Výsledky hledání

výrobce: Microsoft× v celém archivu zrušit filtry

1035 karet z 1072 položek · strana 17 z 18 CZ · EN/orig

12

2

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in the United States. UNC3753 leverages voice phishing (vishing) and social engineering deception…

Google Microsoft Zoom AnyDesk finance obrana US

· Mandiant / Google TI · Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

5

VerdantBamboo: Just Another BRICKSTORM in the Firewall

In September 2025, Volexity conducted an incident response engagement that began after suspicious network traffic was observed from a Linux-based virtual machine appliance on a customer’s network. The virtual machine was an Egnyte Storage Sync system, which is designed to facilitate syncing local on-premise files with the cloud. Volexity discovered that instead of connecting to a domain affiliated with Egnyte, the appliance was connecting to a threat-actor-controlled domain behind Cloudflare IP…

Egnyte Microsoft Synology Cloudflare US

· Volexity · VerdantBamboo: Just Another BRICKSTORM in the Firewall

1

1

Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace

Tycoon 2FA is currently the most prolific Phishing-as-a-Service (PhaaS) platform among AiTM phishing kits. First observed in August 2023 and attributed to Storm-1747 (per Microsoft Threat Intelligence), the kit provides turnkey adversary-in-the-middle (AiTM) capabilities that bypass multi-factor authentication and steal authenticated session tokens from Microsoft 365 and Google Workspace accounts. At its peak, Tycoon 2FA accounted for roughly 62% of phishing attempts blocked by Microsoft,…

Microsoft Google US

tg: varování tg: rozbor tp: phishing tp: identita

· Elastic Security · Detecting Tycoon 2FA AiTM attacks across Entra ID and Google Workspace

1

Kritická a dosud neopravená zranitelnost v prohlížečích Chromium umožňuje zneužití zařízení

Google omylem zveřejnil funkční exploit na dosud neopravenu zranitelnost v jádru Chromium, která existuje už zhruba tři a půl roku a ovlivňuje prohlížeče jako Google Chrome, Microsoft Edge, Brave či Opera. Útok lze spustit pouhou návštěvou škodlivé stránky a umožňuje vytvořit skryté trvalé spojení přes funkci Background Fetch (stahování na pozadí), čímž může zařízení sloužit jako proxy, součást botnetu nebo k omezenému sledování aktivity (bez přímého přístupu k datům v systému). Riziko spočívá…

Google Microsoft Brave Opera CZ

· CSIRT.CZ (CZ.NIC) · Kritická a dosud neopravená zranitelnost v prohlížečích Chromium umožňuje zneužití zařízení

1

5

Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again!

Three progressively compromised versions of a Microsoft-adjacent Python package deliver a full-featured infostealer that spreads through AWS and Kubernetes, exfiltrates every cloud credential it can find, and wipes disks on Israeli and Iranian systems Category: Vulnerabilities & Threats

Microsoft BE

· Aikido Security · Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again!

CVE-2026-45585 Windows BitLocker Security Feature Bypass Vulnerability

Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices. We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available.

EPSS 0.01 CVE-2026-45585 Microsoft US

· Microsoft Security · CVE-2026-45585 Windows BitLocker Security Feature Bypass Vulnerability

1

Pwn2Own Berlin 2026: Day Three Results and Master of Pw

Following two days of intense competition, Day Three of Pwn2Own Berlin 2026 brought the curtain down on an incredible event. Security researchers delivered their final exploits, pushing enterprise systems to the limit one last time as the race for Master of Pwn came to a close.Day Three added to an already historic event, bringing the final totals to $1,298,250 awarded for 47 unique 0-day vulnerabilities across three days of competition. DEVCORE claimed the title of Master of Pwn with a…

Red Hat Microsoft OpenAI VMware US

· ZDI Blog · Pwn2Own Berlin 2026: Day Three Results and Master of Pw

6

Welcome to BlackFile: Inside a Vishing Extortion Operation

Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) techniques to bypass traditional perimeter defenses and multi-factor authentication (MFA), UNC6671…

Microsoft Okta US

· Mandiant / Google TI · Welcome to BlackFile: Inside a Vishing Extortion Operation

