microsoft

Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents

Microsoft Copilot for Word can be exploited to copy hidden instructions from a malicious document into new files. The vulnerability allows Copilot to mistake hidden instructions for user requests, potentially leading to data manipulation. While Microsoft has deployed mitigations, the attack remains exploitable, and user vigilance is recommended when handling external documents.

https://thehackernews.com/2026/07/microsoft-copilot-for-word-can-copy.html

Microsoft Teams Vishing Attacks Lead to Chaos Ransomware Attacks

Threat actors are conducting vishing attacks via Microsoft Teams by impersonating IT support staff to gain remote access to corporate devices, leading to Chaos ransomware infections in North American organizations. The campaign, tracked as STAC4749 by Sophos, targeted mainly Canadian and US companies across multiple sectors, using fake IT domains and remote support tools like Microsoft Quick Assist and RemSupp to deploy backdoors and achieve persistence before deploying ransomware. Some attacks resulted in data theft and rapid ransomware encryption within 17 hours of initial access.

https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks/

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Russian cyber espionage group TA488 has exploited a cross-site scripting vulnerability (CVE-2026-42897) in Microsoft Outlook Web Access (OWA) to maintain persistent mailbox access even after credential changes. The implanted JavaScript malware, dubbed OWAReaper, operates stealthily within the OWA browser context, harvesting credentials, stealing OAuth tokens, and surviving device re-imaging by leveraging server-side persistence on Exchange servers and hidden offline cache elements. This advanced half-click exploit campaign targets various sectors including government and finance, enabling the actor to maintain long-term access that cannot be removed by credential rotation alone.

https://thehackernews.com/2026/07/russian-hackers-exploit-microsoft-owa.html

Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon

Attackers are exploiting Microsoft’s legitimate login system by directing victims to real Microsoft sign-in pages to grant permissions to malicious apps, enabling phishing campaigns to bypass traditional detection. This method, observed in over 200 phishing emails targeting around 120 organizations worldwide, allows attackers to access email, files, Teams, SharePoint, OneDrive, and calendars within the victim’s Microsoft 365 environment. The campaign emphasizes the growing threat of abuse of trusted authentication flows and highlights the need for vigilance despite appearances of legitimate Microsoft login prompts.

https://blog.checkpoint.com/email-security/attackers-are-turning-microsofts-trusted-login-system-into-their-latest-phishing-weapon/

Hackers Compromise Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts

Hackers have compromised hotel Wi-Fi gateways to redirect employees connecting to the network to fake Microsoft 365 login pages, enabling them to steal credentials and authorization tokens without phishing emails or malware. The attack, identified by ReliaQuest since June 2026 across multiple countries, involves DNS manipulation and may exploit weak administrator passwords on gateway devices. Using an always-on VPN that routes traffic through a company network can prevent these redirects, while employees should reject unexpected Microsoft login prompts on public Wi-Fi.

https://hackread.com/hackers-hotel-wi-fi-gateways-hijack-microsoft-365-accounts/

Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials

A threat actor has been compromising public Wi-Fi gateway appliances at venues like hotels and conference centers across the US, India, and Saudi Arabia to hijack DNS settings and redirect users to attacker-controlled sites, harvesting Microsoft 365 credentials of traveling corporate employees. This ongoing campaign since June 2026 resembles tactics used by the Russian-linked APT28 group but shows differences in infrastructure and targeting, suggesting a possible reuse of known tradecraft by a different actor. Organizations providing captive portal Wi-Fi services face heightened risks as attackers employ adversary-in-the-middle techniques to intercept sensitive information from multiple industries.

https://www.securityweek.com/hacked-public-wi-fi-gateways-used-to-harvest-corporate-credentials/

ConsentFix: a New ClickFix Variation for Compromising Microsoft 365 Accounts

Researchers have identified ConsentFix, a new variation of the ClickFix social engineering attack that enables cybercriminals to hijack Microsoft 365 accounts via OAuth tokens without stealing passwords. By tricking users into dragging a session token URL into an attacker-controlled page during a fake authentication process, attackers gain access to corporate email, documents, Teams, and other cloud services, facilitating data exfiltration and lateral movement within organizations. The widespread availability of ConsentFix attack blueprints increases the risk of such intrusions, highlighting the need for robust email security solutions and employee awareness training.

https://www.kaspersky.com/blog/consentfix-microsoft-365-account-hijacking/56155/

Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday

Security researcher Chaotic Eclipse released a new proof-of-concept exploit called LegacyHive, which leverages a Windows User Profile Service vulnerability to achieve arbitrary hive load elevation of privileges. The exploit works on all supported Windows versions, including those patched in the latest July 2026 update, and allows non-admin users to modify registry hives of other accounts, posing a significant privilege escalation risk. Microsoft is investigating the vulnerability and committed to addressing it, while the incident highlights ongoing challenges in coordinated vulnerability disclosure and security patching.

