EHA
Microsoft AI researchers accidently Leaked 38TB of secrets, private keys, and passwords.

Microsoft AI Researchers Leaked 38TB of Secrets, Private Keys, & Passwords

In a recent incident, the Microsoft AI research team inadvertently exposed a staggering 38 terabytes of private data on their GitHub repository.  This exposure resulted from the misconfiguration of an Azure feature known as SAS...
Windows Update Addressed 2 Zero-Days and 52 Other Vulnerabilities

Windows Update Addressed 2 Zero-Days and 52 Other Vulnerabilities

Microsoft has released its Patch Tuesday update, which includes 59 vulnerabilities along with two Zero-Days. The severity for these vulnerabilities ranges from 4.3 (Medium) to 8.8 (High).  Categories of the vulnerabilities patched include Information Disclosure...
Top 20 Most Exploited Vulnerabilities – Hackers are Particularly Drawn to Microsoft’s Products

Top 20 Most Exploited Vulnerabilities: Microsoft Products Draw Hackers

Finding and patching the open vulnerabilities in today's threat landscape is one of the utmost priorities for security researchers and analysts. Identifying weaponized high-risk CVEs actively targeted by Threat Actors and ransomware in the vast...
Hackers Use Weaponized LNK Files to Exploit Microsoft Connection 03Manager Profile

Hackers Use Weaponized LNK Files to Exploit Microsoft Connection Manager Profile

Threat actors have shifted from using malicious macros to malicious LNK files for initial access. This is due to Microsoft's announcement in 2022 to disable macros by default for Office documents downloaded from unknown...
Mass phishing campaign utilizing QR codes to Steal Employees Microsoft credentials

Attackers Weaponizing QR Codes to Steal Employees Microsoft Credentials

A recent discovery highlights a significant QR code phishing campaign that targets Microsoft credentials across various industries.  Notably, a major energy company based in the US is at the forefront of this attack, underscoring the...
Hackers Leverages Teams Chat to Steal Credentials from a Targeted Organization

Hackers Leverages Teams Chat to Steal Credentials from a Targeted Organization

Microsoft Threat intelligence identifies Midnight Blizzard (previously tracked as NOBELIUM) as a highly targeted social engineering attack. The attacker uses compromised Microsoft 365 tenants owned by small businesses to create new domains that appear as...
Hackers Exploit Windows Search

Hackers Exploit Windows Search Feature to Execute Malware on Infected Systems

Malware authors persistently seek novel approaches to exploit unsuspecting users in the active cyber threat landscape. To easily locate all the available files, folders, and other items on your Windows system, Microsoft Windows OS offers...
Microsoft Azure AD Signing Key

Microsoft Struggling to Find How Hackers Steal the Azure AD Signing Key

China's Storm-0558 hacked 25 organizations, including government agencies, using fake tokens for email access, aiming at espionage since May 15, 2023. However, Storm-0558's campaign was blocked by Microsoft without affecting other environments. Not only that...
Microsoft July Security Update

6 Actively Exploited Zero-Days and 132 Flaws Patched – Microsoft Security Update

A total of 132 new security flaws in Microsoft's products were patched, including six zero-day issues that the company claimed were being actively used in the wild. Nine of the 130 vulnerabilities have a severity rating...
New File Analysis Add-on with Microsoft 365 Defender Enable Deeper Insights

New File Analysis Add-on with Microsoft 365 Defender Enable Deeper Insights

Microsoft has taken another step towards security which has revolutionized the way security professionals use Microsoft 365 Defender across devices as well as cloud applications. This time they have pivoted the process of examining...

Unified Endpoint Management

EHA

Managed WAF

Website

Latest News