Wednesday 12 August 2026 14:24:06 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItaliano

#Microsoft


Outlook's Quiet Attack Surface: A New RCE Flaw Turns Ordinary Office Files Into Risk

Published: 12 August 2026 12:56Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

Microsoft’s latest Outlook security disclosure shows how a familiar mail workflow can become a dangerous trust boundary when document handling, previewing, and patch cadence collide.

Microsoft’s Monthly Fix Pack Hides a Bigger Risk: Which Systems Get Patched First?

Published: 12 August 2026 12:52Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

A 420-bug security release, including one zero-day, turns patching into an exposure-management race rather than a routine maintenance task.

Outlook’s Next Patch Warning: A High-Severity RCE With the Trigger Still Hidden

Published: 12 August 2026 12:49Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

Microsoft has flagged a new Outlook remote code execution flaw as Important, but the missing detail that matters most is how the attack is actually reached.

Patch Tuesday’s Quiet Panic: When a Networking Flaw Meets Active Exploitation

Published: 12 August 2026 12:45Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

August’s Windows update cycle mixed a reported WinSock zero-day, four unauthenticated RCEs rated CVSS 9.8, and the kind of triage problem that punishes score-only patching.

SharePoint’s Weak Link: Why One Chained Flaw Can Turn a Server Into an Open Door

Published: 12 August 2026 12:07Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A newly tracked SharePoint Server bug is drawing attention because it may become dangerous only when paired with an older weakness, a reminder that enterprise risk often lives in the seams between trust checks.

Defender on the Defensive: A Patch-Bypass PoC Turns Microsoft’s Guard Rails Into the Prize

Published: 12 August 2026 10:42Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: PATCHVIPER

A disclosed proof-of-concept around ShieldBreak puts Microsoft Defender for Windows under the microscope, but the real story is the risk that a security engine itself can become the most valuable local target.

Microsoft’s Latest Patch Wave Hides a More Dangerous Signal: an Exploited Windows Driver Bug

Published: 12 August 2026 10:39Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A massive August Patch Tuesday brings 398 CVEs, but the security story sharpens around an actively exploited WinSock-related elevation-of-privilege flaw in a kernel-mode Windows driver.

Edge Tests Apple Account Sign-In in Canary Channel

Published: 12 August 2026 10:10Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: TRUSTBREAKER

Microsoft Edge is experimenting with Apple account sign-in in its Canary build, a small feature test that could shape how browser identity options evolve.

Microsoft Patch Flood Turns Risky as a Windows Zero-Day Lands in Active Use

Published: 12 August 2026 08:03Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A broad August patch cycle spans 394 flaws across Microsoft products, but the real pressure point is an actively exploited Windows zero-day among three notable zero-day issues.

Azure Growth by Contract: What a Datacentre Optimisation Deal Really Signals

Published: 12 August 2026 02:03Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: SECPULSE

A three-year Microsoft Datacentre Optimisation agreement is less about a headline logo swap and more about how cloud consumption, governance, and cost control are now being packaged together.

SharePoint Exploit Draws Ransomware Crews Into a Live Fire Zone

Published: 11 August 2026 16:28Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

CISA has confirmed that a high-severity Microsoft SharePoint remote code execution flaw is being abused in ransomware-related attacks, with exploitation flagged since early July.

Passkeys Under Pressure: Why a Phishing-Resistant Login Can Still Become a Target

Published: 11 August 2026 10:43Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A reported attack family aimed at Windows 11 and Microsoft Entra ID is a reminder that passwordless security depends on the whole identity chain, not just the cryptography inside the key.

Microsoft Cuts Off New Picture Password Setup in Windows 11

Published: 11 August 2026 10:29Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

The change narrows one old sign-in path while reinforcing Microsoft's wider push toward PINs, passwords, and biometrics for Windows identity.

Security Gear on the Rack: When Defenders Become the Entry Point

Published: 10 August 2026 16:09Category: Cyber Intelligence & Threat TrendsGeo: North America / USAAuthor: PHANTOMINTEGRITY

Microsoft has warned that a critical flaw in N-able cybersecurity software is being abused in a ransomware chain, while the full scope of impact remains unconfirmed.

AiTM Phishing Turns Microsoft 365 Sessions Into Payroll Hunting Grounds

Published: 10 August 2026 10:42Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

A live Microsoft 365 phishing campaign is stealing authenticated sessions, and the target set points straight at payroll and finance workflows that can be turned into money-moving pressure points.

The Stolen Login Wasn’t the Prize - The Directory Was

Published: 10 August 2026 08:04Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A Microsoft 365 phishing chain reportedly moved beyond simple account theft and into directory reconnaissance, using Microsoft Graph to hunt for staff tied to payroll and finance workflows.

Storm-1175 Reappears With a New Ransomware Build, While One Flaw Link Remains Unproven

Published: 08 August 2026 08:01Category: Ransomware & ExtortionGeo: North America / USAAuthor: HEXSENTINEL

Microsoft Threat Intelligence observed Storm-1175 using a newly named ransomware family, but the suggested N-able connection is still unconfirmed in the available baseline.

Mailbox Theft for Profit: How AiTM Phishing Is Hunting Microsoft 365 Finance Teams

Published: 07 August 2026 17:35Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A phishing wave aimed at Microsoft 365 is using adversary-in-the-middle tricks and residential proxy camouflage to reach the mailboxes that sit closest to payroll and finance workflows.

Windows Hello’s Quiet Shortcut: How a Live Session Can Bleed Into Cloud Identity

Published: 07 August 2026 17:09Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A newly disclosed Windows Hello for Business technique suggests that a user session, not a PIN, may be the real prize for attackers hunting Entra ID access.

When the Lock Screen Is Not the Finish Line

Published: 07 August 2026 16:35Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A disclosed Windows Hello for Business technique suggests that an active Windows session can become a bridge into Microsoft Entra ID, even when the attacker never learns the victim’s PIN, biometrics, or password.