Tag Microsoft

Two Windows Vulnerabilities, Including a Zero-Day, Actively Exploited

Researchers have identified that two critical vulnerabilities in Windows operating systems are currently being exploited in widespread cyberattacks. One of these vulnerabilities is a zero-day flaw that has remained active since 2017, while the second is a significant bug that Microsoft has struggled to patch effectively. The zero-day vulnerability was…

Read MoreTwo Windows Vulnerabilities, Including a Zero-Day, Actively Exploited

Microsoft Confirms Data Leak Affecting Over 65,000 Companies Due to Server Misconfiguration

This week, Microsoft confirmed a significant security breach involving the inadvertent exposure of sensitive information belonging to thousands of customers. The incident stemmed from a security misconfiguration that left an endpoint publicly accessible on the internet without authentication, allowing potential unauthorized access to business transaction data. The company described the…

Read MoreMicrosoft Confirms Data Leak Affecting Over 65,000 Companies Due to Server Misconfiguration

Microsoft Alert: Extensive Phishing Campaigns Exploit Open Redirects

Microsoft has issued a stark warning concerning an extensive credential phishing campaign that exploits open redirector links in email communications. This tactic aims to deceive users into visiting malicious sites while circumventing traditional security measures. According to a report from the Microsoft 365 Defender Threat Intelligence Team, attackers combine these…

Read MoreMicrosoft Alert: Extensive Phishing Campaigns Exploit Open Redirects

Microsoft Alerts on Chinese Botnet Exploiting Router Vulnerabilities for Credential Theft

Microsoft Uncovers Chinese Botnet Targeting Organizations with Evasive Password Spray Attacks Microsoft has reported the activity of a Chinese threat actor known as Storm-0940, which is employing a sophisticated botnet identified as Quad7. This botnet has been linked to a series of highly evasive password spray attacks aimed at stealing…

Read MoreMicrosoft Alerts on Chinese Botnet Exploiting Router Vulnerabilities for Credential Theft

New Zero-Day Attack Targets Windows Users Through Microsoft Office Documents

Microsoft has recently issued a warning regarding an actively exploited zero-day vulnerability affecting Internet Explorer. This flaw is being utilized to compromise Windows systems by means of malicious Microsoft Office documents. Identified as CVE-2021-40444 with a CVSS score of 8.8, the vulnerability resides in MSHTML, a proprietary browser engine that…

Read MoreNew Zero-Day Attack Targets Windows Users Through Microsoft Office Documents

The Microsoft Azure Outage Highlights the Stark Truth About Cloud Failures

Microsoft Azure Suffers Major Outage Amid Configuration Issues Microsoft’s Azure cloud platform, along with its widely utilized 365 services and gaming platforms such as Xbox and Minecraft, experienced significant outages around noon Eastern time on Wednesday. The company attributed these disruptions to “an inadvertent configuration change.” This incident represents the…

Read MoreThe Microsoft Azure Outage Highlights the Stark Truth About Cloud Failures

Warnings Increase Regarding Hacks Targeting Windows Server Update Services

Governance & Risk Management, Patch Management Significant Vulnerability in Windows Server Update Services Exposed Akshaya Asokan (asokan_akshaya) • October 28, 2025 Image: bluestork/Shutterstock Concerns are mounting over the exploitation of a flaw in Windows Server Update Services (WSUS), especially after Microsoft expedited a patch addressing an issue that permits unauthenticated…

Read MoreWarnings Increase Regarding Hacks Targeting Windows Server Update Services

Windows MSHTML Zero-Day Exploited for Cobalt Strike Beacon Deployment in Targeted Attacks

Microsoft Unveils Details of Targeted Phishing Attack Exploiting Critical Vulnerability On Wednesday, Microsoft provided significant insights into a sophisticated phishing campaign that capitalized on a now-resolved zero-day vulnerability in its MSHTML platform. The exploit involved specially designed Office documents aimed at deploying Cobalt Strike Beacon malware on compromised Windows systems,…

Read MoreWindows MSHTML Zero-Day Exploited for Cobalt Strike Beacon Deployment in Targeted Attacks