Articles tagged "Microsoft"

Found 196 articles

Microsoft is currently developing a security patch for a zero-day vulnerability known as 'ShieldBreak,' which was disclosed last week by researcher Nightmare Eclipse. This vulnerability is tracked as CVE-2026-69414 and poses a significant risk, as it can potentially allow attackers to exploit Microsoft Defender, an essential security tool for many users and organizations. The information about this vulnerability is particularly concerning because it could be leveraged by cybercriminals to bypass security measures, compromising systems and data. Microsoft is urging users to stay vigilant while they work on a fix to mitigate the threat. As the situation develops, it’s crucial for users of Microsoft Defender to monitor for updates and implement any recommended patches as soon as they are available.

Read Original

A cybercriminal has claimed to have stolen millions of records from several Fortune 500 companies, including McDonald’s, Tata Consultancy Services (TCS), and Vodafone. This incident raises serious concerns about data security among major corporations, especially those using cloud services like Microsoft Azure. The attackers have not disclosed how they gained access to these records, but the scale of the breach suggests a significant vulnerability. If these claims are verified, it could lead to severe repercussions for the affected companies, including legal action and loss of customer trust. Companies need to reassess their data protection measures to prevent similar incidents in the future.

Read Original
Actively Exploited

Mustang Panda, also known as HoneyMyte, has enhanced its CoolClient backdoor by deploying a signed kernel-mode driver that can conceal processes, files, and network activity. This upgrade makes it significantly harder for security software to detect and remove the malware from infected Windows systems. Kaspersky's recent analysis indicates that this new variant of CoolClient deepens the malware's integration into the operating system, raising concerns for users and organizations relying on Windows. The implications are serious, as this could allow attackers to maintain prolonged access to compromised systems while evading detection. Users and organizations need to remain vigilant and implement security measures to protect against this evolving threat.

Read Original

The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its catalog of exploited vulnerabilities. These include a heap inspection flaw in Cisco Secure Firewall (CVE-2026-20349), a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a critical SQL injection vulnerability in Metabase (CVE-2026-72898). These flaws could allow attackers to exploit systems running affected software, potentially leading to unauthorized access or data breaches. Organizations using these products need to take immediate action to protect their systems. Awareness and prompt updates are essential to mitigate the risks associated with these vulnerabilities.

Read Original

A significant vulnerability in Microsoft SharePoint, tracked as CVE-2026-55040, is being actively exploited by attackers. This flaw, which allows for the bypassing of authentication and the impersonation of users, can lead to unauthorized access to files and the ability to alter data. Microsoft issued a patch for this vulnerability during its July 2026 Patch Tuesday updates, but the release of proof-of-concept exploit code by Rapid7 has prompted immediate exploitation in the wild. Organizations using SharePoint should prioritize applying the provided security updates to protect against potential data breaches and unauthorized modifications. The situation highlights the ongoing risks associated with unpatched vulnerabilities, especially when exploit tools become publicly available.

Read Original

Wireshark has released version 4.6.8 to address 28 security vulnerabilities, with nine of these affecting file parsers that process saved capture files. These vulnerabilities could be exploited simply by opening a maliciously crafted capture file, which means an attacker does not need direct access to the network. The affected file parsers include formats like pcapng, Endace ERF, and several others, specifically on Windows systems. This update is critical for users of Wireshark, as it helps prevent potential exploitation that could compromise sensitive data or system integrity. Users are urged to update to the latest version to mitigate these risks.

Read Original

A new zero-day exploit called 'ShieldBreak' has been released by Nightmare Eclipse, targeting Microsoft Defender. This vulnerability grants attackers SYSTEM privileges, potentially allowing them to take full control of affected systems. Users and organizations running Microsoft Defender should be particularly vigilant, especially since this exploit emerged shortly after the August 2026 Patch Tuesday updates. The existence of such a vulnerability is concerning as it can lead to significant security breaches if not addressed promptly. Companies need to ensure their systems are up to date and monitor for any unusual activity that could indicate exploitation.

Read Original

In August 2026, Microsoft released patches addressing over 400 vulnerabilities, including a serious zero-day exploit identified as CVE-2026-68820. This particular flaw is a use-after-free vulnerability affecting the Windows Ancillary Function Driver for WinSock (AFD.sys), which could allow a low-privileged local attacker to gain elevated privileges to the SYSTEM level. This means that attackers with local access could potentially execute malicious applications to take control of affected systems. The urgency of this update is underscored by the fact that the vulnerability is already being exploited in the wild. Users and organizations relying on Windows systems should prioritize applying these updates to mitigate potential risks.

