR detections • Advanced hunting queries • Learn more Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers, including packages associated with major enterprise software ecosystems such as keyv, flat-cache, cache-manager, and others. The malicious releases contain a Mini Shai-Hulud variant, a self-propagating credential-stealing worm delivered through a large, heavily obfuscated Bun-based JavaScript payload. The malware typically executes automatically through an npm preinstall lifecycle hook before package installation completes.
Patch faster isn’t the answer. Patch smarter is.
The 30-day patch cycle is dead. Most security teams already know this. What they haven’t fully reckoned with is why it died, and what has to replace it. SC Media recently gathered a range of security leaders on exactly this shift, and the picture they described is stark. AI didn’t just add more vulnerabilities to the pile. It collapsed the time between disclosure and exploitation from weeks to hours. Microsoft’s July release patched more than 600 bugs in a single Patch Tuesday, on the heels of a record 206 flaws the month before. In the same week, CISA pushed emergency patch orders for Oracle E-Business and Microsoft SharePoint, and researchers documented a full ransomware operation executed start to finish in under 24 hours. Recent Cloud Security Alliance research puts a number on the danger. Only 9% of organizations remediate critical vulnerabilities within 24 hours.
Russian spies hijack hotel WiFi worldwide to infect travelers with malware, Microsoft warns - Cybernews
Russian spies hijack hotel WiFi worldwide to infect travelers with malware, Microsoft warns Cybernews
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
The calculus of cybersecurity has changed. AI is reshaping how organizations build, deploy, operate, and defend digital systems. AI-powered development tools, agents, and autonomous workflows are accelerating innovation but they are also introducing new attack surfaces, new trust boundaries, and new security challenges. Microsoft has long helped organizations secure their digital estates using Zero Trust principles . That leadership was recently recognized by KuppingerCole analysts, which named Microsoft as the Overall Leader in its Zero Trust Platform Leadership Compass , ranking Microsoft highest for both product and innovation leadership. Learn more about Zero Trust for AI As organizations accelerate AI adoption, secure software development becomes more important than ever.
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
In this article • What is device isolation? • Case study: QNET • Attack chain overview • MITRE ATT&CK techniques observed • References • Learn more Microsoft Defender’s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints. At QNET, an attacker initiated a multi-stage attack using a legitimate Windows tool on a compromised endpoint to retrieve a malicious remote payload–a classic living-off-the-land (LOL) technique that often evades traditional containment. By automatically enforcing the new device isolation action on the compromised endpoint, Defender attack disruption stopped the attack dead in its tracks.
Travelers targeted when logging into hotel Wi-Fi networks
Microsoft has warned that hotel, conference, and other hospitality Wi-Fi networks are being actively abused by a Russian group to target travelers worldwide. The campaign, dubbed “CaptiveCrunch” turns a routine Wi-Fi login moment into an opportunity to compromise corporate accounts and devices. From the user’s perspective, nothing looks out of the ordinary: they connect to hotel Wi-Fi, get the usual captive portal prompt, and perhaps see a familiar‑looking message about needing to update something before they can browse. However, behind the scenes, the allegedly state-linked group position themselves in the network path and manipulate DNS (Domain Name System) and HTTP traffic from captive‑portal Wi-Fi.
A week in security (July 27 – August 2)
Last week on Malwarebytes Labs: • Fake Fortnite rewards are stealing players’ accounts • Fake Flash Player installs AtlasRAT • Malwarebytes for Windows, now available on the Microsoft Store • Hims & Hers sued over alleged health data privacy failures • Hidden prompt turns Microsoft Copilot into an AI worm • Apple accused of letting fake crypto app steal $1.8 million • Buying TikTok views or followers?
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
In this article • The CaptiveCrunch campaign • Storm-2945 and Midnight Blizzard • CaptiveCrunch tradecraft and tooling • How to protect against CaptiveCrunch activity • Microsoft Defender detections and hunting guidance • Indicators of compromise Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some tactic, technique, and procedure (TTP) similarities to the Forest Blizzard DNS hijacking operation that we publicly disclosed in April 2026, we attribute this campaign, which we call CaptiveCrunch, to Storm-2945.
The Security Interviews: Nicole Darden Ford, Microsoft
As a black woman in the white, male-dominated world of cyber security, Microsoft’s Nicole Darden Ford has worked hard to carve out her space in the room. She talks about developing confidence and self-belief, building community, and leading with humility
What’s new in Microsoft Security: July 2026
Every organization needs security that protects end to end with the speed and scale of AI. Microsoft’s vision is simple: security should be ambient and autonomous, just like the AI it protects. As organizations scale AI and expand across environments, security teams need protection that covers every surface. This month’s updates help security and IT teams secure their AI environments, use AI to defend at speed and scale, and strengthen the foundations that AI-powered operations depend on. Here’s what’s new: Project Perception brings agentic defense to security operations Project Perception , newly announced, is a coordinated system of specialized agents, cybersecurity-focused models, and enterprise-wide signals that transform how security operates.
'Certighost' Flaw Haunts Microsoft Active Directory Certificates
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.
