microsoft

Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker

Iran-linked hacktivist group Handala claims responsibility for a data-wiping attack on Stryker, a major medical technology company. The attack forced the shutdown of Stryker's global operations, impacting over 200,000 devices and disrupting supply chains for healthcare providers. The group stated the action was retaliation for a missile strike in Iran that killed many civilians. The incident has raised concerns about cybersecurity in the healthcare sector, as hospitals consider disconnecting from Stryker's services amid the attack.

https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/

Microsoft Reveals ClickFix Campaign Using Windows Terminal to Deploy Lumma Stealer

Microsoft revealed a new phishing campaign, ClickFix, using Windows Terminal to deploy Lumma Stealer malware. The campaign tricks users into executing commands via a trusted app, bypassing detection methods aimed at the Run dialog. It executes a multi-stage attack: downloading and extracting malicious scripts, collecting credentials from browsers, and establishing persistence. The malware targets sensitive data, emphasizing the risks of social engineering tactics in cybersecurity.

https://thehackernews.com/2026/03/microsoft-reveals-clickfix-campaign.html

Inside Tycoon2FA: How a Leading AiTM Phishing Kit Operated at Scale

The article analyzes Tycoon2FA, a phishing-as-a-service platform that enabled large-scale adversary-in-the-middle (AiTM) attacks capable of bypassing multifactor authentication. It explains how the service intercepted login credentials and session cookies through proxy phishing pages that mimicked services such as Microsoft 365 and Gmail. The platform included evasion techniques and user-friendly infrastructure, enabling less-skilled attackers to run campaigns that reached hundreds of thousands of organizations each month. The article concludes with guidance on layered defenses, including improved authentication methods, phishing detection, and coordinated disruption efforts. 

https://www.microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/

Hackers Target Microsoft Entra Accounts in Device Code Vishing Attacks

Hackers are targeting Microsoft Entra accounts using device code phishing and voice vishing, compromising accounts through legitimate Microsoft OAuth flows without needing traditional phishing methods. This allows attackers to gain valid authentication tokens and access victims' accounts, enabling corporate data theft. The ShinyHunters gang is suspected to be behind these attacks, with recommendations for organizations to monitor OAuth apps, revoke suspicious consents, and consider disabling device code flows when unnecessary.

https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks/

Microsoft Says Bug Causes Copilot to Summarize Confidential Emails

Microsoft 365 Copilot bug since January causes AI to incorrectly summarize confidential emails, bypassing DLP policies. A code error allows emails marked with confidentiality labels to be processed, prompting Microsoft to initiate a fix. As of mid-February, they continue monitoring the situation but have not disclosed the full impact or timeline for resolution.

https://www.bleepingcomputer.com/news/microsoft/microsoft-says-bug-causes-copilot-to-summarize-confidential-emails/

Flaws in Popular VSCode Extensions Expose Developers to Attacks

Flaws in popular VSCode extensions allow attackers to steal files and execute code. Vulnerabilities affect extensions like Code Runner and Markdown Preview Enhanced, with over 128 million total downloads. Discovered by Ox Security, the issues pose risks such as data exfiltration and system takeover. Developers are advised against using untrusted configurations and to only install reputable extensions.

https://www.bleepingcomputer.com/news/security/flaws-in-popular-vscode-extensions-expose-developers-to-attacks/

CyberheistNews Vol 16 #07 Uncovering the Sophisticated Phishing Campaign Bypassing M365 MFA

Phishing campaign bypassing M365 MFA detected, compromising accounts by exploiting OAuth 2.0 flows. Attackers trick users into authenticating on legitimate Microsoft domains, stealing access tokens for persistent access to data. Key sectors targeted include tech, manufacturing, and finance. Immediate mitigation requires auditing OAuth apps and reviewing email logs. Additionally, there’s discussion on automation in incident response, AI-driven email security, and the evolution of romance scams using deepfake technology. New voice phishing kits enable real-time control over attacks, raising concerns over email security gaps in organizations.

https://blog.knowbe4.com/cyberheistnews-vol-16-07-uncovering-the-sophisticated-phishing-campaign-bypassing-m365-mfa

