Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

26 / 96 results
Active filter:vendor: microsoft✕ clear
Edgecution: Malicious Edge Extension Enables Sandbox Escapehighperson_alertThreat Actor
person_alertThreat Actor

Edgecution: Malicious Edge Extension Enables Sandbox Escape

Edgecution is a malicious browser extension targeting Microsoft Edge, not a threat actor group. It functions as a tool deployed during ransomware operations to facilitate sandbox escape and establish persistence.

Microsoft18:58 UTC
Europol disrupts Amadey and StealC infrastructure, recovers 27M credentialshighperson_alertThreat Actor
person_alertThreat Actor

Europol disrupts Amadey and StealC infrastructure, recovers 27M credentials

This report describes a law enforcement disruption operation led by Europol in partnership with private sector entities including Bitdefender, Bitsight, ESET, and Microsoft.

Bitdefender13:59 UTC
Europol-led Operation Endgame disrupts Amadey and StealC infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

Europol-led Operation Endgame disrupts Amadey and StealC infrastructure

Europol is a law enforcement agency coordinating international cybercrime investigations. In this context, Europol led Operation Endgame, a coordinated law enforcement action involving Microsoft and international partners targeting cybercriminal infr…

Microsoft12:35 UTC
CI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeovercriticalbug_reportVulnerability
bug_reportVulnerability

CI/CD flaw "Cordyceps" exposes 300+ GitHub repos to supply-chain takeover

300+ GitHub repositories across major organizations including Microsoft, Google, and Apache. Vulnerability affects GitHub Actions CI/CD workflows. Specific products and versions not disclosed in available data.

Microsoft10:48 UTC
Microsoft DCU disrupts StealC and Amadey infostealer infrastructurehighbug_reportVulnerability
bug_reportVulnerability

Microsoft DCU disrupts StealC and Amadey infostealer infrastructure

Organizations globally using Windows systems targeted by StealC and Amadey infostealer malware-as-a-service operations. Infrastructure takedown executed June 24, 2026.

Microsoft10:30 UTC
Microsoft patches AutoJack vulnerability chain in AutoGen Studiohighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches AutoJack vulnerability chain in AutoGen Studio

Microsoft AutoGen Studio - all versions prior to the patched release. AutoGen Studio is a low-code interface for building and managing AI agents. The vulnerability chain affects users who interact with untrusted web content while AutoGen Studio is ru…

Microsoft15:28 UTC
Dual ransomware actors operate simultaneously in Microsoft environmentshighbug_reportVulnerability
bug_reportVulnerability

Dual ransomware actors operate simultaneously in Microsoft environments

Organizations using Microsoft environments, particularly those with insufficient network segmentation and endpoint visibility. No specific product vulnerability; threat involves operational security gaps enabling parallel intrusions.

Microsoft14:00 UTC
AutoJack exploit chain enables RCE on AI browsing agents via malicious pageshighbug_reportVulnerability
bug_reportVulnerability

AutoJack exploit chain enables RCE on AI browsing agents via malicious pages

AI browsing agents (autonomous web browsers with AI capabilities) that interact with privileged local services via JavaScript. Specific products and versions not disclosed in Microsoft's research disclosure.

Microsoft13:30 UTC
AutoJack exploit chain enables RCE on AI agent hosts via malicious webpagecriticalbug_reportVulnerability
bug_reportVulnerability

AutoJack exploit chain enables RCE on AI agent hosts via malicious webpage

Microsoft AutoGen Studio users running AI browsing agents. Affects deployments where AutoGen Studio's MCP WebSocket is accessible to localhost without authentication. Specific version range not disclosed.

Microsoft22:17 UTC
Windows cryptocurrency clipper campaign uses USB worms and Tor C2highbug_reportVulnerability
bug_reportVulnerability

Windows cryptocurrency clipper campaign uses USB worms and Tor C2

Windows systems with Windows Script Host and ActiveX enabled. Campaign active since February 2026 targeting cryptocurrency users via USB-based LNK worm propagation.

Microsoft12:30 UTC
DragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

DragonForce Deploys Backdoor.Turn RAT via Microsoft Teams Infrastructure

DragonForce is a threat actor associated with ransomware operations. The group has demonstrated advanced capabilities in developing custom tooling and leveraging legitimate cloud infrastructure for command-and-control communications.

Microsoft11:30 UTC
Cryptocurrency clipper malware with worm propagation targets Windowshighbug_reportVulnerability
bug_reportVulnerability

Cryptocurrency clipper malware with worm propagation targets Windows

Windows systems globally. No specific product vulnerability; threat relies on social engineering, malicious downloads, or lateral movement. All cryptocurrency wallet users on Windows are potential targets.

Microsoft21:11 UTC
Microsoft Defender zero-day CVE-2026-50656 enables privilege escalationhighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day CVE-2026-50656 enables privilege escalation

Microsoft Defender Malware Protection Engine across all Windows versions. Specific affected engine versions not disclosed. Impacts enterprise and consumer deployments relying on Microsoft Defender for endpoint protection.

