Articles tagged "Microsoft"

Found 196 articles

A China-based cyber operation known as JadeProx has been identified targeting government, healthcare, and education sectors in Asia and Latin America. Researchers from Group-IB discovered an exposed server on Alibaba Cloud in Singapore that was linked to these attacks. The operation utilizes a new Windows loader called TriBack Loader, which had not been documented before. Although the server was offline by the time of the report in mid-April 2026, the implications of these attacks are significant, as they threaten sensitive information and operations within critical public services. Organizations in the affected regions need to bolster their security measures to defend against such sophisticated threats.

Read Original

As artificial intelligence becomes more integrated into daily business operations, companies are facing challenges in managing its use, particularly with what is known as 'Shadow AI.' This refers to the AI tools and applications that employees adopt without formal approval or oversight from their organizations. The rapid adoption of these tools, often outpacing the company’s governance capabilities, raises significant security concerns. Employees are using AI for various tasks—from drafting emails to analyzing data—which can expose sensitive information or lead to compliance issues. Companies need to establish clear policies and oversight mechanisms to mitigate the risks associated with unregulated AI usage, ensuring that security and data protection measures keep up with this technological shift.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog due to evidence of active exploitation. The vulnerabilities include CVE-2026-16232, which affects Check Point SmartConsole and involves improper authentication, and CVE-2026-50522, a deserialization issue in Microsoft SharePoint. These vulnerabilities are significant risks, especially for federal agencies, as they can allow attackers to gain total control over the affected systems. CISA's Binding Operational Directive (BOD) 26-04 mandates that federal agencies prioritize rapid remediation of such high-risk vulnerabilities. While this directive specifically applies to federal agencies, CISA encourages all organizations to adopt similar risk-based approaches to vulnerability management and remediation.

Read Original

Attackers are actively exploiting a serious remote code execution vulnerability in Microsoft SharePoint, identified as CVE-2026-50522. This vulnerability allows them to extract the IIS machine keys from on-premise SharePoint servers, enabling long-term access to the compromised systems. Following the release of public exploit code, researchers from WatchTowr reported successful attacks occurring just hours later. Companies using on-premise SharePoint installations need to be particularly vigilant, as the stolen machine keys can facilitate ongoing unauthorized access. It's crucial for organizations to patch this vulnerability promptly and take additional measures to secure their machine keys to prevent future exploitation.

Read Original

A serious remote code execution (RCE) vulnerability in Microsoft SharePoint, identified as CVE-2026-50522, is currently being exploited by attackers. This vulnerability has a CVSS score of 9.8, indicating its severity. It was patched during Microsoft's July 2026 Patch Tuesday, but following the release of public proof-of-concept (PoC) exploit code, researchers from watchTowr have observed active exploitation in the wild. Organizations using SharePoint need to ensure they have applied the latest updates to protect against potential breaches. The situation underscores the urgency for companies to stay current on security patches to mitigate risks associated with known vulnerabilities.

Read Original
Actively Exploited

Hackers are taking advantage of a serious vulnerability in Microsoft SharePoint, identified as CVE-2026-50522, which allows them to steal machine keys. This means that even if the affected servers are patched, attackers can still maintain access to these systems. The flaw is critical, and its exploitation poses a significant risk to organizations using SharePoint, potentially leading to unauthorized access to sensitive information. Companies using SharePoint should take immediate action to secure their systems and monitor for any suspicious activity. The ongoing exploitation of this vulnerability highlights the need for vigilance in securing enterprise software against such threats.

Read Original
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

The Hacker News

Actively Exploited

A serious vulnerability in Microsoft SharePoint Server, identified as CVE-2026-50522, is currently being exploited in the wild. This flaw, which has a CVSS score of 9.8, allows attackers to execute arbitrary code on affected systems through deserialization of untrusted data. The vulnerability was patched by Microsoft during its July 2026 Patch Tuesday update but has since been targeted by malicious actors. Organizations using SharePoint need to prioritize applying the latest security updates to protect against potential unauthorized access and exploitation. It's crucial for administrators to stay vigilant and monitor their systems for any signs of compromise.

