Výsledky hledání

výrobce: Microsoft× v celém archivu zrušit filtry

1035 karet z 1072 položek · strana 11 z 18 CZ · EN/orig

8

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

OverviewRapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month.Our…

KEV ✓ EPSS 0.51 CVSS 8.1 CVE-2026-55040 CVE-2026-63520 Microsoft veřejná správa finance US

· Rapid7 · CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

Overview of the attack In July 2026, Kaspersky experts detected a new attack by the Head Mare group. Previously, we classified them as hacktivists, but now we define them as an APT group due to the sophistication of their TTPs and the absence of destructive activity (encryption, wiping) in the targeted infrastructures. In this latest campaign, the attackers exploited a chain of vulnerabilities in the TrueConf video conferencing server and replaced the original TrueConf client installers with…

TrueConf Kaspersky Microsoft energetika výroba a průmysl doprava telekomunikace RU

· Securelist (Kaspersky) · Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability CVE-2026-72898 Metabase SQL Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious…

KEV ✓ EPSS 0.94 CVE-2026-20349 CVE-2026-68820 CVE-2026-72898 Cisco Microsoft Metabase veřejná správa US

· CISA Advisories · CISA Adds Three Known Exploited Vulnerabilities to Catalog

Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection

Project CAV3RN is a modular espionage framework used against targets in Israel. This report expands on two earlier publications: the first was published in June 2026 as part of our Kaspersky Threat Intelligence Reporting service, and the second was published on Securelist the following month, further documenting the framework’s evolving architecture and C2 capabilities. Continued tracking of this cluster in early August 2026 uncovered several previously undocumented components that expanded the…

Microsoft Google obrana RU

· Securelist (Kaspersky) · Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection

2

Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise 

Security teams are being asked to defend a growing attack surface with fewer people and around the clock, against threat actors who never take a night off. As cyberattackers increasingly use AI to launch and scale campaigns, the volume, speed, and sophistication of threats continue to rise. Closing that gap takes more than tooling. It takes a partner that pairs a leading security platform with scaled intelligence and human experts who can act on your behalf at any hour. That’s exactly what…

Microsoft US

tg: propagace tp: AI

· Microsoft Security Blog · Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise 

IT threat evolution in Q2 2026. Non-mobile statistics

IT threat evolution in Q2 2026. Non-mobile statistics IT threat evolution in Q2 2026. Mobile statistics The statistics in this report are based on detection verdicts returned by Kaspersky products unless otherwise stated. The information was provided by Kaspersky users who consented to sharing statistical data. Quarterly figures In Q2 2026: Kaspersky products blocked nearly 400 million attacks that originated with various online resources. Web Anti-Virus responded to 52 million unique links.…

KEV ✓ · ransomware EPSS 0.84 CVE-2026-33825 CVE-2026-50751 CVE-2026-50752 Kaspersky Microsoft Check Point Palo Alto Networks RU

· Securelist (Kaspersky) · IT threat evolution in Q2 2026. Non-mobile statistics

1

Payroll Pirates Phishing Campaign Targets Microsoft 365 Financial Workflows (Campaign)

The attack begins with phishing emails impersonating voicemail notifications that direct victims through a multi-stage redirect chain abusing legitimate services, including Google Meet, Google Ads infrastructure, and Amazon S3, before ultimately reaching an attacker-controlled...

Microsoft finance US

· Wiz Research · Payroll Pirates Phishing Campaign Targets Microsoft 365 Financial Workflows (Campaign)

11

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

Written by: Tyler McLellan, Austin Larsen Introduction Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multiple extortion fronts including Redact, Pink, Helix, and Falcon. UNC6671 continues to rely on voice…

Microsoft Okta finance US

· Mandiant / Google TI · UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

1

​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)

As organizations adopt AI, they must secure both cloud and AI environments through a unified security control plane as their attack surface expands. Because modern applications and AI workloads are built and run in the cloud, security teams must understand which exposures matter most, prioritize what can truly be exploited, and reduce risk across cloud infrastructure, applications, identities, data, and AI systems in one place. Modern IT estates now span multiple clouds and on-premises systems,…

Microsoft US

tg: propagace tp: AI

· Microsoft Security Blog · ​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)

