Security News

Microsoft now pays up to $30,000 for some AI vulnerabilities
2025-04-24 15:06

Microsoft announced an increase in bug bounty payouts to $30,000 for AI vulnerabilities found in Dynamics 365 and Power Platform services and products. [...]

Microsoft fixes bug causing incorrect 0x80070643 WinRE errors
2025-04-24 13:54

Microsoft says it resolved a known issue causing erroneous 0x80070643 installation failure errors when deploying the April 2025 Windows Recovery Environment (WinRE) updates. [...]

Russian Hackers Exploit Microsoft OAuth to Target Ukraine Allies via Signal and WhatsApp
2025-04-23 10:49

Multiple suspected Russia-linked threat actors are "aggressively" targeting individuals and organizations with ties to Ukraine and human rights with an aim to gain unauthorized access to Microsoft...

Attackers phish OAuth codes, take over Microsoft 365 accounts
2025-04-23 10:23

Suspected Russian threat actors are using OAuth-based phishing attacks to get targets to grant them access to their Microsoft 365 (M365) accounts. “The primary tactics observed involve the...

Microsoft fixes Remote Desktop freezes caused by Windows updates
2025-04-23 07:59

​Microsoft has resolved a known issue causing Remote Desktop sessions to freeze on Windows Server 2025 and Windows 11 24H2 devices. [...]

Microsoft fixes Windows Server 2025 blue screen, install issues
2025-04-23 07:33

Microsoft has fixed several known issues that caused Blue Screen of Death (BSOD) and installation issues on Windows Server 2025 systems with a high core count. [...]

Microsoft Secures MSA Signing with Azure Confidential VMs Following Storm-0558 Breach
2025-04-22 07:38

Microsoft on Monday announced that it has moved the Microsoft Account (MSA) signing service to Azure confidential virtual machines (VMs) and that it's also in the process of migrating the Entra ID...

Microsoft rated this bug as low exploitability. Miscreants weaponized it in just 8 days
2025-04-21 17:43

It's now hitting govt, enterprise targets On March 11 - Patch Tuesday - Microsoft rolled out its usual buffet of bug fixes. Just eight days later, miscreants had weaponized one of the...

Microsoft Entra account lockouts caused by user token logging mishap
2025-04-21 16:26

Microsoft confirms that the weekend Entra account lockouts were caused by the invalidation of short-lived user refresh tokens that were mistakenly logged into internal systems. [...]

Widespread Microsoft Entra lockouts tied to new security feature rollout
2025-04-19 22:04

Windows administrators from numerous organizations report widespread account lockouts triggered by false positives in the rollout of a new Microsoft Entra ID's "leaked credentials" detection app...