Microsoft
Everything filed under by vendor in our cybersecurity coverage, the 20 reports filed on it so far.

GitHub and Microsoft launch ReviewBench AI code review benchmark
GitHub and Microsoft have released ReviewBench, an open benchmark for evaluating AI code review tools using 219 real-world pull requests.

Windows 11 KB5124010 update crashes apps using AC-3 audio
Microsoft confirms the optional September 2026 KB5124010 preview update for Windows 11 causes crashes in some games and applications that use AC-3...

China-Nexus Actor UAT-11587 Uses Antino Backdoor
Cisco Talos details a China-nexus threat actor, UAT-11587, using a Rust-based backdoor called Antino that leverages Microsoft 365 services for covert...

Microsoft details China-linked NeedyMantis malware framework
Microsoft has publicly detailed the NeedyMantis malware framework, discovered during analysis of the May 2026 Daemon Tools supply chain attack.

Microsoft Warns of Passkey Phishing Cloud Attacks
Microsoft details two campaigns: one blasting CEO-impersonation invoice scams and another using passkey-themed social engineering to hijack Microsoft...

Phishing Campaign Abuses Microsoft 365 Direct Send Feature
A phishing campaign exploiting Microsoft 365's Direct Send feature sent nearly 30,000 emails, primarily during US Eastern business hours, to bypass...

Microsoft Patches Record 974 Flaws, Two Exploited Zero-Days
Microsoft's September 2026 Patch Tuesday addressed a record 974 vulnerabilities, including two Windows zero-days under active exploitation. The U.S.

Arctic Wolf Exposes Microsoft 365 Data Theft Campaign
A threat cluster tracked as PREY-0058 is using fake IT calls and proxy sign-ins to steal data from executives for extortion, according to Arctic Wolf.

Anthropic locks Claude accounts after infostealer malware
Anthropic is locking users out of Claude accounts due to login sessions compromised by infostealer malware. Separately, nearly 22,000 Microsoft...

Microsoft Warns of High-Volume Phishing Campaign Using Invisible Unicode
Microsoft has alerted of a phishing campaign using invisible Unicode tag characters to split financial keywords and evade email filters.

Microsoft and Adobe Patch Critical Vulnerabilities
September 2026's Patch Tuesday follows a record-breaking August with 398 CVEs patched. Experts highlight actively exploited SharePoint and Exchange...

22,000 Exchange Servers Unpatched for Critical Flaw
Nearly 22,000 Microsoft Exchange servers are still vulnerable to a critical patched flaw, CVE-2026-62911, for which a working exploit is now online.

CISA Adds Six Exploited Flaws to KEV Catalog
CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog on August 26, including high-severity flaws in Citrix and Microsoft...

TerminalFix Campaign Uses Fake Cloudflare Lures
Microsoft details TerminalFix, a ClickFix variant that tricks users into running malicious PowerShell commands via fake Cloudflare CAPTCHA pages.

OpenAI Leads 130 Firms in Cyber Defense Pledge
OpenAI is leading a coalition of nearly 130 technology and cybersecurity firms, including Microsoft and Google, in a pledge to bolster global cyber...

Tech Giants Warn of Narrowing Window to Counter AI-Enabled Attacks
Over 100 tech and cybersecurity firms, including OpenAI and Microsoft, warn AI-enabled attacks threaten critical infrastructure.

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that could allow a single click on a crafted link to silently...

Microsoft Defender Patch Bypass Exploit Claims SYSTEM Access
A security researcher has released a proof-of-concept exploit for a Microsoft zero-day vulnerability, claiming it can bypass a previously released...

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Microsoft has released its monthly security updates, addressing 398 flaws, including a Windows driver zero-day under active attack.

Lazarus Group Exploits Windows Zero-Day Vulnerability to Gain SYSTEM Access and Deploy Backdoor
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting...