Microsoft
Curated coverage and analysis in this editorial area.

TokenLover and YaksaLover: The PhaaS Kits That Measure Persistence With a 'Password Change Survival Rate'
Italy's ACN details two Phishing-as-a-Service toolkits that abuse the Device Code Flow and NGC keys to achieve persistence that surviv…

Midnight Blizzard Turns Hotel Wi-Fi Into a Trap for Corporate Travelers
Storm-2945, a Midnight Blizzard sub-cluster, compromises captive portal networks worldwide to deliver the CornFlake RAT and steal Micr…

Hotel DNS Attacks: Corporate VPNs Aren't Enough to Protect Microsoft 365
ReliaQuest has documented an active campaign since June 2026 that compromises hotel Wi-Fi gateways to redirect Microsoft 365 logins to…

May 2026 Patch Tuesday: 161 CVEs, No Zero-Days, But Wormable Risks Loom
Microsoft's May 2026 Patch Tuesday fixes 161 vulnerabilities with no actively exploited zero-days — the first such month since June 20…

Device Code Phishing: How Attackers Bypass MFA on Microsoft 365
Proofpoint documents threat clusters exploiting Microsoft's legitimate OAuth device authorization flow to compromise Microsoft 365 acc…

Kratos Dismantled: AiTM Code Remains in Hands of 1,800 Criminals
German and U.S. authorities seized over 200 servers linked to the Kratos phishing-as-a-service kit, but the source code still circulat…

Record Patch Tuesday: Microsoft Fixes 622 Bugs, Two Zero-Days Already Exploited
Microsoft's July 2026 Patch Tuesday sets an all-time high with 622 CVEs patched, including two actively exploited zero-days in SharePo…

LegacyHive: The Windows Zero-Day With Free Micropatches While Microsoft Investigates
The LegacyHive zero-day in the Windows User Profile Service enables local privilege escalation. ACROS Security has already released fr…

Microsoft Patches RoguePlanet, the Defender Black Hole That Handed SYSTEM to Anyone
CVE-2026-50656: a race condition in the Windows 10 and 11 antivirus engine let a standard user gain SYSTEM privileges. The silent engi…

OWAReaper: The Malware That Survives Device Reimaging
Russia-aligned APT Laundry Bear (TA488) exploited CVE-2026-42897, an XSS flaw in Outlook Web Access, to deploy OWAReaper — a browser-b…

CVE-2026-56163: Microsoft Mitigates Critical AKS Flaw Without Customer Action
Microsoft assigned CVE-2026-56163 a maximum CVSS 10.0 score for a critical elevation-of-privilege vulnerability in Azure Kubernetes Se…

Kratos Phishing Kit Dismantled: 200 Servers Seized, but AiTM Code Remains in Circulation
German, U.S., and Indonesian authorities took down the Kratos phishing kit, seizing over 200 servers and arresting the alleged develop…