Security News

Microsoft 365 anti-phishing feature can be bypassed with CSS
2024-08-07 05:00

Researchers have demonstrated a method to bypass an anti-phishing measure in Microsoft 365 (formerly Office 365), elevating the risk of users opening malicious emails.` [...]

Microsoft punches back at Delta Air Lines and its legal threats
2024-08-07 01:50

Microsoft has labelled Delta Air Lines' accusations it's partly to blame for the outages caused by CrowdStrike's buggy software "False" and "Misleading" - and insulted the state of the carrier's IT infrastructure. Delta, which has hired a law firm and threatened to sue Microsoft and CrowdStrike over the July 19 meltdown, previously claimed recovering from the BSOD blitz cost it $500 million.

Users call on Microsoft to update Outlook's friendly name feature
2024-08-06 12:18

Users are urging Microsoft to rethink how it shows sender email addresses in Outlook because phishing criminals are taking advantage, using helpful, friendly names to serve up emails loaded with malicious intent. Outlook will helpfully show the friendly name if it can rather than the actual address of the sender.

Microsoft Azure outage takes down services across North America
2024-08-05 21:03

​Microsoft has mitigated an Azure outage that lasted more than two hours and took down multiple services for customers across North and Latin America. [...]

Microsoft Confirms Global Azure Outage Caused by DDoS Attack
2024-08-01 16:58

The Azure outage had global reach, impacting a subset of customers attempting to connect to Azure App Services, Application Insights, Azure IoT Central, Azure Log Search Alerts, Azure Policy, the Azure portal itself, and a subset of Microsoft 365 and Microsoft Purview services. Many different organisations made statements on Tuesday, notifying users that their services were disrupted as a result of the Azure DDoS attack.

Microsoft Says Ransomware Groups Are Exploiting the Newly-Patched VMware ESXi Flaw
2024-07-31 17:52

A vulnerability in the ESXi hypervisor was patched by VMware last week, but Microsoft has revealed that it has already been exploited by ransomware groups to gain administrative permissions. The vulnerability affects ESXi versions 7.0 and 8.0 and VMware Cloud Foundation versions 4.x and 5.x., but patches were only rolled out for ESXi 8.0 and VMware Cloud Foundation 5.x. It has a relatively low CVSS severity score of 6.8.

'Error' in Microsoft's DDoS defenses amplified 8-hour Azure outage
2024-07-31 12:58

Do you have problems configuring Microsoft's Defender? You might not be alone: Microsoft admitted that whatever it's using for its defensive implementation exacerbated yesterday's Azure instability. Microsoft has published its strategy to defend against network-based DDoS attacks, noting it was unique due to the global footprint of the company.

Microsoft says massive Azure outage was caused by DDoS attack
2024-07-31 12:54

Microsoft confirmed that a nine-hour outage on Tuesday, which disrupted numerous Microsoft 365 and Azure services worldwide, was caused by a distributed denial-of-service (DDoS) attack. Affected services included Microsoft Entra, Intune, Power BI, Power Platform, Azure App Services, and others.The company explained that their DDoS protection mechanisms were triggered, but an error in the implementation of their defenses exacerbated the attack's impact. Once the issue was identified, Microsoft made networking configuration changes and rerouted to alternate paths to mitigate the problem.

Microsoft: DDoS defense error amplified attack on Azure, leading to outage
2024-07-31 10:42

A DDoS attack that started on Tuesday has made a number of Microsoft Azure and Microsoft 365 services temporarily inaccessible, the company has confirmed. Microsoft's mitigation statement on the Azure status history page.

Delta Air Lines dials up Microsoft's legal nemesis over CrowdStrike losses
2024-07-30 19:00

Delta Air Lines lost hundreds of millions of dollars due to the CrowdStrike outage earlier this month - and it has hired a high-powered law firm to claw some of those lost funds back, potentially from the Falcon maker and Microsoft itself. CNBC broke the news yesterday that Delta had hired famed lawyer David Boies to look into what the airline could do to recoup as much as an estimated $500 million in operational losses due to the July 19 CrowdStrike outage.