Microsoft’s latest Outlook security disclosure shows how a familiar mail workflow can become a dangerous trust boundary when document handling, previewing, and patch cadence collide.
A 420-bug security release, including one zero-day, turns patching into an exposure-management race rather than a routine maintenance task.
Microsoft has flagged a new Outlook remote code execution flaw as Important, but the missing detail that matters most is how the attack is actually reached.
August’s Windows update cycle mixed a reported WinSock zero-day, four unauthenticated RCEs rated CVSS 9.8, and the kind of triage problem that punishes score-only patching.
A newly tracked SharePoint Server bug is drawing attention because it may become dangerous only when paired with an older weakness, a reminder that enterprise risk often lives in the seams between trust checks.
A disclosed proof-of-concept around ShieldBreak puts Microsoft Defender for Windows under the microscope, but the real story is the risk that a security engine itself can become the most valuable local target.
A massive August Patch Tuesday brings 398 CVEs, but the security story sharpens around an actively exploited WinSock-related elevation-of-privilege flaw in a kernel-mode Windows driver.
Microsoft Edge is experimenting with Apple account sign-in in its Canary build, a small feature test that could shape how browser identity options evolve.
A broad August patch cycle spans 394 flaws across Microsoft products, but the real pressure point is an actively exploited Windows zero-day among three notable zero-day issues.
A three-year Microsoft Datacentre Optimisation agreement is less about a headline logo swap and more about how cloud consumption, governance, and cost control are now being packaged together.
CISA has confirmed that a high-severity Microsoft SharePoint remote code execution flaw is being abused in ransomware-related attacks, with exploitation flagged since early July.
A reported attack family aimed at Windows 11 and Microsoft Entra ID is a reminder that passwordless security depends on the whole identity chain, not just the cryptography inside the key.
The change narrows one old sign-in path while reinforcing Microsoft's wider push toward PINs, passwords, and biometrics for Windows identity.
Microsoft has warned that a critical flaw in N-able cybersecurity software is being abused in a ransomware chain, while the full scope of impact remains unconfirmed.
A live Microsoft 365 phishing campaign is stealing authenticated sessions, and the target set points straight at payroll and finance workflows that can be turned into money-moving pressure points.
A Microsoft 365 phishing chain reportedly moved beyond simple account theft and into directory reconnaissance, using Microsoft Graph to hunt for staff tied to payroll and finance workflows.
Microsoft Threat Intelligence observed Storm-1175 using a newly named ransomware family, but the suggested N-able connection is still unconfirmed in the available baseline.
A phishing wave aimed at Microsoft 365 is using adversary-in-the-middle tricks and residential proxy camouflage to reach the mailboxes that sit closest to payroll and finance workflows.
A newly disclosed Windows Hello for Business technique suggests that a user session, not a PIN, may be the real prize for attackers hunting Entra ID access.
A disclosed Windows Hello for Business technique suggests that an active Windows session can become a bridge into Microsoft Entra ID, even when the attacker never learns the victim’s PIN, biometrics, or password.