Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > Microsoft
#Microsoft

N0va Phishing Kit Hijacks Real Microsoft Logins to Steal Session Tokens

10 September 2026  |  dark6  |  Phishing

A new phishing kit called N0va abuses legitimate device-code authentication flows for Microsoft, Google, and other trusted services to steal access and refresh tokens rather than passwords. The...

>> read more

Microsoft’s September Patch Wave Fixes 973 Flaws and Two Exploited Zero-Days

9 September 2026  |  dark6  |  Vulnerability

Microsoft’s September 2026 security release addresses 973 vulnerabilities across Windows, Office, SQL Server and other enterprise products. Two privilege-escalation zero-days are already being exploited, making rapid testing and...

>> read more

Microsoft’s September Patch Tuesday Closes 973 Holes, Including Two Zero-Days Already Under Attack

9 September 2026  |  dark6  |  Vulnerability

Microsoft's September 2026 security update addresses 973 vulnerabilities — one of its largest releases on record — including two Windows elevation-of-privilege flaws that attackers are actively exploiting. Several...

>> read more

Microsoft’s New Windows Tool Quietly Resets Chrome, Firefox, and Brave to Bing

24 August 2026  |  dark6  |  Privacy

A newly spotted Microsoft installer called MicrosoftSettings.exe pushes a browser extension that switches Chrome, Firefox, and Brave over to Bing search and the MSN homepage. Security researchers note...

>> read more

Microsoft Confirms Entra ID Zero-Day Was Exploited Before the Fix Went Live

21 August 2026  |  dark6  |  Vulnerability

Microsoft has disclosed CVE-2026-69836, a maximum-severity deserialization flaw in Entra ID that attackers exploited in the wild before the company silently patched it server-side. There is no customer...

>> read more

CISA Gives Agencies Until August 21 to Patch Actively Exploited Windows VPN Flaw

20 August 2026  |  dark6  |  Vulnerability

CISA has added a double-free memory corruption bug in Microsoft's Internet Key Exchange service extensions to its Known Exploited Vulnerabilities catalog after confirming active attacks, giving federal agencies...

>> read more

Four Chained Flaws in Microsoft SCCM Let Any Domain User Seize Full Server Control

18 August 2026  |  dark6  |  Vulnerability

A newly disclosed exploit chain in Microsoft System Center Configuration Manager, tracked as CVE-2026-47301, lets a standard Active Directory user achieve remote code execution as SYSTEM on the...

>> read more

Microsoft Is Merging Consumer and Enterprise Copilot — Security Teams Should Watch the Seams

17 August 2026  |  dark6  |  AI

Microsoft is consolidating its consumer and business Copilot apps into a single Microsoft 365 Copilot experience, reachable from a unified m365.cloud.Microsoft address. Microsoft insists personal and organizational data...

>> read more