Microsoft patches 398 flaws, including exploited CVE-2026-68820 that lets local attackers reach SYSTEM, plus four unauthenticated 9.8 RCEs.
Microsoft says Russian hackers are exploiting public Wi-Fi networks to intercept Microsoft account logins and install malware ...
Microsoft blames Russian state-sponsored APT Midnight Blizzard for hacking hotel Wi-Fi networks to steal travelers’ ...
SharePoint CVE-2026-55040 lets unauthenticated attackers impersonate users and chain with CVE-2026-63520 for code execution ...
Hackers are compromising hotel Wi-Fi gateways to redirect business travelers to fake Microsoft 365 login pages that can ...
The 8 best agentic SOC platforms for Microsoft Sentinel in 2026, compared. What Security Copilot's agents do today, GA versus ...
A Storm-2945 campaign layers device code phishing onto hijacked hotel Wi-Fi to bypass MFA on Microsoft 365 accounts. Here's ...
Microsoft has warned travellers about CaptiveCrunch, a cyberattack campaign targeting hotel Wi-Fi and other public guest networks worldwide.The campaign can red ...
New Jalisco and OmegaLord phishing kits target Microsoft 365 accounts by abusing device code flows, OAuth tokens, and MFA prompts to maintain access.
The sign-in prompt in Office 365 or Microsoft 365 desktop apps may say device TPM problem, Trusted Platform Module ...
Right on the heels of Microsoft releasing a record number of security patches, a researcher has published exploit code that can enable low-privilege Windows accounts to make sensitive changes to ...
Two campaigns created 4M+ fake identities to enumerate Microsoft Entra ID accounts — without logins. Learn how to detect the ...