2026-09-04 19:10 UTC
Vendor Research
Microsoft Security Blog · Shayak Lahiri · indexed 2026-09-04 20:30 UTC
As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge AI in customer-owned environments appeared first on Microsoft Security Blog.
P0
2026-09-04 16:18 UTC
Security Journalism
Security Week · SecurityWeek News · indexed 2026-09-07 17:25 UTC
Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion. The post In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation appeared first on SecurityWeek.
P0
2026-09-04 16:07 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-07 17:25 UTC
The Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility. The post OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders appeared first on SecurityWeek.
P0
2026-09-04 15:57 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 16:10 UTC
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The
P0
2026-09-04 14:30 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-04 14:40 UTC
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]
P0
2026-09-04 13:39 UTC
Security Journalism
The Record · indexed 2026-09-04 13:55 UTC
Russia's data centers are concentrated in areas increasingly exposed to Ukrainian drone attacks. The Kremlin wants them to stiffen their physical defenses.
P0
2026-09-04 13:22 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-04 13:30 UTC
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...]
P25
2026-09-04 12:22 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-04 12:35 UTC
Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. [...]
P0
2026-09-03 16:00 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Noam Kochavi and Sarah Wolstencroft · indexed 2026-09-03 16:45 UTC
Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog.
P0
2026-09-03 15:26 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial
P0
2026-09-03 15:22 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-03 15:35 UTC
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. [...]
P0
2026-09-03 13:50 UTC
Security Journalism
BleepingComputer · Sponsored by Flare · indexed 2026-09-03 14:00 UTC
Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]
P0
2026-09-03 13:17 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-03 14:00 UTC
412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration. A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin American purchase records with a heavy concentration of Brazilian data. […]
P0
2026-09-03 12:16 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-03 12:25 UTC
Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. [...]
P0
2026-09-03 11:53 UTC
Other
Proofpoint Threat Insight · indexed 2026-09-07 17:30 UTC
P0
2026-09-03 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Reese Lewis and Sara McBroom · indexed 2026-09-03 10:20 UTC
Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America appeared first on Unit 42.
P0
2026-09-03 08:55 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-03 09:05 UTC
Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. [...]
P0
2026-09-02 22:51 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Sagar Patil, Arlette Umuhire Sangwa, Jesse Birch and Ravikant Tiwari · indexed 2026-09-03 00:10 UTC
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity. The post Impersonating IT support: how threat actors turn a remote session into enterprise-wide access appeared first on Microsoft …
P0
2026-09-02 18:27 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 19:30 UTC
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them
P0
2026-09-02 16:51 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-02 17:05 UTC
The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.
P0
2026-09-02 16:41 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 17:50 UTC
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users," Microsoft
P0
2026-09-02 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-08 13:30 UTC
An inside look at Knight Office, a newly discovered AiTM phishing kit featuring custom control panels, Cloudflare Turnstile, and M365 Token theft.
P0
2026-09-02 10:29 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-02 10:35 UTC
Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. [...]
P0
2026-09-01 22:48 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Microsoft Defender Experts and Parth Jomadkar · indexed 2026-09-01 23:55 UTC
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system compromise: Tracking a deceptive software download campaign appeared first on Microsoft Security B…
P0
2026-09-01 18:55 UTC
Vendor Research
Microsoft Security Blog · Microsoft Defender Experts Cybersecurity Incident Response · indexed 2026-09-01 20:15 UTC
Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR Workshop: The workshop you shouldn’t miss appeared first on Microsoft Security Blog.
P0
2026-09-01 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-01 03:50 UTC
Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In thi…
P0
2026-09-01 12:38 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-01 12:50 UTC
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]
P10
2026-09-01 11:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 11:50 UTC
The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year, accounting
P0
2026-08-31 20:09 UTC
Security Journalism
Dark Reading · Arielle Waldman · indexed 2026-09-01 12:50 UTC
While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the rules.
P0
2026-08-31 18:51 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-31 19:05 UTC
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]
P0