Microsoft
Curated coverage and analysis in this editorial area.

Hotel Wi-Fi DNS Attacks Steal Microsoft 365 Accounts, Bypass MFA
Threat actors compromise hotel and conference center Wi-Fi captive portals to manipulate DNS and steal Microsoft 365 credentials, sess…

Certighost: Ten Days After the Patch, the Exploit Is Public and the Domain Falls
The Certighost proof-of-concept for CVE-2026-54121 lets a standard domain user impersonate a Domain Controller via AD CS. Released exa…

Record Patch Tuesday: Microsoft Fixes 570 CVEs and Two Actively Exploited Zero-Days in AD FS and SharePoint
The July 14, 2026 Patch Tuesday sets a record with 570 CVEs patched, two actively exploited zero-days, and a third publicly disclosed.…

LegacyHive: Zero-Day Windows Flaw Patched by 0Patch Before Microsoft
The LegacyHive vulnerability in the Windows User Profile Service enables local privilege escalation. ACROS Security has released free…

Misconfigured Server Exposes Three Evilginx Operations Targeting Microsoft 365
A phishing server with directory listing enabled exposed complete M365 phishing toolkits, two distinct MFA bypass techniques, and evid…

Joint Operation Dismantles Kratos: The AiTM Phishing Kit That Bypasses MFA
German, U.S., and Indonesian authorities have taken down over 200 servers powering the Kratos phishing kit. The code survives among ro…

Miasma Worm Infects 73 Microsoft GitHub Repos via AI Coding Agents
The Miasma worm compromised 73 Microsoft repositories on GitHub in 105 seconds. The malware activates when a developer opens the repos…

Device Code Phishing: Legitimate Authentication Becomes the Weapon to Breach M365
Device code phishing exploits Microsoft's legitimate OAuth flow to bypass MFA. Low-cost PhaaS kits like DEBULL and ARToken have indust…

Microsoft Patch Tuesday July 2026: Two Zero-Days, and the CVSS 5.3 Is More Dangerous Than the 7.8
Microsoft's July 2026 Patch Tuesday addressed 570 CVEs, including two actively exploited zero-days: CVE-2026-56164 in SharePoint Serve…

German Police Dismantle Kratos, the Kit That Turned AiTM Phishing Into a Franchise
German, U.S., and Indonesian authorities dismantled the Kratos phishing-as-a-service platform, seizing over 200 servers and arresting…

Microsoft Uncovers OAuth Abuse: Vishing and Supply Chain Attacks Target SaaS
Microsoft has documented ShinyHunters-linked campaigns abusing trusted OAuth relationships in Salesforce through vishing and third-par…

LegacyHive: Nightmare Eclipse's Ninth Zero-Day Pierces Fully Patched Windows
Nightmare Eclipse has released LegacyHive, a zero-day exploit targeting the Windows User Profile Service to load arbitrary registry hi…