Microsoft Discloses DNS-Based ClickFix Attack Using Nslookup for Malware Staging

Microsoft revealed a new ClickFix attack utilizing nslookup for malware staging. Attackers trick users into running DNS lookups to retrieve malicious payloads, circumventing security measures by having victims infect their own machines. This technique has evolved into various forms and leverages DNS traffic as a stealthy method of signaling to malicious infrastructure. The attack can lead to further malware deployment, including remote access trojans and information stealers, particularly targeting both Windows and macOS users amidst rising incidents of cryptocurrency theft.

https://thehackernews.com/2026/02/microsoft-discloses-dns-based-clickfix.html

Microsoft Warns That Poisoned AI Buttons and Links May Betray Your Trust

Microsoft warns of “AI Recommendation Poisoning,” a technique where malicious data manipulates AI responses, risking trust in AI services. Companies have been embedding hidden prompts in AI links, influencing outputs subtly. This can result in AI providing biased advice on crucial topics like health and finance, often unnoticed by users. Microsoft advises caution with AI-related links, reviewing AI memory, and scanning for manipulation attempts in corporate settings.

https://www.theregister.com/2026/02/12/microsoft_ai_recommendation_poisoning/

Russia-linked Attackers Abuse New Microsoft Office Zero-day

Russia-linked APT28 hackers exploit latest Microsoft Office zero-day, targeting Ukrainian government and EU organizations. Ukraine's CERT reports rapid weaponization of the CVE-2026-21509 vulnerability, leading to phishing campaigns and malware deployment via malicious DOC files. Microsoft has issued patches, but concerns about increasing cyberattacks persist due to slow user updates.

https://www.theregister.com/2026/02/02/russialinked_apt28_microsoft_office_bug/

Microsoft Gave FBI Keys To Unlock Encrypted Data, Exposing Major Privacy Flaw

Microsoft provided the FBI with encryption keys for BitLocker-protected data on three laptops, following a warrant related to a Covid unemployment assistance fraud investigation in Guam. This case marks the first known instance of Microsoft providing law enforcement with encryption keys. Privacy experts criticize Microsoft for this decision, arguing that it compromises user privacy and security, and urging the company to adopt stronger protections like those offered by Apple and Google.

https://www.forbes.com/sites/thomasbrewster/2026/01/22/microsoft-gave-fbi-keys-to-unlock-bitlocker-encrypted-data/

Microsoft Knocks Offline RedVDS Cybercrime Marketplace Linked to $40M in Fraud

Microsoft disrupted the RedVDS cybercrime marketplace, linked to $40 million in fraud, by seizing key infrastructure and working with international law enforcement. RedVDS enabled mass phishing and account takeover campaigns, compromising over 191,000 organizations worldwide. The service sold access to Windows RDP servers, leaving behind technical indicators like a shared computer name and a cloned Windows Server 2022 image.

https://redmondmag.com/articles/2026/01/15/microsoft-knocks-offline-redvds-cybercrime-marketplace.aspx

Reprompt: The Single-Click Microsoft Copilot Attack That Silently Steals Your Personal Data

Varonis Threat Labs identified a new AI vulnerability called Reprompt in Microsoft Copilot that allows attackers to exploit a single click on a seemingly legitimate link to bypass security controls and exfiltrate sensitive user data without detection. This attack can lead to significant data breaches by firing off malicious commands that continue even after the user interacts with the Copilot. Key methods involve URL parameter manipulation and managing hidden follow-up requests, making it difficult to spot the exploitation attempts. Microsoft has since patched the vulnerability. Recommendations are made for both vendors and users to enhance security against such vulnerabilities.

https://www.varonis.com/blog/reprompt

State-linked and Criminal Hackers Use Device Code Phishing Against M365 Users

State-linked hackers exploit device code phishing to target Microsoft 365 users, using techniques that impersonate legitimate access workflows. Groups from Russia and China lead recent attacks, employing tools like SquarePhish2 and Graphish phishing kits. This method involves users entering a device code, granting hackers access to their accounts. Cybersecurity firm Proofpoint notes the increased use of this tactic for attacks on various sectors, including government and education.

https://www.cybersecuritydive.com/news/state-linked-criminal-hackers-device-code-phishing-m365/808396/

Scroll to Top