Microsoft has introduced a new capability in Defender for Office 365 to protect against prompt injection attacks, which target AI-powered email workflows, such as Microsoft 365 Copilot.
This update reflects the evolving threat landscape, where attackers increasingly attempt to manipulate...
Microsoft will retire the Podcasts feature in its consumer Copilot app on August 18, 2026, permanently removing access to both the creation tool and all previously generated podcast content. This change affects both free and paid Copilot users, including...
Microsoft has released the out-of-band update KB5121767 for Windows 11 to resolve a system performance and compatibility issue affecting a limited number of Dell devices.
The update addresses issues with the Intel Innovation Platform Framework (Intel IPF) driver following recent Windows updates.
Released...
The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-56164, to its Known Exploited Vulnerabilities catalog due to confirmed active exploitation.
This flaw affects on-premises deployments of Microsoft SharePoint Server and...
Microsoft has released security updates for CVE-2026-56155, an actively exploited elevation-of-privilege vulnerability in Active Directory Federation Services (AD FS).
This flaw allows an authenticated local attacker with low privileges to gain administrator-level access on affected systems.
CVE-2026-56155 stems from insufficient granularity...
Forg365 is a phishing-as-a-service platform that targets Microsoft accounts, combining AI-powered phishing, session theft, and post-compromise mailbox access in a single operator panel
The platform is reportedly distributed through Telegram, where criminals can access a 30-day trial, pay about per...
Microsoft has released security updates to address a newly disclosed zero-day vulnerability in Microsoft Defender, publicly referred to as “RoguePlanet.”
The flaw, tracked as CVE-2026-50656, affects the Microsoft Malware Protection Engine and could allow attackers to gain elevated privileges on...
Security researchers from HawkTrace have disclosed technical details of a high-severity server-side request forgery (SSRF) vulnerability in Microsoft Exchange, tracked as CVE-2026-45504.
The flaw, which carries a CVSS score of 8.8, allows authenticated, low-privileged users to read arbitrary files from...
Microsoft's vulnerability landscape just sent a mixed signal that every security team needs to understand. According to the newly released Microsoft Vulnerabilities Report 2026 — the 13th annual edition published by BeyondTrust — the total number of disclosed Microsoft...
Microsoft has disclosed a critical remote code execution vulnerability in its Office ecosystem that can be exploited through a malicious Excel file.
The vulnerability, tracked as CVE-2025-60727, affects multiple versions of Microsoft Office and underscores the continued risk posed by...