Pwn2Own Berlin 2026 - Day Two Results

Day Two of Pwn2Own Berlin 2026 and the stakes continue to rise! Security researchers are back on the Pwn2Own stage, pushing enterprise systems to their limits as the competition heats up. More exploits, more surprises, and more standout moments are unfolding, so follow along here for live updates as the race for Master of Pwn intensifies. There were plenty of big targets on the schedule today, including SharePoint, Exchange, and Safari.Following an action-packed Day One where $523,000 was…

Microsoft Apple Red Hat Mozilla US

· ZDI Blog · Pwn2Own Berlin 2026 - Day Two Results

Riasztás Microsoft termékeket érintő sérülékenységekről – 2026. május

Tisztelt Ügyfelünk! A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet (NBSZ NKI) riasztást ad ki a Microsoft szoftvereket érintő kritikus kockázati besorolású sérülékenységek kapcsán, azok súlyossága, kihasználhatósága és a szoftverek széleskörű elterjedtsége miatt. A Microsoft tárgyhavi biztonsági csomagjában összesen 137 különböző biztonsági hibát javított, ugyanakkor a javítások között nem szerepelt olyan nulladik napi (zero-day) sebezhetőség, amelyet a […]

Microsoft HU

· NKI Maďarsko · Riasztás Microsoft termékeket érintő sérülékenységekről – 2026. május

SPOJENO PŘES CVE [Màj] Vulnérabilité dans Microsoft Exchange Server (15 mai 2026)

[Mise à jour du 11 juin 2026] Le 9 juin 2026, Microsoft a publié des versions correctives. [Publication initiale] Le 14 mai 2026, Microsoft a publié un avis de sécurité concernant la vulnérabilité CVE-2026-42897 affectant Exchange Server. Elle permet à un attaquant non authentifié de provoquer...

KEV ✓ EPSS 0.72 CVE-2026-42897 Microsoft FR US

· CERT-FR – alerty · [Màj] Vulnérabilité dans Microsoft Exchange Server (15 mai 2026) · Microsoft Security · CVE-2026-42897 Microsoft Exchange Server Spoofing Vulnerability

1

Pwn2Own Berlin 2026 - Day One Results

Welcome to Day One of Pwn2Own Berlin 2026! Today, 22 entries took the Pwn2Own stage to target AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products, as the world’s top security researchers push technology to its limits. Exploits, surprises, and breakthrough discoveries are unfolding.After Day One, we awarded $523,000 for 24 unique 0-days! DEVCORE is currently in the lead for Master of Pwn, but a pack of teams are right on their heels. Stay tuned tomorrow for…

Microsoft OpenAI NVIDIA Oracle US

· ZDI Blog · Pwn2Own Berlin 2026 - Day One Results

2

Pwn2Own Berlin 2026: The Full Schedule

Willkommen! (Welcome!) Pwn2Own Berlin 2026 has arrived at OffensiveCon, and the world’s top security researchers are ready. This year’s enterprise-focused competition features AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products.Earlier today, we held the random draw to determine attempt order. Below is the official schedule. All times are Berlin local time (CET) and may change as the competition progresses. Check back for live updates.In case you missed it…

Microsoft Oracle OpenAI Mozilla US

· ZDI Blog · Pwn2Own Berlin 2026: The Full Schedule

6

The May 2026 Security Update Review

I’m currently in Berlin helping set up for Pwn2Own Berlin, but that doesn’t stop Patch Tuesday from coming, and it’s another big one. At least nothing is listed as being in the wild – for now. Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. Due to technical difficulties, there will not be a video companion for this month.Adobe Patches for May 2026For May, Adobe released 10 bulletins addressing 52 unique CVEs in…

Microsoft Adobe US

· ZDI Blog · The May 2026 Security Update Review

CVE-2026-40367 Microsoft Word Remote Code Execution Vulnerability

The security impact for this vulnerability has been revised from Critical to Important. In addition, the CVSS vector and FAQs were modified. This change does not affect the available security updates. Customers should continue to install the recommended updates to remain protected from this vulnerability.

EPSS 0.00 CVE-2026-40367 Microsoft US

· Microsoft Security · CVE-2026-40367 Microsoft Word Remote Code Execution Vulnerability

CVE-2026-41100 Microsoft 365 Copilot for Android Spoofing Vulnerability

Added Microsoft Excel for Android, Microsoft Word for Android, Microsoft Loop for Android, Microsoft PowerPoint for Android and Microsoft OneNote for Android softwares to the Security Updates table. Customers that are running supported version of these products are encouraged to update to the indicated versions to be protected from this vulnerability.