Kali365: The Phishing-as-a-Service Operation Expanding Beyond Microsoft 365
By Assaf Morag, Cybersecurity Researcher Most phishing kits steal passwords. Kali365 does something more dangerous: it tricks victims into authenticating on a genuine Microsoft page, completing MFA themselves, and unknowingly handing an attacker-controlled session the resulting access tokens. No credentials are intercepted. No fake login page is required. The victim does everything right and still loses control of their identity. But Kali365 is no longer limited to Microsoft 365. What began as a device-code phishing kit has grown into a subscription phishing platform that impersonates identity providers, cloud services, email platforms, file-sharing tools, and messaging applications across multiple brands and regions. In May 2026, the FBI described Kali365 as an emerging Phishing-as-a-Service (PhaaS) platform distributed mainly through Telegram.
Detection Without Automated Response Fails: Lessons for Identity-First CTI
By Flare Product In the mid-2010s, endpoint security reached a breaking point. Malware volume grew nearly eightfold between 2010 and 2016. Ransomware campaigns like WannaCry and NotPetya exploited the gap between detection and manual response with devastating efficiency. The industry’s answer was EDR: push automated response as close to the point of attack as possible and close the gap to zero. It worked. According to the 2024 Microsoft Digital Defense Report , over 90% of attacks that progressed to the ransom stage now originate from unmanaged devices, the systems that fall outside the EDR shield. The lesson was clear: detection without automated response is not defense; it is observation. Identity security is now at the same inflection point. Fifty million breached identities are traded weekly across Telegram and dark web channels.
HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
Group-IB uncovers HOLLOWGRAPH, a Windows malware that abuses Microsoft Graph API to exfiltrate files and receive commands from the attacker using Microsoft 365 calendar events, and DNS tunneling to refresh credentials used in C2 communication.
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical." Microsoft notes that two of the vulnerabilities disclosed this month have been exploited in the wild. CVE-2026-56155 is an important-severity elevation of privilege vulnerability in Active Directory Federation Services (AD FS) caused by insufficient granularity of access control. An authorized attacker could use it to elevate privileges locally. CVE-2026-56164 is a moderate-severity vulnerability in Microsoft SharePoint Server caused by missing authentication for a critical function. An unauthorized attacker could exploit it to perform spoofing over a network.
Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence. Nearly 60 of the bugs quashed in July’s Patch Tuesday earned a “critical” severity rating, meaning miscreants or malware could use them to seize remote control over a Windows device with little or no help from the user. Microsoft also addressed three zero-day flaws, including two that are already being exploited in the wild.
June 2026 CVE Landscape
In June 2026, Insikt Group® identified 59 high-impact vulnerabilities that should be prioritized for remediation , 30 of which had a Very Critical Recorded Future Risk Score. This represents a 47% increase from last month. 23 of the 59 vulnerabilities were included in the US Cybersecurity and Infrastructure Security Agency (CISA)’s Known Exploited Vulnerabilities (KEV) catalog, 33 were reported by vendors, and three were primarily surfaced through honeypot data. The 59 vulnerabilities in this report affected products from 36 vendors, with Microsoft accounting for approximately 17% of the vulnerabilities. The remaining exposure was concentrated across a range of enterprise software, security products, network infrastructure, developer tooling, and cloud platform vendors.
Conditional Access Misconfigurations Exposed 55 Orgs with MFA On
Two Microsoft 365 attacks got through Conditional Access policies that seemed fully configured. Learn what went wrong and how Huntress Managed ISPM catches these gaps first.
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI
Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021 , remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any SAML-federated application, bypassing multifactor authentication (MFA), conditional access, and all identity-based controls. However, during a recent red team engagement, Mandiant discovered that when ADFS certificates are manually rotated, configuration drift can silently leave active signing keys exposed in Machine DPAPI.
[remote] Microsoft - NTLMv2 Hash Capture
Microsoft - NTLMv2 Hash Capture
[tl;dr sec] #329 - AI-powered Honeypots, GitHub Action Canaries, Microsoft’s Agentic Security Scanner
Hey there, I hope you’ve been doing well! 🍦 Ice Cream Bonding There’s this Mediterranean place I like to go to sometimes, Souvla, that has delicious frozen Greek yogurt you can get with baklava on top. It’s helped me power through many a late night writing tl;dr sec . Like tonight 😅 I’ve gradually started befriending the manager over time, over a series of froyos. We’ve discussed how it’s sometimes difficult to make new (deep) friends as you get older, some of his work challenges, and more. All from periodic 5 minute conversations.
Welcome to BlackFile: Inside a Vishing Extortion Operation
Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671 gains deep access to cloud environments. The group primarily targets Microsoft 365 and Okta infrastructure, leveraging Python and PowerShell scripts to programmatically exfiltrate sensitive corporate data for subsequent extortion attempts. This post details UNC6671’s attack lifecycle and provides defenders with actionable guidance to detect and mitigate these identity-centric threats.
Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite
Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim to accept a Microsoft Teams chat invitation from an account outside their organization. The UNC6692 campaign demonstrates an interesting evolution in tactics, particularly the use of social engineering, custom malware, and a malicious browser extension, playing on the victim’s inherent trust in several different enterprise software providers.