https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html

Microsoft’s Secure Boot Has Been Broken for a Decade and No One Noticed Until Now

Researchers at security firm ESET discovered that Microsoft’s Secure Boot, designed to prevent malicious firmware infections, has been bypassable for 13 years due to old, vulnerable “shim” binaries that were never revoked despite known defects. This flaw affects both Windows and Linux devices by allowing attackers to load malicious firmware at boot time, persisting even after OS reinstallation; Microsoft only revoked the faulty shims after ESET’s report in June 2026. The incident highlights inherent complexity and trust issues in the Secure Boot model, which depends heavily on Microsoft’s oversight and has struggled to handle revocations and scaling effectively.

https://arstechnica.com/security/2026/07/microsoft-secure-boot-has-been-broken-for-most-of-its-existence/

Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack

Microsoft released its largest Patch Tuesday to date, addressing 622 vulnerabilities, including two zero-day elevation-of-privilege flaws actively exploited in SharePoint Server (CVE-2026-56164) and Active Directory Federation Services (CVE-2026-56155). Organizations are urged to prioritize these patches despite their moderate severity ratings, as both affect critical identity and collaboration infrastructure, and attackers are currently exploiting them. The update also ends support for SharePoint Server 2016 and 2019, and continues Kerberos RC4 hardening, which may cause authentication issues if service accounts still rely on RC4.

https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html

Evolving Windows Vulnerability Management to Meet the Speed of AI-powered Discovery

Microsoft is enhancing Windows vulnerability management by leveraging AI-powered tools like the multi-model agentic scanning harness (MDASH) to accelerate discovery, prioritization, and remediation of security issues across its codebase. The company integrates AI into its engineering and validation processes to speed up fixes while maintaining update quality, and provides customers with tools and guidance to deploy timely security updates safely, supporting a shift toward continuous, risk-based patching to reduce exposure amid growing AI-driven vulnerability discovery.

https://blogs.windows.com/windowsexperience/2026/07/09/evolving-windows-vulnerability-management-to-meet-the-speed-of-ai-powered-discovery/

Patch for Windows Defender 0-Day Could Allow Attackers to Fill Hard Disk

A patch released by Microsoft to fix a zero-day vulnerability (CVE-2026-50656) in the Windows Defender malware protection engine may cause affected Windows machines to write excessively large files that can fill the hard disk. Researcher NightmareEclipse reported that new defense-in-depth mitigations introduced in the patch cause the engine to leak data when handling certain files and their associated Zone.Identifier metadata, potentially allowing attackers to exhaust disk space via specially crafted SMB server responses. Microsoft has not yet confirmed the disk-filling behavior, while the researcher’s ongoing public disclosures highlight a continued dispute with Microsoft over vulnerability handling.

https://arstechnica.com/security/2026/07/patch-for-windows-defender-0-day-could-allow-attackers-to-fill-hard-disk/

Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges

Microsoft has released a security update to patch a privilege escalation vulnerability known as RoguePlanet (CVE-2026-50656) in its Malware Protection Engine, which could allow attackers to gain SYSTEM-level privileges and execute arbitrary code. The flaw, disclosed by researcher Chaotic Eclipse, exploited a race condition and affected fully patched Windows systems, but Microsoft’s update has mitigated the issue along with adding defense-in-depth improvements. Additionally, the researcher identified a potential new data leak caused by the patch that requires further investigation.

https://thehackernews.com/2026/07/microsoft-patches-rogueplanet-defender.html

Entra Passkey Enrollment Vishing Targets Microsoft 365 Users

A threat actor tracked as O-UNC-066 has been conducting vishing campaigns targeting Microsoft 365 users across multiple industries by impersonating Microsoft Entra passkey enrollment processes. Attackers use phishing sites mimicking legitimate enrollment portals to trick victims into registering passkeys controlled by the attacker, enabling account takeover and data theft from SharePoint and OneDrive. The extortion group Pink, associated with this campaign, exfiltrates stolen data and pressures victims for ransom payments.

https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vishing-targets-microsoft-365-users/

When Checking the URL Isn’t Enough: Phishing Via the Microsoft Identity Platform

The article discusses a sophisticated phishing technique that abuses the Microsoft identity platform’s device code flow, making it difficult to detect purely by checking URLs. Attackers leverage this method to bypass traditional phishing defenses by exploiting trusted Microsoft OAuth authentication processes, highlighting the need for enhanced vigilance and security measures beyond URL inspection to defend against such threats.

https://securelist.com/microsoft-device-code-phishing-attack/120350/

Scroll to Top