EPSS 0.00 CVE-2026-41100 Microsoft US

· Microsoft Security · CVE-2026-41100 Microsoft 365 Copilot for Android Spoofing Vulnerability

1

1

1

CI/CD pipeline abuse: the problem no one is watching

Preamble In 2025 and 2026, we watched a pattern play out across the industry. Attackers stopped going after production servers directly and started targeting the automation that deploys to them. Compromised developer credentials, a modified workflow file, and suddenly every secret in a CI/CD environment is streaming to an attacker-controlled endpoint. We saw this play out across incidents involving major open-source projects, Fortune 500 companies, and critical infrastructure tooling. The…

GitHub GitLab Microsoft US

tg: rozbor tg: novinka v produktu tp: dodavatelský řetězec tp: AI tp: identita

· Elastic Security · CI/CD pipeline abuse: the problem no one is watching

1

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in recent years, UNC6692 relied heavily on impersonating IT helpdesk employees, convincing their victim…

Microsoft Google US

· Mandiant / Google TI · Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

2

Riasztás Microsoft termékeket érintő sérülékenységekről – 2026. április

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet (NBSZ NKI) riasztást ad ki a Microsoft szoftvereket érintő kritikus kockázati besorolású sérülékenységek kapcsán, azok súlyossága, kihasználhatósága és a szoftverek széleskörű elterjedtsége miatt.

Microsoft HU

· NKI Maďarsko · Riasztás Microsoft termékeket érintő sérülékenységekről – 2026. április

2

The April 2026 Security Update Review

It’s time once again for Patch Tuesday, and this one is huge. We’ve also got multiple exploits in the wild, which adds another layer of urgency to this month’s release. Take a break from your regularly scheduled activities, and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for April 2026For April, Adobe released 12 bulletins addressing 61 unique CVEs in…

Adobe Microsoft US

· ZDI Blog · The April 2026 Security Update Review

1

1

2026-004: Critical Vulnerability in SharePoint Exploited

On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026. Additionally, three further RCE flaws affecting Microsoft SharePoint were…

Microsoft EU

· CERT-EU · 2026-004: Critical Vulnerability in SharePoint Exploited

1

1

Announcing Pwn2Own Berlin for 2026

If you just want to read the contest rules, click here. Willkommen zurück, meine Damen und Herren, zu unserem zweiten Wettbewerb in Berlin! That’s correct (if Google translate didn’t steer me wrong). After our inaugural competition last year, Pwn2Own returns to Berlin and OffensiveCon. Outside of our shipping troubles, we had an amazing time and can’t wait to get back.Last year, we added Artificial Intelligence as a category with great results. This year, we’re expanding this and splitting it…

Microsoft VMware Adobe AWS US

· ZDI Blog · Announcing Pwn2Own Berlin for 2026

1

The March 2026 Security Update Review

I am back in the friendly confines of the Mid-South headquarters of TrendAI ZDI (a.k.a. my home office), and am all set for the third patch Tuesday of 2026. Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft.If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for March 2026For March, Adobe released eight bulletins addressing 80 unique CVEs in Adobe…

Adobe Microsoft US

· ZDI Blog · The March 2026 Security Update Review

1

Patch diff to SYSTEM

Intro Patch diffing has long fascinated me. I think part of it has to do with the race against the clock, reversing, exploiting, and trying to attain that “1day” exploit status. For advanced Windows targets, Valentina Palmiotti and Ruben Boonen proved that this was already possible nearly 3 years ago. But, they are some of the world's most talented exploit devs. Can LLMs raise the capability floor for us mere mortals? Fortunately, and maybe a bit alarmingly, the answer is yes. The Hunt When the…

Microsoft US

· Elastic Security · Patch diff to SYSTEM

1

CVE-2026-20841: Arbitrary Code Execution in the Windows Notepad

In this excerpt of a TrendAI Research Services vulnerability report, Nikolai Skliarenko and Yazhi Wang of the TrendAI Research team detail a recently patched command injection vulnerability in the Windows Notepad application. This bug was originally discovered by Cristian Papa and Alasdair Gorniak of Delta Obscura. Successful exploitation of this vulnerability could result in the execution of arbitrary commands in the security context of the victim's account. The following is a portion of their…

EPSS 0.12 CVE-2026-20841 Microsoft US

· ZDI Blog · CVE-2026-20841: Arbitrary Code Execution in the Windows Notepad

1