Microsoft Exchange Server
A page on products in our cybersecurity coverage, part of our tech reporting, alongside the 26 reports filed on it so far.

Microsoft details China-linked NeedyMantis
Microsoft has publicly detailed the NeedyMantis malware framework, discovered during analysis of the May 2026 Daemon Tools supply chain attack.

Kiteworks issues global server shutdown
Kiteworks advised customers worldwide to shut down servers for a six-hour window on Saturday, September 26, based on credible threat intelligence from

F5 Patches Critical BIG-IP APM Zero-Day Exploited for RCE
F5 has released hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in BIG-IP APM. The flaw, a heap-based buffer overflow with a CVSS...

EU Auditors Cite Information-Sharing Gaps in Cyber Response
The EU Court of Auditors warns that insufficient information exchange and undefined roles are hindering the bloc's ability to detect and respond to...

Check Point Zero-Day Exploited in Targeted July Attacks
Check Point has disclosed that a critical zero-day vulnerability in its Security Management Server was exploited in targeted attacks in July.

Microsoft Warns of Passkey Phishing Cloud Attacks
Microsoft details two campaigns: one blasting CEO-impersonation invoice scams and another using passkey-themed social engineering to hijack Microsoft...

Phishing Campaign Abuses Microsoft 365 Direct Send Feature
A phishing campaign exploiting Microsoft 365's Direct Send feature sent nearly 30,000 emails, primarily during US Eastern business hours, to bypass...

Microsoft Patches Record 974 Flaws, Two Exploited Zero-Days
Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two Windows zero-days under active exploitation. The U.S.

Arctic Wolf Exposes Microsoft 365 Data Theft Campaign
A threat cluster tracked as PREY-0058 is using fake IT calls and proxy sign-ins to steal data from executives for extortion, according to Arctic Wolf.

Stacklok releases open-source ToolHive for secure MCP server
Stacklok has released ToolHive, an open-source platform for securely running Model Context Protocol servers inside isolated containers.

Anthropic locks Claude accounts after infostealer malware
Anthropic is locking users out of Claude accounts due to login sessions compromised by infostealer malware. Separately, nearly 22,000 Microsoft...

Microsoft Warns of High-Volume Phishing Campaign Using
Microsoft has alerted of a phishing campaign using invisible Unicode tag characters to split financial keywords and evade email filters, with peak...

Microsoft and Adobe Patch Critical Vulnerabilities
September 2026's Patch Tuesday follows a record-breaking August with 398 CVEs patched. Experts highlight actively exploited SharePoint and Exchange...

22,000 Exchange Servers Unpatched for Critical Flaw
Nearly 22,000 Microsoft Exchange servers are still vulnerable to a critical patched flaw, CVE-2026-62911, for which a working exploit is now online.

CISA Adds Six Exploited Flaws to KEV Catalog
CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog on August 26, including high-severity flaws in Citrix and Microsoft...

TerminalFix Campaign Uses Fake Cloudflare
Microsoft details TerminalFix, a ClickFix variant that tricks users into running malicious PowerShell commands via fake Cloudflare CAPTCHA pages to...

OpenAI Leads 130 Firms in Cyber Defense
OpenAI is leading a coalition of nearly 130 technology and cybersecurity firms, including Microsoft and Google, in a pledge to bolster global cyber

Tech Giants Warn of Narrowing Window to
Over 100 tech and cybersecurity firms, including OpenAI and Microsoft, warn AI-enabled attacks threaten critical infrastructure.

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert...

New Cryptographic Context Injection Attack Puts Grok Chat Data at Risk
Adversa AI discloses a new attack technique that can cause xAI's Grok chatbot to send user data to an attacker-controlled server

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that could allow a single click on a crafted link to silently...

Ransomware Affiliate 'Ransom Busters' Claims to Delete Stolen Data for a Fee
A ransomware affiliate, 'Ransom Busters', has been sending emails to victim organizations claiming to delete stolen data from ransomware groups'...

Microsoft Defender Patch Bypass Exploit Claims SYSTEM Access
A security researcher has released a proof-of-concept exploit for a Microsoft zero-day vulnerability, claiming it can bypass a previously released...

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Microsoft has released its monthly security updates, addressing 398 flaws, including a Windows driver zero-day under active attack.