Výsledky hledání

výrobce: Microsoft v celém archivu

Různé zkratky a hodnoty pod každou zprávou mají svoji legendu — pokud na údaji postojíte myší. Některé jsou klikatelné. Typicky CVE.

zrušit filtry CZ · EN/orig

629 karet z 647 položek · strana 10 z 11

29

2

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in the United States. UNC3753 leverages voice phishing (vishing) and social engineering deception…

Google Microsoft Zoom AnyDesk finance obrana US

Mandiant / Google TI ·

5

VerdantBamboo: Just Another BRICKSTORM in the Firewall

In September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The virtual machine was an Egnyte Storage Sync system, which is designed to facilitate syncing local on-premise files with the cloud. Volexity discovered that instead of connecting to a domain affiliated with Egnyte, the appliance was connecting to a threat-actor-controlled domain behind Cloudflare IP…

Egnyte Microsoft Synology Cloudflare US

Volexity ·

1

1

Kritická a dosud neopravená zranitelnost v prohlížečích Chromium umožňuje zneužití zařízení

Google omylem zveřejnil funkční exploit na dosud neopravenu zranitelnost v jádru Chromium, která existuje už zhruba tři a půl roku a ovlivňuje prohlížeče jako Google Chrome, Microsoft Edge, Brave či Opera. Útok lze spustit pouhou návštěvou škodlivé stránky a umožňuje vytvořit skryté trvalé spojení přes funkci Background Fetch (stahování na pozadí), čímž může zařízení sloužit jako proxy, součást botnetu nebo k omezenému sledování aktivity (bez přímého přístupu k datům v systému). Riziko spočívá…

Google Microsoft Brave Opera CZ

CSIRT.CZ (CZ.NIC) ·

1

5

CVE-2026-45585 Windows BitLocker Security Feature Bypass Vulnerability

Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available.

EPSS 0.01 CVE-2026-45585 Microsoft US

Microsoft Security ·

1

Pwn2Own Berlin 2026: Day Three Results and Master of Pw

Following two days of intense competition, Day Three of Pwn2Own Berlin 2026 brought the curtain down on an incredible event. Security researchers delivered their final exploits, pushing enterprise systems to the limit one last time as the race for Master of Pwn came to a close.Day Three added to an already historic event, bringing the final totals to $1,298,250 awarded for 47 unique 0-day vulnerabilities across three days of competition. DEVCORE claimed the title of Master of Pwn with a…

Red Hat Microsoft OpenAI VMware US

ZDI Blog ·

6

Welcome to BlackFile: Inside a Vishing Extortion Operation

Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671…

Microsoft Okta US

Mandiant / Google TI ·

Pwn2Own Berlin 2026 - Day Two Results

Day Two of Pwn2Own Berlin 2026 and the stakes continue to rise! Security researchers are back on the Pwn2Own stage, pushing enterprise systems to their limits as the competition heats up. More exploits, more surprises, and more standout moments are unfolding, so follow along here for live updates as the race for Master of Pwn intensifies. There were plenty of big targets on the schedule today, including SharePoint, Exchange, and Safari.Following an action-packed Day One where $523,000 was…

Microsoft Apple Red Hat Mozilla US

ZDI Blog ·

Riasztás Microsoft termékeket érintő sérülékenységekről – 2026. május

Tisztelt Ügyfelünk! A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet (NBSZ NKI) riasztást ad ki a Microsoft szoftvereket érintő kritikus kockázati besorolású sérülékenységek kapcsán, azok súlyossága, kihasználhatósága és a szoftverek széleskörű elterjedtsége miatt. A Microsoft tárgyhavi biztonsági csomagjában összesen 137 különböző biztonsági hibát javított, ugyanakkor a javítások között nem szerepelt olyan nulladik napi (zero-day) sebezhetőség, amelyet a […]

Microsoft HU

NKI Maďarsko ·

[Màj] Vulnérabilité dans Microsoft Exchange Server (15 mai 2026)

[Mise à jour du 11 juin 2026] Le 9 juin 2026, Microsoft a publié des versions correctives. [Publication initiale] Le 14 mai 2026, Microsoft a publié un avis de sécurité concernant la vulnérabilité CVE-2026-42897 affectant Exchange Server. Elle permet à un attaquant non authentifié de provoquer...

KEV ✓ EPSS 0.70 CVE-2026-42897 Microsoft FR US 2 zdrojů

CERT-FR – alerty · Microsoft Security

1

Pwn2Own Berlin 2026 - Day One Results

Welcome to Day One of Pwn2Own Berlin 2026! Today, 22 entries took the Pwn2Own stage to target AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products, as the world’s top security researchers push technology to its limits. Exploits, surprises, and breakthrough discoveries are unfolding.After Day One, we awarded $523,000 for 24 unique 0-days! DEVCORE is currently in the lead for Master of Pwn, but a pack of teams are right on their heels. Stay tuned tomorrow for…

Microsoft OpenAI NVIDIA Oracle US

ZDI Blog ·

2

Pwn2Own Berlin 2026: The Full Schedule

Willkommen! (Welcome!) Pwn2Own Berlin 2026 has arrived at OffensiveCon, and the world’s top security researchers are ready. This year’s enterprise-focused competition features AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products.Earlier today, we held the random draw to determine attempt order. Below is the official schedule. All times are Berlin local time (CET) and may change as the competition progresses. Check back for live updates.In case you missed it…

Microsoft Oracle OpenAI Mozilla US

ZDI Blog ·

6

The May 2026 Security Update Review

I’m currently in Berlin helping set up for Pwn2Own Berlin, but that doesn’t stop Patch Tuesday from coming, and it’s another big one. At least nothing is listed as being in the wild – for now. Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. Due to technical difficulties, there will not be a video companion for this month.Adobe Patches for May 2026For May, Adobe released 10 bulletins addressing 52 unique CVEs in…

Microsoft Adobe US

ZDI Blog ·