2

Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps

The calculus of cybersecurity has changed. AI is reshaping how organizations build, deploy, operate, and defend digital systems. AI-powered development tools, agents, and autonomous workflows are accelerating innovation but they are also introducing new attack surfaces, new trust boundaries, and new security challenges. Microsoft has long helped organizations secure their digital estates using Zero Trust principles. That leadership was recently recognized by KuppingerCole analysts, which named…

Microsoft US

tg: novinka v produktu tg: návod tg: propagace tp: AI

· Microsoft Security Blog · Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps

128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 

In this article What is device isolation?Case study: QNETAttack chain overviewMITRE ATT&CK techniques observedReferencesLearn more Microsoft Defender’s attack disruption now includes device isolation, a new response action that extends autonomous protection directly to compromised endpoints. At QNET, an attacker initiated a multi-stage attack using a legitimate Windows tool on a compromised endpoint to retrieve a malicious remote payload–a classic living-off-the-land (LOL) technique that often…

Microsoft obchod US

tg: incident tg: rozbor tg: propagace tp: malware tp: ransomware

· Microsoft Security Blog · 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 

1

3rd August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported that drinking water safety was not affected. While the attack was not officially attributed, federal…

KEV ✓ · ransomware EPSS 0.87 CVSS 9.8 CVE-2026-20316 CVE-2026-42897 CVE-2026-59309 CVE-2026-59310 CVE-2026-59726 CVE-2026-63077 CVE-2026-66066 Cisco Broadcom JetBrains Microsoft vodárenství finance zdravotnictví telekomunikace IL

tg: incident tg: zranitelnost tg: přehled tp: phishing tp: únik dat tp: AI tp: průmyslové systémy

· Check Point Research · 3rd August – Threat Intelligence Report

4

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

In this article The CaptiveCrunch campaignStorm-2945 and Midnight BlizzardCaptiveCrunch tradecraft and toolingHow to protect against CaptiveCrunch activityMicrosoft Defender detections and hunting guidanceIndicators of compromise Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some…

Microsoft veřejná správa US

tg: varování tg: rozbor tp: malware tp: phishing tp: identita tp: špionáž

· Microsoft Security Blog · CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

CaptiveCrunch: Midnight Blizzard Hospitality Network AiTM Campaign (Campaign)

Microsoft Threat Intelligence identified CaptiveCrunch, an ongoing cyberespionage campaign conducted by Storm-2945, a subgroup of the Russian state-sponsored actor Midnight Blizzard. The campaign compromises hospitality-sector captive portal infrastructure to perform adversary...

Microsoft obchod telekomunikace US

· Wiz Research · CaptiveCrunch: Midnight Blizzard Hospitality Network AiTM Campaign (Campaign)

1

​​​​What’s new in Microsoft Security: July 2026

Every organization needs security that protects end to end with the speed and scale of AI. Microsoft’s vision is simple: security should be ambient and autonomous, just like the AI it protects. As organizations scale AI and expand across environments, security teams need protection that covers every surface. This month’s updates help security and IT teams secure their AI environments, use AI to defend at speed and scale, and strengthen the foundations that AI-powered operations depend on.…

Microsoft US

tg: novinka v produktu tg: propagace tp: AI tp: identita

· Microsoft Security Blog · ​​​​What’s new in Microsoft Security: July 2026

2

Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here

Elastic automatically translates your Microsoft Sentinel detection rules into Elastic Security. Export your Scheduled and Near Real Time (NRT) analytics rules from Sentinel, upload them, and Elastic picks up the mapping and translation from there using an LLM you choose. Watchlists and severity mappings carry over. This is the first automatic migration path off a modern SIEM, available now in Tech Preview in 9.5, and it works across multiple cloud providers and regions so you can deploy closer…

Elastic Microsoft US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here

Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here

Elastic automatically translates your Microsoft Sentinel detection rules into Elastic Security. Export your Scheduled and Near Real Time (NRT) analytics rules from Sentinel, upload them, and Elastic picks up the mapping and translation from there using an LLM you choose. Watchlists and severity mappings carry over. This is the first automatic migration path off a modern SIEM, available now in Tech Preview in 9.5, and it works across multiple cloud providers and regions so you can deploy closer…

Elastic Microsoft US

tg: novinka v produktu tg: propagace tp: AI

· Elastic Security · Stop rewriting detection rules by hand: automatic Sentinel-to-Elastic migration is here

