Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

20 / 96 results
Active filter:vendor: microsoft✕ clear
Microsoft Defender zero-day "RoguePlanet" exploited for SYSTEM accesscriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day "RoguePlanet" exploited for SYSTEM access

Microsoft Defender on all updated Windows systems. No CVE assigned yet. Vulnerability is a race condition enabling local privilege escalation to SYSTEM.

Microsoft03:22 UTC
Microsoft Defender zero-day 'RoguePlanet' enables SYSTEM privilege escalationcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender zero-day 'RoguePlanet' enables SYSTEM privilege escalation

Microsoft Defender on Windows systems. Specific affected versions not disclosed. Given Defender's deployment, scope includes enterprise endpoints, servers running Defender, and consumer Windows installations with default security configuration.

Microsoft21:11 UTC
Microsoft June 2026 Patch Tuesday: ~200 patches, 36 critical, 3 with PoCscriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft June 2026 Patch Tuesday: ~200 patches, 36 critical, 3 with PoCs

Microsoft products across the portfolio. Approximately 200 vulnerabilities patched, including ~36 critical-severity issues. At least 3 vulnerabilities have public proof-of-concept exploit code available.

Microsoft20:07 UTC
Microsoft June 2026 Patch Tuesday: 200 flaws, 3 disclosed zero-dayshighbug_reportVulnerability
bug_reportVulnerability

Microsoft June 2026 Patch Tuesday: 200 flaws, 3 disclosed zero-days

Microsoft products across the ecosystem. 200 vulnerabilities patched, including 3 publicly disclosed zero-day vulnerabilities. Specific affected products and CVE identifiers not yet detailed in available information.

Microsoft15:57 UTC
Microsoft GitHub repos compromised, 73 disabled for distributing malwarehighbug_reportVulnerability
bug_reportVulnerability

Microsoft GitHub repos compromised, 73 disabled for distributing malware

73 repositories across Microsoft's official GitHub organizations (Azure, microsoft, Azure-Samples, MicrosoftDocs). Organizations using Microsoft sample code, Azure templates, or CI/CD pipelines referencing these repositories are potentially affected.

Microsoft13:42 UTC
Miasma worm compromises 73 Microsoft GitHub repos in supply chain attackhighbug_reportVulnerability
bug_reportVulnerability

Miasma worm compromises 73 Microsoft GitHub repos in supply chain attack

73 Microsoft GitHub repositories across four organizations: Azure, Azure-Samples, Microsoft, and MicrosoftDocs. GitHub has disabled access to affected repositories.

Microsoft04:58 UTC
UNC5221 Deploys Brickstorm, Plenet, AgentPSD in M365 Espionage Campaignhighperson_alertThreat Actor
person_alertThreat Actor

UNC5221 Deploys Brickstorm, Plenet, AgentPSD in M365 Espionage Campaign

UNC5221 is a Chinese APT group attributed to conducting cyber espionage operations. The group demonstrates advanced capabilities in targeting cloud environments, specifically Microsoft 365 infrastructure.

Microsoft16:09 UTC
OP-512 Targets IIS Servers with Custom Web Shell Frameworkhighperson_alertThreat Actor
person_alertThreat Actor

OP-512 Targets IIS Servers with Custom Web Shell Framework

OP-512 is a previously unreported threat cluster assessed by ReliaQuest with moderate to high confidence to be linked to China. The actor demonstrates espionage-focused objectives, leveraging custom web shell frameworks to compromise Microsoft Intern…

Microsoft10:33 UTC
Windows Netlogon RCE under active exploitation after patch releasecriticalbug_reportVulnerability
bug_reportVulnerability

Windows Netlogon RCE under active exploitation after patch release

Microsoft Windows Netlogon service, all versions prior to recent patch. Affects domain controllers and systems with Netlogon service enabled. Specific CVE and affected version details not provided in alert.