Uncovering agent logging gaps in Copilot Studio
During research, we sometimes encounter scenarios that remind us that it's a good idea to trust but verify. In September 2025, we noticed that certain Microsoft Copilot Studio agent settings did not log certain administrative actions related to sharing, authentication, logging, and publication of Copilot Studio agents.
OpenAI Explains URL-Based Data Exfiltration Mitigations in New Paper
Last week I saw this paper from OpenAI called “Preventing URL-Based Data Exfiltration in Language-Model Agents”, which goes into detail on new mitigations they’ve added. This is a great read. I like this transparency. Initial Disclosure in 2023 Nearly three years ago I reported the zero-click data exfiltration exploit to OpenAI. Back in early 2023 OpenAI did not have a bug bounty program, so communication was via email, and unfortunately there was little traction or appetite to fix the problem in ChatGPT. I also reported the same issue to Microsoft as Bing Chat was impacted, and Microsoft applied a fix (via a Content-Security-Policy header) in May 2023 to generally prevent loading of images.
Bypassing Windows Administrator Protection
A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection . The goal of this feature is to replace User Account Control (UAC) with a more robust and importantly, securable system to allow a local user to access administrator privileges only when necessary. This blog post will give a brief overview of the new feature, how it works and how it’s different from UAC. I’ll then describe some of the security research I undertook while it was in the insider preview builds on Windows 11. Finally I’ll detail one of the nine separate vulnerabilities that I found to bypass the feature to silently gain full administrator privileges. All the issues that I reported to Microsoft have been fixed, either prior to the feature being officially released (in optional update KB5067036 ) or as subsequent security bulletins.
Windows Defender Support Logs
I ran across a LinkedIn post the other day that mentioned using Windows Defender Support Logs (actually, I think the post referred to them as "diagnostic" logs). These logs are found in the following folder: C:\ProgramData\Microsoft\Windows Defender\Support\ ...and follow the naming convention: MpWppTracing-YYYYMMDD-HHMMSS-00000003-fffffffeffffffff.bin The post mentions using strings to parse the files, but I was wondering if there was a parser available, and like Deadpool, I figured I'd go looking... and I found something called mplog_parser . I've had a few opportunities to pull down some of these files from endpoints, but nothing has popped out as being related to the incident in question. That's okay, though...I'll keep this one in my kit, and I'll have to give the parser from Github a shot.
Amazon Q Developer: Remote Code Execution with Prompt Injection
The Amazon Q Developer VS Code Extension (Amazon Q) is a popular coding agent, with over 1 million downloads . The extension is vulnerable to indirect prompt injection, and in this post we discuss a vulnerability that allowed an adversary (or also the AI for that matter) to run arbitrary commands on the host without the developer’s consent. The resulting impact of the vulnerability is the same as CVE-2025-53773 that Microsoft fixed in GitHub Copilot, however AWS did not issue a CVE when patching the vulnerabili
Data Exfiltration via Image Rendering Fixed in Amp Code
In this post we discuss a vulnerability that was present in Amp Code from Sourcegraph by which an attacker could exploit markdown driven image rendering to exfiltrate sensitive information. This vulnerability is common in AI applications and agents, and it’s actually similar to one we discussed last year in GitHub Copilot which Microsoft fixed . Exploit Demonstration For the proof-of-concept I use a pre-existing demo that created a longer time ago. It happened to just work with Amp as well. The prompt injection is hosted on a website which asks the AI to “backup” information to a third-party site by rendering an image and including previous chat data as a query parameter.
Issue 247: Dropbox and Dell breaches, vulnerability in Next.js, API growth causing concerns
This week, we have news of two high-profile breaches. First up is the Dropbox breach, potentially affecting millions of users, and then the Dell breach, affecting 49 million records. We also have details of a vulnerability in the Next. js component. We also have a free on-demand recording from Microsoft Build on Navigating the Depths of API Security testing. We share an article on how API growth is causing cybersecurity concerns and the menace of unknown APIs. Finally, we have a refresh of the excellent Awesome API Security guide. Breach: Dropbox users in major data breach The first breach this week was a potentially large-scale one suffered by Dropbox. Dropbox disclosed a data breach affecting its Dropbox Sign (formerly HelloSign) users.
Issue 233: Flaws in OAuth social sign-in, securing API gateways, scalable SaaS security
This week, we have important news of a vulnerability in the OAuth social sign-in feature of many popular platforms, potentially impacting billions of users. We have two articles from The NewStack, the first a guide on securing your API gateway and the second how to design scalable SaaS API security. We also have news of a significant partnership between Microsoft and 42Crunch designed to deliver end-to-end API security for enterprises. We finish with two guides, the first on preventing API breaches and the second from Dana Epp on using Burp Collaborator to prove API exploitability. Vulnerability: Flaws in OAuth social sign-in put billions at risk The most important item this week (and in the last few months) is the vulnerability discovered by Salt Labs in implementing the OAuth protocol in several popular websites.
