Security News

How to download the latest Windows 10 ISO from Microsoft
2021-01-02 12:30

This article provides two ways you can download the latest Windows 10 ISO images from Microsoft. Microsoft recommends using their Windows 10 Media Creation Tool to download the latest ISO image or create a bootable USB drive.

Microsoft Says SolarWinds Hackers Accessed Some of Its Source Code
2020-12-31 20:50

Microsoft on Thursday revealed that the threat actors behind the SolarWinds supply chain attack were able to gain access to a small number of internal accounts and escalate access inside its...

Microsoft Says 'SolarWinds' Hackers Viewed Internal Code
2020-12-31 19:41

Microsoft acknowledged Thursday that attackers who spearheaded a massive hack of government and private computer networks gained access to its internal "source code," a key building block for its...

Microsoft: SolarWinds hackers accessed our source code
2020-12-31 14:52

The threat actors behind the SolarWinds attack could breach internal Microsoft accounts to view the source code for Microsoft products. [...]

Microsoft: SolarWinds hackers' goal was the victims' cloud data
2020-12-29 13:30

Microsoft says that the end goal of the SolarWinds supply chain compromise was to pivot to the victims' cloud assets after deploying the Sunburst/Solorigate backdoor on their local networks. As the Microsoft 365 Defender Team explains, after infiltrating a target's network with the help of the Sunburst backdoor, the attackers' goal is to gain access to the victims' cloud assets.

Google: Microsoft Improperly Patched Exploited Windows Vulnerability
2020-12-28 13:15

Google Project Zero has disclosed a Windows zero-day vulnerability caused by the improper fix for CVE-2020-0986, a security flaw abused in a campaign dubbed Operation PowerFall. Tracked as CVE-2020-17008, the new vulnerability was reported to Microsoft on September 24.

CISA releases Azure, Microsoft 365 malicious activity detection tool
2020-12-28 12:48

"CISA has created a free tool for detecting unusual and potentially malicious activity that threatens users and applications in an Azure/Microsoft O365 environment," the US federal agency said. Sparrow checks the unified Azure/M365 audit log for indicators of compromise, lists Azure AD domains, and checks Azure service principals and their Microsoft Graph API permissions to discover potential malicious activity.

Microsoft Warns CrowdStrike of Hackers Targeting Azure Cloud Customers
2020-12-27 22:15

The hacking endeavor was reported to the company by Microsoft's Threat Intelligence Center on December 15, which identified a third-party reseller's Microsoft Azure account to be making "Abnormal calls" to Microsoft cloud APIs during a 17-hour period several months ago. The undisclosed affected reseller's Azure account handles Microsoft Office licensing for its Azure customers, including CrowdStrike.

Windows 10 Cloud PC: What is known about Microsoft's new service
2020-12-27 12:43

Microsoft is believed to be working on a new virtualized desktop experience called 'Cloud PC' to help administrators deploy and manage Windows 10 PCs in the cloud via web browser, mobile app or another PC. Cloud PC will also allow Microsoft to handle your organization's device configuration by applying updates security improvements regularly, and offer managed support. Cloud PC is based on Azure and Windows Virtual Desktop and it won't replace any version of Windows.

A Second Hacker Group May Have Also Breached SolarWinds, Microsoft Says
2020-12-23 22:44

As the probe into the SolarWinds supply chain attack continues, new digital forensic evidence has brought to light that a separate threat actor may have been abusing the IT infrastructure provider's Orion software to drop a similar persistent backdoor on target systems. "The investigation of the whole SolarWinds compromise led to the discovery of an additional malware that also affects the SolarWinds Orion product but has been determined to be likely unrelated to this compromise and used by a different threat actor," Microsoft 365 research team said on Friday in a post detailing the Sunburst malware.