Security News

New Mamba 2FA bypass service targets Microsoft 365 accounts
2024-10-08 20:27

An emerging phishing-as-a-service (PhaaS) platform called Mamba 2FA has been observed targeting Microsoft 365 accounts in AiTM attacks using well-crafted login pages. [...]

Microsoft patches two zero-days exploited in the wild (CVE-2024-43573, CVE-2024-43572)
2024-10-08 19:37

For October 2024 Patch Tuesday, Microsoft has released fixes for 117 security vulnerabilities, including two under active exploitation: CVE-2024-43573, a spoofing bug affecting the Windows MSHTML...

Microsoft fixes Remote Desktop issues caused by Windows Server update
2024-10-08 19:08

​Microsoft says this month's Patch Tuesday cumulative updates fix a known issue that causes Windows servers to disrupt Remote Desktop connections in enterprise networks after installing the July...

Microsoft October 2024 Patch Tuesday fixes 5 zero-days, 118 flaws
2024-10-08 18:16

Today is Microsoft's October 2024 Patch Tuesday, which includes security updates for 118 flaws, including five publicly disclosed zero-days, two of which are actively exploited. [...]

Microsoft Edge begins testing Copilot Vision
2024-10-08 09:15

Microsoft Edge Canary has been updated with an interesting feature called Copilot Vision, but it's still in testing. [...]

Microsoft: Word deletes some documents instead of saving them
2024-10-07 20:11

Microsoft warns that a new bug may cause Word for Windows to delete some documents instead of saving them. [...]

US Government, Microsoft Aim to Disrupt Russian threat actor ‘Star Blizzard’
2024-10-07 13:35

Read more about the U.S. Department of Justice and Microsoft’s efforts to interrupt the activities of Russian-based threat actor Star Blizzard, and learn how to protect from this threat.

Over 5,000 Fake Microsoft Notifications Fueling Email Compromise Campaigns
2024-10-04 16:41

Check Point documented 5,000 emails coming from legitimate-looking organizational domains.

U.S. and Microsoft Seize 107 Russian Domains in Major Cyber Fraud Crackdown
2024-10-04 13:06

Microsoft and the U.S. Department of Justice (DoJ) on Thursday announced the seizure of 107 internet domains used by state-sponsored threat actors with ties to Russia to facilitate computer fraud...

Microsoft and DOJ disrupt Russian FSB hackers' attack infrastructure
2024-10-03 17:58

Microsoft and the Justice Department have seized over 100 domains used by the Russian ColdRiver hacking group to target United States government employees and nonprofit organizations from Russia...