Výsledky hledání

výrobce: Microsoft× v celém archivu zrušit filtry

1035 karet z 1072 položek · strana 7 z 18 CZ · EN/orig

4

1

1

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

In this article Attack chain overviewMitigation and protection guidanceLearn more Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns…

Microsoft Cloudflare US

tg: varování tg: rozbor tp: malware tp: phishing

· Microsoft Security Blog · TerminalFix campaign deploys a reverse tunnel through multistage intrusion

9

3

​​​​​​What’s new in Microsoft Security: August 2026

As organizations incorporate AI agents into more processes across business and operations, security teams can benefit from greater visibility and new purpose-built tools that help manage, secure, and govern AI. This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments. Here’s what’s new: Extend expert-led protection with new capabilities…

Microsoft US

tg: novinka v produktu tp: AI tp: identita

· Microsoft Security Blog · ​​​​​​What’s new in Microsoft Security: August 2026

NCSC-2026-0286 [1.01] [H/H] Kwetsbaarheden verholpen in Microsoft Office

Microsoft heeft kwetsbaarheden verholpen in diverse Office producten. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de categorieën schade zoals beschreven in onderstaande tabel. Voor succesvol misbruik moet de kwaadwillende het slachtoffer misleiden een malafide bestand te openen of link te volgen. In onderstaande tabel wordt de kwetsbaarheid met kenmerk **CVE-2026-65667** genoemd met een CVSS score van 10.0. Ook worden de kwetsbaarheden met…

Microsoft NL

· NCSC-NL · NCSC-2026-0286 [1.01] [H/H] Kwetsbaarheden verholpen in Microsoft Office

SPOJENO PŘES CVE Ke zeužití kritické chyby ve Windows stačí poslat škodlivé packety

Americká CISA upozornila na aktivní zneužívání zranitelnosti CVE-2026-33824 (CVSS 9,8) ve Windows Internet Key Exchange (IKE). Ke zneužití této zranitelnosti stačí na neaktualizovaný počítač se systémem Windows odeslat speciálně upravené síťové pakety přes UDP porty 500 nebo 4 500. Zranitelnost se týká podporovaných verzí Windows 10, Windows 11 a Windows Serveru. Microsoft opravu vydal již v dubnu, takže je nezbytné neprodleně aktualizovat. Pokud to z nějakého důvodu není možné, doporučuje se…

KEV ✓ EPSS 0.73 CVSS 9.8 CVE-2026-33824 Microsoft veřejná správa CZ US

· CSIRT.CZ (CZ.NIC) · Ke zeužití kritické chyby ve Windows stačí poslat škodlivé packety · BleepingComputer · Critical RCE flaw in Windows IKE Extension now actively exploited · CISA KEV · Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability (CVE-2026-33824) · ZDI Blog · CVE-2026-33824: Remote Code Execution in Windows IKEv2 · Microsoft Security · CVE-2026-33824 Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability

5

CISA Adds Six Known Exploited Vulnerabilities to Catalog

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability…

KEV ✓ EPSS 0.84 CVE-2015-3246 CVE-2015-5287 CVE-2019-1068 CVE-2021-23758 CVE-2022-0995 CVE-2026-8452 Red Hat Microsoft Citrix veřejná správa US

· CISA Advisories · CISA Adds Six Known Exploited Vulnerabilities to Catalog

Exploits and vulnerabilities in Q2 2026

The vulnerability landscape shifted significantly in Q2 2026. First, the number of registered CVEs reached an unprecedented level. This is driven primarily by the widespread adoption of AI, both for application development and search for security flaws. This resulted in entire new classes of vulnerabilities emerging, particularly in the Linux networking subsystem. Second, security researchers have been publishing exploits for unpatched vulnerabilities more frequently. Publications like these…

KEV ✓ · ransomware EPSS 1.00 CVE-2017-0199 CVE-2017-11882 CVE-2018-0802 CVE-2023-38831 CVE-2025-6218 CVE-2025-8088 CVE-2026-31431 CVE-2026-31635 CVE-2026-43284 CVE-2026-43494 CVE-2026-43500 CVE-2026-46300 CVE-2026-46331 Microsoft Kaspersky RU

· Securelist (Kaspersky) · Exploits and vulnerabilities in Q2 2026

SPOJENO PŘES CVE Linux Kernel Out-of-Bounds Write Vulnerability (CVE-2022-0995)

CISA added CVE-2022-0995 to the Known Exploited Vulnerabilities catalog. Affected product: Linux Kernel. Remediation due date: 2026-09-09.

