Domingo 26 Julio 2026 23:23:52 GMT+02:00

Netcrook

InicioManifiesto
Noticias
Techcrook
Geocrook
WikicrookEquipoAppContactoLogin
EnglishItaliano

#Microsoft


One Hash, One Claim, Zero Proof: The ExfilSquad-Microsoft Bulletin

Published: 26 July 2026 14:17Category: Ransomware & ExtortionGeo: North America / USAAuthor: HEXSENTINEL

A ransomware allegation naming Microsoft surfaced with a single hash and no victim website, leaving only a narrow signal and no verified breach.

Extortion Listing Turns Microsoft Into a High-Value Claim, Not a Verified Breach

Published: 26 July 2026 14:17Category: Ransomware & ExtortionGeo: North America / USAAuthor: LOGICFALCON

Exfilsquad is tied to a fresh victim entry that alleges millions of records, but the breach itself and the data claim remain unverified.

Azure Automation’s Quiet Default That Could Have Collapsed Tenant Boundaries

Published: 24 July 2026 18:55Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

Microsoft corrected a public-by-default configuration and code flaws in a cloud automation service that may have created a cross-tenant identity risk, without any confirmed exploitation in the available material.

A Routine Route Change Knocked Microsoft’s Cloud Off Balance

Published: 24 July 2026 18:04Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: SECPULSE

A maintenance bug in an automated network system reportedly removed IP routes from more devices than intended, showing how quickly a shared cloud backbone can turn a small error into a wide service disruption.

When the Helpdesk Arrives in Chat: Microsoft Teams as the New Social-Engineering Front

Published: 24 July 2026 10:54Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

Attackers are using Microsoft Teams conversations to pose as internal IT support, turning a trusted workplace channel into a path for credentials, remote access, and account takeover attempts.

When the Inbox Is No Longer Enough: Phishing Moves Into Chat and Calls

Published: 24 July 2026 10:51Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

Microsoft’s warning points to a harder problem for defenders: attackers are increasingly exploiting the trust built into workplace communication tools, with Teams emerging as a prime social-engineering surface.

When Guest Wi-Fi Becomes the Attack Surface for Cloud Identity Theft

Published: 24 July 2026 10:31Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A reported campaign against hotel and conference-center Wi-Fi gateways shows how DNS manipulation and risky login flows can push Microsoft 365 users toward attacker-controlled infrastructure without email lures or endpoint malware.

The Quiet Wi-Fi Trap Turning Travel Logins Into Identity Theft

Published: 24 July 2026 10:08Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A compromise at the hotel or conference network edge can steer Microsoft 365 sign-ins off course, showing how DNS tampering can become an identity attack without phishing or malware.

Microsoft 365 Falters, and the Modern Office Feels the Shock

Published: 23 July 2026 18:14Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: TRUSTBREAKER

An ongoing outage affecting Teams, SharePoint, Excel, and the Microsoft 365 Admin Center exposes how quickly cloud productivity can turn into a business continuity problem.

Passkeys Enter the Blast Radius When Identity Logic Breaks

Published: 23 July 2026 15:01Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: PATCHVIPER

Researchers flagged exploitable flaws in Microsoft’s passkey handling, a reminder that passwordless systems still depend on careful implementation, especially around privileged access.

When the Inbox Becomes the Incident: Exchange Online’s Quarantine Glitch

Published: 23 July 2026 12:26Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

Microsoft is working to resolve an Exchange Online issue that is mistakenly quarantining customer mailboxes, a reminder that cloud email controls can fail without any attacker in sight.

Microsoft Draws a New Line in the Inbox: Defending Email from AI Manipulation

Published: 23 July 2026 12:24Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

Defender for Office 365 is now being used to blunt prompt injection, a reminder that enterprise email is becoming an input channel for assistants as much as a message stream for humans.

Microsoft Pushes Prompt Injection Defense Upstream, Into the Inbox

Published: 23 July 2026 12:12Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: KERNELWATCHER

Defender for Office 365 is now inspecting inbound email for hidden AI instructions before they can reach a mailbox or be consumed by Microsoft 365 Copilot.

Microsoft Sets a Hard Stop on Exchange Security Fixes

Published: 22 July 2026 14:48Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: TRUSTBREAKER

The October cutoff for Exchange 2016 and Exchange 2019 turns a support notice into a planning deadline for any organization still depending on those mail servers.

The Login Trick That Turns Trust Into a Token

Published: 22 July 2026 14:24Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A legitimate Microsoft sign-in path is being treated as an attack surface, where user approval can hand an adversary a valid session without breaking the protocol itself.

The Fake Microsoft Page That Chases the Session, Not Just the Password

Published: 22 July 2026 12:06Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: NEURALSHIELD

AiTM phishing turns a trusted login screen into a relay point for credentials, MFA output, and live session tokens, which can make account takeover look like a normal sign-in.

Kratos Falls, But the Real Target Was Never a Password

Published: 22 July 2026 10:48Category: Legal, Policy & Government CybersecurityGeo: North America / USAAuthor: ROOTBEACON

A law-enforcement takedown of the Kratos phishing kit underscores a harder truth for cloud defenders: attackers are increasingly chasing live Microsoft 365 sessions, not just login credentials.

Procurement Emails Became the Bait in a Session-Theft Campaign Against Microsoft 365

Published: 22 July 2026 10:37Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

AiTM phishing can turn a routine vendor request into a live browser hijack, letting attackers reuse an authenticated Microsoft 365 session even after MFA is completed.

Microsoft Turns Sovereign AI Into a Distribution Strategy, Not Just a Promise

Published: 22 July 2026 04:03Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: SECPULSE

The expanded Microsoft-Mistral partnership shows how enterprise AI is shifting toward regulated deployments, local control, and model choice across cloud, edge, and disconnected environments.

SharePoint’s Newest RCE Warning Exposes the Cost of Slow Patch Cycles

Published: 21 July 2026 18:24Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A critical deserialization flaw in Microsoft SharePoint Server has moved from patch note to active-risk territory, reminding defenders how fast a single missed update can become an entry point.