-
A suspected Microsoft Power Pages configuration failure has been linked to the exposure of roughly 27 million records across 13 organizations, after the data-extortion group ExfilSquad published 382.64 GB of alleged victim data via torrent distribution…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft has released security updates that address six vulnerabilities in Exchange Server. These vulnerabilities include flaws that could allow remote code execution (RCE), privilege escalation, denial-of-service (DoS), spoofing, and bypass of securi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly disclosed vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-63520, could allow attackers to execute arbitrary code remotely on affected systems. This flaw has a severity rating of 8.1 out of 10 according to CVSS v3.1. It affects…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft has disclosed a new remote code execution (RCE) vulnerability in Outlook, tracked as CVE-2026-70329. They warn that successful exploitation could allow attackers to run malicious code on affected systems. Released on August 11, 2026, this vul…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft’s August 2026 Patch Tuesday released fixes for hundreds of vulnerabilities across various products, including Windows, Office, SharePoint, Azure, .NET, PowerShell, Visual Studio Code, and other enterprise solutions. A total of 394 distinct fl…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A widespread phishing operation that compromises Microsoft 365 accounts through adversary-in-the-middle (AiTM) infrastructure, then uses Microsoft Graph to identify employees handling payroll, finance, HR, benefits, invoices, and banking workflows. The…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Stolen Greatness authentication tokens are providing sustained, MFA‑approved access to victim Microsoft 365 tenants for more than two weeks after the initial phish, underscoring that token replay – not password theft – is driving the persistence in thi…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Microsoft’s Bug Bounty Program awarded over $20 million to 562 security researchers this year, marking the highest total payout and the largest number of recognized researchers in the program’s history. Contributors hailed from 64 countries…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Learn how Kali365 has been abusing Microsoft device login to gain OAuth tokens, targeting US firms, and how SOC teams can detect, hunt, and stop these phishing attacks.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A controlled proof-of-concept by Barracuda’s Red Team has demonstrated how a compromised Microsoft 365 account with Copilot access can serve as a powerful launchpad for business email compromise (BEC). This scenario ultimately enables attackers to impe…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


