Microsoft
Curated coverage and analysis in this editorial area.

Microsoft Dismantles Fox Tempest: The Takedown of a Global Malware-Signing Syndicate
Microsoft’s Digital Crimes Unit has seized the infrastructure of Fox Tempest, a major 'malware-signing-as-a-service' provider that ena…

May Patch Tuesday: A Rare Zero-Day Break Amid Record AI Discovery Volumes
Microsoft’s May 2026 update ends a two-year streak of active zero-days, patching approximately 137 vulnerabilities. However, the integ…

Active Exchange Zero-Day: Unpatched OWA Vulnerability Under Exploitation
Microsoft has confirmed CVE-2026-42897, a zero-day XSS vulnerability in on-premise Exchange servers currently under active attack. Wit…

May 2026 Patch Tuesday: 137 Vulnerabilities Addressed, No Zero-Days Found Despite Critical DNS RCE
Microsoft has patched 137 vulnerabilities in its May 2026 security update. While no active exploits have been detected, critical unaut…

Microsoft Patch Tuesday: Legacy MSMQ Flaw Enables Local SYSTEM Escalation
The May 12, 2026, security update addresses CVE-2026-33838, an elevation-of-privilege vulnerability in Windows Message Queuing (MSMQ).…

Microsoft Exchange Zero-Day Exploited: Permanent Patch Restricted to ESU Customers
Microsoft has confirmed active in-the-wild exploitation of CVE-2026-42897 affecting Exchange on-premise servers. CISA has issued a hig…

May Patch Tuesday: AI-Driven Discovery Pushes 2026 Vulnerability Count Past 500
Microsoft's May 12, 2026, update addresses more than 130 vulnerabilities, revealing the impact of its internal MDASH AI system. The to…

May 2026 Patch Tuesday: AI-Driven Discovery Marks a Turning Point in Vulnerability Management
Microsoft and industry partners address over 130 vulnerabilities as AI systems like MDASH and Project Glasswing accelerate the discove…

Microsoft MDASH Deployment Identifies 16 Windows Flaws via 100+ AI Agents
Microsoft’s MDASH, an agentic multi-model system, discovered 16 vulnerabilities—including four critical RCEs—patched in the May 2026 u…

BitLocker Zero-Day: Encrypted Drives Unlocked via USB and WinRE — No Credentials Needed
A new proof-of-concept named YellowKey enables BitLocker bypasses on Windows 11 and Server editions by exploiting the Windows Recovery…

Microsoft May Patch Tuesday Fixes 120 Flaws, but DNS and Dynamics 365 Bugs Demand Priority
Microsoft’s May 2026 update fixes roughly 120 vulnerabilities, targeting critical gaps in DNS, Dynamics 365, and Office components. Wh…

CVE-2026-3854: Critical GitHub RCE Leaves 88% of On-Premise Servers Exposed
Wiz Research has detailed CVE-2026-3854, a critical RCE vulnerability in GitHub’s internal Git pipeline. While GitHub.com was patched…