Wednesday, September 16, 2026
Follow on LinkedIn

Microsoft

Microsoft Defender for Office 365 Adds New Prompt Injection Protection

Microsoft has introduced a new capability in Defender for Office 365 to protect against prompt injection attacks, which target AI-powered email workflows, such as Microsoft 365 Copilot. This update reflects the evolving threat landscape, where attackers increasingly attempt to manipulate...

Microsoft to Discontinue Podcasts Option on Copilot and to Delete Contents

Microsoft will retire the Podcasts feature in its consumer Copilot app on August 18, 2026, permanently removing access to both the creation tool and all previously generated podcast content. This change affects both free and paid Copilot users, including...

Microsoft Releases KB5121767 Out-of-Band Update to Fix Dell USB-C Compatibility Bug

Microsoft has released the out-of-band update KB5121767 for Windows 11 to resolve a system performance and compatibility issue affecting a limited number of Dell devices. The update addresses issues with the Intel Innovation Platform Framework (Intel IPF) driver following recent Windows updates. Released...

CISA Warns of Microsoft SharePoint Server Vulnerability Actively Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-56164, to its Known Exploited Vulnerabilities catalog due to confirmed active exploitation. This flaw affects on-premises deployments of Microsoft SharePoint Server and...

Microsoft Active Directory Services 0-Day Vulnerability Actively Exploited in the Wild

Microsoft has released security updates for CVE-2026-56155, an actively exploited elevation-of-privilege vulnerability in Active Directory Federation Services (AD FS). This flaw allows an authenticated local attacker with low privileges to gain administrator-level access on affected systems. CVE-2026-56155 stems from insufficient granularity...

Forg365 Phishing Platform Using AI to Attack Microsoft 365 Accounts

Forg365 is a phishing-as-a-service platform that targets Microsoft accounts, combining AI-powered phishing, session theft, and post-compromise mailbox access in a single operator panel The platform is reportedly distributed through Telegram, where criminals can access a 30-day trial, pay about per...

Microsoft Releases Patch for RoguePlanet Defender Zero-Day Vulnerability

Microsoft has released security updates to address a newly disclosed zero-day vulnerability in Microsoft Defender, publicly referred to as “RoguePlanet.” The flaw, tracked as CVE-2026-50656, affects the Microsoft Malware Protection Engine and could allow attackers to gain elevated privileges on...

Microsoft Exchange SSRF Vulnerability Details Released Along With Public PoC Exploit

Security researchers from HawkTrace have disclosed technical details of a high-severity server-side request forgery (SSRF) vulnerability in Microsoft Exchange, tracked as CVE-2026-45504. The flaw, which carries a CVSS score of 8.8, allows authenticated, low-privileged users to read arbitrary files from...

Critical Flaws Double as Elevation of Privilege Dominates the Cyber Threats – Analysis of Microsoft Vulnerabilities Report 2026

Microsoft's vulnerability landscape just sent a mixed signal that every security team needs to understand. According to the newly released Microsoft Vulnerabilities Report 2026 — the 13th annual edition published by BeyondTrust — the total number of disclosed Microsoft...

Microsoft 365 Apps RCE Vulnerability Exploited Using a Malicious Excel File

Microsoft has disclosed a critical remote code execution vulnerability in its Office ecosystem that can be exploited through a malicious Excel file. The vulnerability, tracked as CVE-2025-60727, affects multiple versions of Microsoft Office and underscores the continued risk posed by...

Latest News

Latest News