+1 more
Read Original

A security researcher known as Chaotic Eclipse has released a proof of concept (PoC) for a new zero-day vulnerability named ShieldBreak, affecting Microsoft Defender. This vulnerability successfully bypasses the previously issued patch for CVE-2026-50656, known as RoguePlanet, which was intended to address a race condition. If exploited, ShieldBreak could allow attackers to execute code with SYSTEM-level privileges on affected systems. This presents a serious risk to users of Microsoft Defender, as the flaw can potentially compromise the security of their devices. Companies using Microsoft Defender should take immediate action to assess their systems and apply necessary security measures to mitigate this risk.

Read Original

A security researcher known as Chaotic Eclipse has released a proof-of-concept (PoC) for a serious zero-day vulnerability dubbed ShieldBreak, affecting Microsoft Defender for Windows. This vulnerability allows attackers to bypass the existing patch for CVE-2026-50656, also known as RoguePlanet, which has a CVSS score of 7.8, indicating a significant security risk. The flaw could enable unauthorized access with SYSTEM privileges, putting users' systems at risk. This discovery is crucial as it highlights the weaknesses in Microsoft Defender's security measures, potentially exposing millions of users to exploitation. Companies using Microsoft Defender should remain vigilant and apply any available patches while monitoring for any signs of exploitation.

Read Original

Microsoft's August Patch Tuesday updates address several vulnerabilities, with CVE-2026-62878 standing out due to its severity. This remote code execution vulnerability in Windows DNS Server has a high CVSS score of 9.8 and can be exploited without user interaction. This means attackers could potentially take control of affected systems easily, posing a significant risk to organizations relying on Windows DNS servers for their operations. It’s crucial for system administrators to prioritize applying this patch to protect their networks from potential exploitation. The updates are part of Microsoft's ongoing efforts to enhance security across its products, but this particular flaw underscores the importance of timely patch management.

Read Original

Microsoft has released its monthly security updates, addressing a total of 398 vulnerabilities, including a serious zero-day flaw that is currently being exploited in attacks. This particular vulnerability, tracked as CVE-2026-68820, affects a core Windows kernel driver responsible for network socket operations. Attackers who already have code running on a targeted machine can exploit this flaw to gain elevated privileges, potentially allowing them to execute commands with SYSTEM-level access. Given the active exploitation, users and organizations should prioritize applying the patch to mitigate the risk of unauthorized access. The patch is crucial for maintaining system security and preventing further attacks.

Read Original

Researchers have discovered a serious vulnerability in Microsoft SharePoint that allows unauthorized access to servers, including administrative functions, without a valid account. This flaw, known as CVE-2026-55040, has a CVSS score of 9.1, indicating its severity. It affects various versions of SharePoint, specifically SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. The researchers utilized an AI agent to help identify this exploit chain, which raises concerns about the potential for widespread abuse. Organizations using these SharePoint versions should take immediate action to secure their systems to prevent unauthorized access.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, indicating they are actively exploited in the wild. The vulnerabilities include a heap inspection flaw in Cisco Secure Firewall Adaptive Security Appliance (CVE-2026-20349), a use-after-free vulnerability in Microsoft Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a SQL injection vulnerability in Metabase (CVE-2026-72898). These vulnerabilities pose significant risks, especially to federal agencies, prompting CISA to emphasize the need for rapid remediation of high-risk vulnerabilities. While the Binding Operational Directive 26-04 applies specifically to federal agencies, CISA encourages all organizations to adopt similar risk-based approaches to vulnerability management. Organizations aware of other exploited vulnerabilities can submit them for potential inclusion in the KEV Catalog.

Read Original

Microsoft Threat Intelligence has reported that a group known as Storm-1175, which is believed to operate from China, has exploited an authentication-bypass vulnerability (CVE-2026-18577) in N-able's N-central remote monitoring and management tool. This exploitation allowed the attackers to gain initial access to systems and subsequently deploy a new ransomware variant called StormEncryptor. Organizations using N-central are at risk, as the vulnerability could lead to significant data loss and operational disruption. The incident emphasizes the importance of monitoring for vulnerabilities in remote management tools, as they can be entry points for cybercriminals. Companies should ensure they are using the latest security updates and patches to protect against such threats.

Read Original
PreviousPage 2 of 14Next