2

IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains

Phishing was the primary means of gaining initial access this quarter, appearing in over half of all Cisco Talos Incident Response (Talos IR) engagements – an increase from approximately a third of engagements last quarter. Attackers continued to innovate their delivery methods to evade defenses, deploying QR code-embedded PDFs to bypass traditional email gateways and hosting links on trusted cloud platforms. We also saw a spike in authentication abuse this quarter — observed in 65 percent of…

Microsoft Zoho US

· Cisco Talos · IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains

Chaos in Teams vishing

Attackers used Microsoft Teams vishing, custom malware, and remote access tools to facilitate ransomware deploymentCategories: Threat ResearchTags: Microsoft Teams, vishing, Ransomware, Chaos

Microsoft GB

· Sophos Threat Research · Chaos in Teams vishing

1

27th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping operations and affected approximately 5,000 customers. KFC Japan warned of possible shortages. Nichirei confirmed personal data theft, while the RansomHouse group claimed responsibility and published a subset of the stolen…

KEV ✓ EPSS 0.85 CVE-2025-66376 CVE-2026-16232 CVE-2026-50522 Check Point Oracle Microsoft Zimbra energetika vodárenství doprava veřejná správa IL

tg: incident tg: zneužíváno tg: přehled tp: ransomware tp: únik dat tp: AI tp: průmyslové systémy

· Check Point Research · 27th July – Threat Intelligence Report

7

2026-009: Critical Vulnerabilities in Microsoft SharePoint

[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. CERT-EU…

KEV ✓ · ransomware EPSS 0.85 CVE-2026-32201 CVE-2026-45659 CVE-2026-50522 CVE-2026-56164 CVE-2026-58644 Microsoft EU

· CERT-EU · 2026-009: Critical Vulnerabilities in Microsoft SharePoint

2

SPOJENO PŘES CVE Microsoft SharePoint Deserialization of Untrusted Data Vulnerability (CVE-2026-50522)

CISA added CVE-2026-50522 to the Known Exploited Vulnerabilities catalog. Affected product: Microsoft SharePoint. Remediation due date: 2026-07-25.

KEV ✓ EPSS 0.85 CVSS 8.1 CVE-2026-50522 Microsoft veřejná správa US

· CISA KEV · Microsoft SharePoint Deserialization of Untrusted Data Vulnerability (CVE-2026-50522) · Zero Day Initiative · ZDI-26-412: (Pwn2Own) Microsoft SharePoint Deserialization of Untrusted Data Remote Code Execution Vulnerability · Microsoft Security · CVE-2026-50522 Microsoft SharePoint Remote Code Execution Vulnerability

Multiples vulnérabilités dans Microsoft Sharepoint (22 juillet 2026)

Le 14 juillet 2026, à l'occasion de sa mise à jour mensuelle, Microsoft a publié, entre autres, des correctifs pour deux vulnérabilités critiques affectant SharePoint. Les vulnérabilités CVE-2026-50522 et CVE-2026-58644 permettent à un attaquant non authentifié d'exécuter du code arbitraire à...

KEV ✓ EPSS 0.85 CVE-2026-50522 CVE-2026-58644 Microsoft FR

· CERT-FR – alerty · Multiples vulnérabilités dans Microsoft Sharepoint (22 juillet 2026)

3

SPOJENO PŘES CVE ZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-50325.

EPSS 0.00 CVSS 7.0 CVE-2026-50325 Microsoft US

· Zero Day Initiative · ZDI-26-445: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability · Microsoft Security · CVE-2026-50325 Win32k Elevation of Privilege Vulnerability

SPOJENO PŘES CVE ZDI-26-446: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-50297.

EPSS 0.00 CVSS 7.0 CVE-2026-50297 Microsoft US

· Zero Day Initiative · ZDI-26-446: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability · Microsoft Security · CVE-2026-50297 Win32k Elevation of Privilege Vulnerability

2

20th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information, employee details, and other sensitive information submitted while requesting technical assistance. Jscrambler, a…

KEV ✓ · ransomware EPSS 0.97 CVE-2026-15409 CVE-2026-15410 CVE-2026-56155 CVE-2026-56164 CVE-2026-60137 CVE-2026-63030 Microsoft WordPress SonicWall výroba a průmysl finance IL