Read Original

Microsoft has issued an out-of-band update, KB5121767, to address a shutdown issue affecting certain Dell PCs that arose after the installation of July 2026 Windows 11 security updates. Users reported that their devices were unexpectedly shutting down, which raised concerns about system stability and user productivity. This fix specifically targets Dell systems, indicating that the problem may be linked to specific hardware configurations. Users of affected Dell PCs are encouraged to install this update to prevent further shutdowns and ensure their systems operate correctly. This incident serves as a reminder of the complexities involved in software updates, especially when they interact with various hardware.

Read Original

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included new vulnerabilities in its Known Exploited Vulnerabilities catalog, specifically targeting the KNX Protocol Connection Authorization Option 1 from the KNX Association and various flaws related to Oracle products. This update is crucial as it indicates that these vulnerabilities could be actively exploited by attackers, posing risks to organizations using affected systems. The inclusion of these vulnerabilities serves as a warning to IT departments and security teams to prioritize patching and mitigation efforts. Notably, CISA also added vulnerabilities from SonicWall and Microsoft to the catalog, emphasizing the ongoing need for vigilance in cybersecurity practices. Companies should review their systems and apply necessary updates to safeguard against potential attacks.

Read Original
Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Microsoft SharePoint Server to its list of Known Exploited Vulnerabilities. This flaw, identified as CVE-2026-58644, has a high severity score of 9.8, indicating that it poses a significant risk. Federal Civilian Executive Branch agencies are mandated to implement necessary patches by July 19, 2026. The vulnerability involves a deserialization issue that could allow attackers to execute remote code on affected systems, making it crucial for organizations using SharePoint to take immediate action. By addressing this vulnerability, agencies can help prevent potential exploitation by malicious actors.

Read Original
Actively Exploited

The Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities to its Known Exploited Vulnerabilities Catalog due to evidence that they are being actively exploited. The vulnerabilities include two related to Fortinet's FortiSandbox, identified as CVE-2026-25089 and CVE-2026-39808, both of which are OS command injection flaws. The third vulnerability, CVE-2026-58644, affects Microsoft SharePoint and involves the deserialization of untrusted data. These vulnerabilities present serious risks, especially to federal agencies, which are urged to prioritize their remediation as mandated by CISA’s Binding Operational Directive 26-04. While this directive applies specifically to federal civilian agencies, CISA encourages all organizations to adopt similar practices for managing vulnerabilities. Organizations are also invited to report any exploited vulnerabilities not currently listed in the KEV Catalog.

Read Original

Researchers have identified vulnerabilities in older UEFI shim bootloaders signed by Microsoft, which could allow attackers to bypass Secure Boot protections on affected systems. This issue is significant because it affects a wide range of devices, regardless of the operating system they run. Essentially, if a device uses these outdated bootloaders, it may be at risk of being compromised. The implications are serious, as Secure Boot is designed to ensure that only trusted software runs during the system's startup process. Users and organizations should review their systems for these vulnerabilities and take appropriate action to mitigate the risks.

Read Original
Zoom Fixes CVE-2026-53412, a Critical Account Takeover Bug

Security Affairs

Zoom has identified and patched a serious vulnerability in its Windows applications, labeled CVE-2026-53412, which carries a CVSS score of 9.8. This flaw allows attackers to take control of user accounts without needing any authentication, posing a significant risk to users of older versions of the Workplace and Windows VDI Client. The vulnerability primarily affects organizations using these outdated versions, making it essential for them to update promptly. The potential for account takeover could lead to unauthorized access to sensitive information, making this a critical security issue for affected users. Zoom's quick response to fix this vulnerability is crucial to protect its user base from potential exploitation.

Read Original

Zoom has addressed a serious security flaw in its Windows applications that could allow attackers to take over user accounts. This vulnerability, identified as CVE-2026-53412, has a high severity score of 9.8, indicating its potential impact. The flaw affects several Zoom products, including the Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows. Users of these applications are at risk, making it crucial for them to apply the necessary updates. By patching this vulnerability, Zoom aims to protect its users from unauthorized access and potential misuse of their accounts.

Read Original

A new zero-day vulnerability in Windows, dubbed 'LegacyHive', has been disclosed by a researcher known as Nightmare Eclipse. To mitigate the risk of immediate exploitation, the researcher has stripped the proof-of-concept exploit from public access. This vulnerability could potentially allow attackers to execute arbitrary code on affected systems, putting users and organizations at risk. Windows users and administrators should be particularly vigilant as they await further details and patches. The situation is evolving, and users are advised to stay updated on any security advisories related to this vulnerability.

Read Original
PreviousPage 4 of 14Next