Microsoft10:30 UTC
Microsoft May 2026 Patch Tuesday: 118 vulnerabilities, 16 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft May 2026 Patch Tuesday: 118 vulnerabilities, 16 critical

Microsoft products and services across the ecosystem. 118 total vulnerabilities: 16 critical severity, 102 important severity. Specific affected products and CVE identifiers not yet detailed in available information.

Microsoft14:06 UTC
Storm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilitieshighperson_alertThreat Actor
person_alertThreat Actor

Storm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilities

Storm-2697 is a threat actor tracked by Microsoft Threat Intelligence that operates as a ransomware affiliate group. The actor deploys The Gentlemen ransomware, a sophisticated Go-based encryption tool, suggesting technical proficiency in modern prog…

Microsoft13:00 UTC
Microsoft SharePoint RCE vulnerability requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE vulnerability requires immediate patching

Microsoft SharePoint Server (specific versions not disclosed in advisory). Organizations running on-premises SharePoint deployments are affected. SharePoint Online managed by Microsoft likely already patched.

Microsoft14:23 UTC
AI chatbot abuse delivers cryptojacking malware via social engineeringhighbug_reportVulnerability
bug_reportVulnerability

AI chatbot abuse delivers cryptojacking malware via social engineering

Users of AI chatbots (platform-agnostic); Windows systems targeted for cryptojacking payload deployment. Campaign actively observed by Microsoft; no specific product vulnerability, relies on social engineering.

Microsoft05:45 UTC
Cryptojacking campaign uses SEO poisoning and ScreenConnect for GPU mininghighbug_reportVulnerability
bug_reportVulnerability

Cryptojacking campaign uses SEO poisoning and ScreenConnect for GPU mining

Organizations using ScreenConnect remote access software; high-performance PCs with GPUs; users searching for compromised topics via search engines and AI chatbots. Campaign leverages Microsoft .NET utilities for execution.

Microsoft19:35 UTC
Microsoft patches SharePoint RCE flaw via unsafe deserializationhighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches SharePoint RCE flaw via unsafe deserialization

Microsoft SharePoint Server (specific versions not disclosed). Vulnerability involves deserialization of untrusted data leading to remote code execution with CVSS 8.8.

CVE-2026-4565909:49 UTC
Windows Server 2016 domain controller lookups fail after KB5087537 updatehighbug_reportVulnerability
bug_reportVulnerability

Windows Server 2016 domain controller lookups fail after KB5087537 update

Windows Server 2016 domain controllers running KB5087537 (May 2026 security update). Impacts Active Directory domain controller lookup functionality and domain connectivity.

Microsoft05:41 UTC
FBI warns of Kali365 phishing-as-a-service targeting Microsoft 365highperson_alertThreat Actor
person_alertThreat Actor

FBI warns of Kali365 phishing-as-a-service targeting Microsoft 365

Kali365 is a phishing-as-a-service (PhaaS) platform that enables threat actors to conduct credential harvesting and account takeover operations against Microsoft 365 users.

Microsoft10:45 UTC
F5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movementhighperson_alertThreat Actor
person_alertThreat Actor

F5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movement

The threat actor behind this campaign remains unattributed. Motivation appears to be credential theft and network persistence within enterprise environments.

F514:53 UTC
Microsoft Defender privilege escalation CVE-2026-41091 under active exploithighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender privilege escalation CVE-2026-41091 under active exploit

Microsoft Defender on Windows systems. Specific product versions not disclosed. Vulnerability allows local attackers to escalate privileges to SYSTEM level through improper link resolution handling.

CVE-2026-4109108:55 UTC
Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operationcriticalperson_alertThreat Actor
person_alertThreat Actor

Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operation

Fox Tempest is a threat actor attributed by Microsoft as operating a malware-signing-as-a-service (MSaaS) business model. The actor exploited Microsoft's Artifact Signing system to provide malicious code signing services to other cybercriminals, enab…

Microsoft12:36 UTC