KEV ✓ EPSS 0.10 CVE-2022-0995 Linux Microsoft veřejná správa školství média US

tg: varování tg: rozbor tp: malware tp: podvod tp: únik dat tp: AI

· CISA KEV · Linux Kernel Out-of-Bounds Write Vulnerability (CVE-2022-0995) · Cisco Talos · UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations

4

GTA 6 leak hunt could expose data belonging to thousands of Discord users

Someone leaked footage of the upcoming game Grand Theft Auto (GTA) 6 this month, and the game’s publisher badly wants to know who. It’s after a range of data about members of three Discord servers going back to June 1 this year in a bid to nail the perpetrator. Take-Two Interactive, the publisher behind the GTA series, hit Microsoft and Discord with a subpoena on August 20. It’s demanding IP addresses, phone numbers, linked Google and Xbox accounts, and OneDrive contents of certain server…

Take-Two Interactive Microsoft Discord US

· Malwarebytes Labs · GTA 6 leak hunt could expose data belonging to thousands of Discord users

The safety penalty: Reclaiming operational sovereignty in the age of AI

As frontier models advance in cyber capability, their guardrails also become more restrictive. Defenders relying on these models to power core SOC processes cannot afford to pay the “safety penalty” of being blocked by these safeguards. Organizations should monitor model refusal rates and use the data to create a strategy to ensure operational sovereignty.The allure of the cloud and the hidden "safety penalty" Cybersecurity has made a big bet on cloud-hosted AI. Building and running frontier…

OpenAI Anthropic Amazon Microsoft US

· Cisco Talos · The safety penalty: Reclaiming operational sovereignty in the age of AI

Savjeti Nacionalnog CERT-a za siguran početak školske godine – razmisli prije nego klikneš

Internet je veliko mjesto gdje gotovo svatko može stvarati i dijeliti sadržaj. Zato je važno obratiti pozornost i razmisliti o sadržaju s kojim se susrećete. Prije nego što nešto kliknete, podijelite ili povjerujete, zastanite i razmislite tko je objavio sadržaj i zašto te je li istinit ili je osmišljen da vas navede na krivi trag. Najčešći oblici prijevara na internetu s kojima se možete susresti S početkom školske godine mogu se očekivati prijevare kao što su phishing poruke s navodnim važnim…

Microsoft Google školství HR

· CERT.hr · Savjeti Nacionalnog CERT-a za siguran početak školske godine – razmisli prije nego klikneš

SPOJENO PŘES CVE CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A public PoC was released on August 12, 2026, and Microsoft assigned the CVE on August 14, and no patch is available yet. Qualys VMDR provides detection across Windows environments, and Qualys TruRisk Eliminate offers a mitigation that teams can apply now, with…

EPSS 0.11 CVE-2026-50656 CVE-2026-69414 Microsoft US

tg: zranitelnost tg: rozbor tg: propagace

· Qualys · CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days

5

SPOJENO PŘES CVE ZDI-26-605: Microsoft Windows Localized Filenames Improper Input Validation NTLM Response Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose NTLM responses on affected installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-50508.

EPSS 0.09 CVSS 3.3 CVE-2026-50508 Microsoft US

· Zero Day Initiative · ZDI-26-605: Microsoft Windows Localized Filenames Improper Input Validation NTLM Response Information Disclosure Vulnerability · Microsoft Security · CVE-2026-50508 Windows NTLM Spoofing Vulnerability

ZDI-26-606: Microsoft Windows Compatibility Appraiser Link Following Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code in the context of LOCAL SERVICE on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0.

CVSS 7.0 Microsoft US

· Zero Day Initiative · ZDI-26-606: Microsoft Windows Compatibility Appraiser Link Following Local Privilege Escalation Vulnerability

ZDI-26-607: Microsoft Office HTML Injection Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Office. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.6.

CVSS 7.6 Microsoft US

· Zero Day Initiative · ZDI-26-607: Microsoft Office HTML Injection Information Disclosure Vulnerability

1

SPOJENO PŘES CVE Microsoft Entra ID Remote Code Execution Vulnerability

Classification: Critical, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.1: 10.0, CVEs: CVE-2026-69836, Summary: Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency.

EPSS 0.02 CVSS 10.0 CVE-2026-69836 Microsoft veřejná správa FI IT US FR

· NCSC-FI · Microsoft Entra ID Remote Code Execution Vulnerability · CSIRT Itálie (ACN) · Rilevato sfruttamento di vulnerabilità in Microsoft Entra ID · CISA KEV · Microsoft Entra ID Deserialization of Untrusted Data Vulnerability (CVE-2026-69836) · CERT-FR – avis · Vulnérabilité dans Microsoft Entra ID (21 août 2026) · Microsoft Security · CVE-2026-69836 Microsoft Entra ID Remote Code Execution Vulnerability

7

Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)

In every MFA rollout, there will come a time where you think you are closing in on "done", and some automation to list what's left would be handy. Something quicker than scrolling through the web interface through thousands of accounts ... This is that method. Also, remember when we discussed yesterday about the beta graph commands in the Microsoft.Graph.Beta library? We'll use one of those beta commands here! # import, if it's not already there Import-Module -Name Microsoft.Graph.Beta.Reports …

Microsoft US

· SANS Internet Storm Ctr. · Who Got Missed in the MFA Rollout? More Powershell + Graph + Entra scripting!, (Fri, Aug 21st)

Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)

One thing that folks never seem to do after "going to the CLOOOOUUUUD" is to look at their logs, logs that they would have checked daily when things were on premise. One log that really bears looking at is the log of successful and failed logins. the call for that is: # import needed, if they're not already in place Import-Module Microsoft.Graph.Reports # connect with the correct scope Connect-MgGraph -Scopes "AuditLog.Read.All", "Directory.Read.All" $f = Get-MgAuditLogSignIn Let's look at one…