· Check Point Research · 20th July – Threat Intelligence Report

1

3

Begun, the Patch Wars have

Welcome to this week’s edition of the Threat Source newsletter. We all knew, to some degree or another, that this summer was going to a hot mess. I don’t mean FIFA drama or record setting heat waves. I mean the slow but steady momentum that AI frontier models were accruing for vulnerability research. If you were like me, and guesstimating exactly when that shoe would drop, my money was on the middle of summer. And... well, friends, I hate to say it, but I was right. This July’s Patch Tuesday is…

Microsoft US

tg: rozbor tg: názor tg: přehled tp: malware tp: AI

· Cisco Talos · Begun, the Patch Wars have

Riasztás Microsoft szoftverek 2026 júliusában javított sérülékenységeiről

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Microsoft szoftvereket érintő kritikus kockázati besorolású sérülékenységek kapcsán azok súlyossága, a szoftverek széleskörű elterjedtsége, valamint az egyes biztonsági hibákat érintő aktív kihasználások miatt. A Microsoft tárgyhavi biztonsági csomagjában összesen 622 különböző biztonsági hibát javított, köztük 3 db nulladik napi (zero-day) sebezhetőséget is amelyet a Microsoft […]

Microsoft HU

· NKI Maďarsko · Riasztás Microsoft szoftverek 2026 júliusában javított sérülékenységeiről

6

Patchtisdag juli 2026 – samlad information om månadens säkerhetsuppdateringar

Flera leverantörer har släppt sina månatliga säkerhetsuppdateringar för juli. Nedan finns en sammanställning av de säkerhetsuppdateringar som Cisco, Microsoft, SAP, Ivanti, Fortinet och Adobe har publicerat inför och i samband med patchtisdagen. Följ länkarna för att komma till respektive leverantörs uppdateringar. [1, 2, 3, 4, 5, 6]

Cisco Microsoft SAP Ivanti SE

· CERT-SE · Patchtisdag juli 2026 – samlad information om månadens säkerhetsuppdateringar

SPOJENO PŘES CVE ZDI-26-414: Microsoft PowerShell Help Directory Traversal Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft PowerShell. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-40400.

EPSS 0.01 CVSS 7.8 CVE-2026-40400 Microsoft US

· Zero Day Initiative · ZDI-26-414: Microsoft PowerShell Help Directory Traversal Remote Code Execution Vulnerability · Microsoft Security · CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability

SPOJENO PŘES CVE ZDI-26-415: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-49805.

EPSS 0.00 CVSS 7.0 CVE-2026-49805 Microsoft US

· Zero Day Initiative · ZDI-26-415: Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability · Microsoft Security · CVE-2026-49805 Win32k Elevation of Privilege Vulnerability

SPOJENO PŘES CVE ZDI-26-416: Microsoft Hyper-V netvsc Out-Of-Bounds Read Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Hyper-V. An attacker must first obtain the ability to execute low-privileged code within a Windows virtual machine under Hyper-V in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-54129.

EPSS 0.00 CVSS 7.8 CVE-2026-54129 Microsoft US

· Zero Day Initiative · ZDI-26-416: Microsoft Hyper-V netvsc Out-Of-Bounds Read Local Privilege Escalation Vulnerability · Microsoft Security · CVE-2026-54129 Windows Hyper-V Elevation of Privilege Vulnerability

SPOJENO PŘES CVE ZDI-26-417: Microsoft Windows ServerManager Exposed Dangerous Method Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50311.

EPSS 0.00 CVSS 7.8 CVE-2026-50311 Microsoft veřejná správa US

· Zero Day Initiative · ZDI-26-417: Microsoft Windows ServerManager Exposed Dangerous Method Local Privilege Escalation Vulnerability · Microsoft Security · CVE-2026-50311 Windows Server Elevation of Privilege Vulnerability

SPOJENO PŘES CVE ZDI-26-418: Microsoft SharePoint SPFieldMultiLineText Cross-Site Scripting Vulnerability

This vulnerability allows remote attackers to execute web requests with a target user's privileges on affected installations of Microsoft SharePoint. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2026-55126.

EPSS 0.01 CVSS 7.3 CVE-2026-55126 Microsoft US

· Zero Day Initiative · ZDI-26-418: Microsoft SharePoint SPFieldMultiLineText Cross-Site Scripting Vulnerability · Microsoft Security · CVE-2026-55126 Microsoft SharePoint Server Spoofing Vulnerability