CVE-2026-5065615:36 UTC
Windows June updates break Office launch from third-party appshighbug_reportVulnerability
bug_reportVulnerability

Windows June updates break Office launch from third-party apps

Windows systems with June 2024 updates installed. Affects third-party applications attempting to launch Microsoft Office applications or open Office documents. Specific Windows versions not yet disclosed by Microsoft.

Microsoft09:54 UTC
Microsoft Defender zero-day "RoguePlanet" awaits patch after disclosurehighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day "RoguePlanet" awaits patch after disclosure

Microsoft Defender (all versions currently deployed). Specific affected versions not disclosed. Impacts organizations relying on Defender for endpoint protection.

Microsoft06:32 UTC
GhostTree Abuses NTFS Junctions to Evade Microsoft Defender Scanshighperson_alertThreat Actor
person_alertThreat Actor

GhostTree Abuses NTFS Junctions to Evade Microsoft Defender Scans

GhostTree is a threat actor that has developed an evasion technique exploiting recursive NTFS junctions to bypass antivirus scanning. The actor targets the information technology sector and leverages inherent Windows file system features to create in…

Microsoft12:17 UTC
DragonForce Ransomware Gang Deploys Backdoor.Turn via Teams Infrastructurehighperson_alertThreat Actor
person_alertThreat Actor

DragonForce Ransomware Gang Deploys Backdoor.Turn via Teams Infrastructure

DragonForce is a ransomware gang that has developed custom tooling to support their extortion operations. The group demonstrates advanced capabilities in developing bespoke malware and leveraging legitimate cloud infrastructure for command-and-contro…

Microsoft08:18 UTC
ScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lureshighperson_alertThreat Actor
person_alertThreat Actor

ScarCruft Deploys NarwhalRAT via Microsoft Account Phishing Lures

ScarCruft (also tracked as APT37, InkySquid, Reaper, and Group123) is a North Korean state-sponsored advanced persistent threat group. The actor is attributed to North Korea's intelligence apparatus and conducts espionage operations aligned with Pyon…

Microsoft06:14 UTC
Microsoft 365 Copilot SearchLeak allows data exfiltration via trusted linkhighbug_reportVulnerability
bug_reportVulnerability

Microsoft 365 Copilot SearchLeak allows data exfiltration via trusted link

Microsoft 365 Copilot Enterprise Search. All organizations using M365 Copilot with Enterprise Search enabled are potentially affected. Specific version details not disclosed.

Microsoft13:09 UTC
SearchLeak in Microsoft 365 Copilot enables data theft via crafted URLscriticalbug_reportVulnerability
bug_reportVulnerability

SearchLeak in Microsoft 365 Copilot enables data theft via crafted URLs

Microsoft 365 Copilot Enterprise. All organizations using Copilot with access to mailbox, OneDrive, or SharePoint data are potentially affected. Specific vulnerable versions not disclosed.

Microsoft11:00 UTC
BitLocker bypass via recovery partition XML files (GreatXML)highbug_reportVulnerability
bug_reportVulnerability

BitLocker bypass via recovery partition XML files (GreatXML)

Windows BitLocker encryption on systems with recovery partitions. All Windows versions with BitLocker enabled are potentially affected. Specific version scope not yet published.

Microsoft15:43 UTC
Microsoft June 2025 Patch Tuesday: 206 vulnerabilities, 33 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft June 2025 Patch Tuesday: 206 vulnerabilities, 33 critical

Microsoft products across the ecosystem. 206 total vulnerabilities: 33 critical, 173 important severity. Specific affected products and CVE identifiers not yet detailed in available information.

Microsoft13:47 UTC
Microsoft patches actively exploited XSS zero-day in Exchange Server OWAhighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches actively exploited XSS zero-day in Exchange Server OWA

Microsoft Exchange Server (all versions with Outlook Web Access enabled). Specific patched versions not provided. Affects organizations exposing OWA to users.

Microsoft11:44 UTC
Microsoft patches 3 zero-days: YellowKey, GreenPlasma, MiniPlasmacriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches 3 zero-days: YellowKey, GreenPlasma, MiniPlasma

All fully patched Windows systems prior to latest patch release. YellowKey and GreenPlasma enable SYSTEM privilege escalation; MiniPlasma bypasses BitLocker encryption on protected drives.

Microsoft07:57 UTC
Microsoft patches 206 vulnerabilities including 3 zero-days, 39 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches 206 vulnerabilities including 3 zero-days, 39 critical

Microsoft software portfolio: 206 vulnerabilities patched including 56 remote code execution (RCE) flaws, 63 privilege escalation issues, 39 critical-severity vulnerabilities, and 3 actively exploited zero-day flaws.

Microsoft07:38 UTC
Windows Server domain controllers under active RCE attackcriticalbug_reportVulnerability
bug_reportVulnerability

Windows Server domain controllers under active RCE attack

Windows Server domain controllers (all supported versions). Specific version details not yet published by Microsoft. Unauthenticated remote code execution vulnerability.

Microsoft06:47 UTC