Microsoft US

· SANS Internet Storm Ctr. · Even MOAR Powershell, looking at Entra logins - the good, the bad and the password sprays, (Fri, Aug 21st)

Multiples vulnérabilités dans Microsoft Edge (21 août 2026)

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

EPSS 0.01 CVE-2026-76033 CVE-2026-76034 CVE-2026-76035 CVE-2026-76037 CVE-2026-76038 CVE-2026-76040 CVE-2026-76041 CVE-2026-76042 CVE-2026-76043 CVE-2026-76044 CVE-2026-76045 CVE-2026-76047 Microsoft FR

· CERT-FR – avis · Multiples vulnérabilités dans Microsoft Edge (21 août 2026)

13

Is Cyber missing the Marque?

Welcome to this week’s edition of the Threat Source newsletter. Hello friend. I’m Mick. This is my first Threat Source newsletter, so I should probably introduce myself before I start telling you all the things I think you should be paying attention to. With assistance from an unnamed LLM, my bio reads like this: Mick Baccio is a globally recognized security strategist with a career spanning offensive operations, threat intelligence, and national-level incident response. He currently advises…

GitLab Apple Microsoft veřejná správa obrana US

· Cisco Talos · Is Cyber missing the Marque?

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. Examples of these techniques can be found in our previous blog on UNC6293’s phishing operations. We now track an…

Microsoft Google veřejná správa obrana školství US

· Mandiant / Google TI · Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Using Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th)

Building on the last diary on Using MS Graph and Powershell, let's look at "Risky" logins. Risky logins are a derived set of parameters that look at various (you guessed it) risky login parameters. What is considered a risk? In most cases this is either impossible geography - in other words "we're not expecting to see you at that IP, in that subnet, ASN or country", or unusual device - ie "that's not your regular computer" There are two groups of commands in this area. You can do Risk Detection…

Microsoft US

· SANS Internet Storm Ctr. · Using Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th)

BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive

Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 – without exploits, vulnerabilities, or memory corruption? In this publication, we present the first full reverse engineering of the Windows Defender Boot-Time Removal driver (BTR.sys) and its proprietary transaction…

Microsoft IL

· Check Point Research · BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive

Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)

Microsoft Graph is a newer API that is meant to replace several others. OK, it's at version 2.3.9, so it's not all that new, but it's new enough that lots of folks (and commercial tools) aren't using it yet. It allows you to Get and Set info from/to M365, Entra Users and Entra managed machines for starters. Let's dig in! Let's start exploring just by dumping a user table: $AllUsers = Get-MgUser -All -Property Id, DisplayName, UserPrincipalName, AccountEnabled, SignInActivity | Where-Object { $_…

Microsoft US

· SANS Internet Storm Ctr. · Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)

4

41 deceptive download sites show a real link, then send you somewhere else

We identified a network of 41 websites impersonating popular games and Windows software, all designed to push visitors towards the same Download Studio installer. The sites advertise everything from Counter-Strike, Half-Life, Fallout, Roblox, PUBG, and The Witcher to VLC, 7-Zip, Paint.NET, VMware, Total Commander, and Foxit PDF. They go to surprising lengths to look convincing, using accurate product information, genuine developer resources, and even real download links. But the link you see…

Microsoft US

tg: varování tg: rozbor tp: podvod

· Malwarebytes Labs · 41 deceptive download sites show a real link, then send you somewhere else

Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026

Security teams are overwhelmed with findings but still struggle to answer a simple question: which risks matter right now? A vulnerability alone is rarely the problem. The same vulnerability running in production, exposed through a misconfiguration or over-permissioned identity, is a real path to compromise. Organizations do not need longer lists of alerts. They need context that connects code, cloud resources, identities, and runtime activity so they can prioritize the issues that pose the…

Microsoft US

tg: propagace

· Microsoft Security Blog · Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026

3

SPOJENO PŘES CVE CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now

Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing the patch alone does not complete remediation, as the fix replaces a kernel driver and requires…

KEV ✓ EPSS 0.06 CVSS 7.0 CVE-2026-68820 Microsoft US FR

tg: zneužíváno tg: regulace tg: návod tg: propagace

· Qualys · CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now · CERT-FR – avis · Multiples vulnérabilités dans Microsoft Windows (12 août 2026) · Tenable Research · Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820) · Microsoft Security · CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability · CISA KEV · Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability (CVE-2026-68820)

Microsoft security advisory – August 2026 monthly rollup (AV26-804) – Update 1

Serial Number: AV26-804Date: August 11, 2026Updated: August 18, 2026 As of August 11, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on Mac OS .NET 8.0 installed on Windows .NET 9.0 installed on Linux .NET 9.0 installed on Mac OS .NET 9.0 installed on Windows App Installer Application Insights Profiler Azure Active Directory Azure…

KEV ✓ EPSS 0.73 CVE-2026-33824 CVE-2026-55040 Microsoft CA

· Cyber Centre Kanada · Microsoft security advisory – August 2026 monthly rollup (AV26-804) – Update 1