Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

23 / 195 results
Active filter:vendor: microsoft✕ clear
Malicious VS Code extensions steal crypto wallets and credentials from devshighbug_reportVulnerability
bug_reportVulnerability

Malicious VS Code extensions steal crypto wallets and credentials from devs

Microsoft Visual Studio Code users who installed "Solidity Pro" extensions (helper-beeps.solidity-pro or web3devtoolsx.solidity-pro) from Open VSX marketplace. Extensions targeted Ethereum/Web3 developers.

Microsoft10 Aug · 05:38 UTC
CSS attacks bypass webmail sanitizers to steal passwords and tokenshighbug_reportVulnerability
bug_reportVulnerability

CSS attacks bypass webmail sanitizers to steal passwords and tokens

Microsoft Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail webmail interfaces. Attacks exploit CSS and HTML parsing discrepancies to escape message boundaries.

Microsoft8 Aug · 06:03 UTC
NatJack attacks hijack TCP sessions via NAT manipulation; Windows & Linux CVEshighbug_reportVulnerability
bug_reportVulnerability

NatJack attacks hijack TCP sessions via NAT manipulation; Windows & Linux CVEs

Windows NAT (Hyper-V): Windows 11 24H2 <26100.8875, 25H2 <26200.8875, 26H1 <28000.2525, Server 2025 <26100.33158 (CVE-2026-56181, CVSS 8.3). Linux Netfilter conntrack: kernel <5.10.259, <5.15.210, <6.1.176, <6.6.143, <6.12.93, <6.18.35, <7.0.12, <7.1…

Microsoft7 Aug · 08:58 UTC
AitM phishing campaign targets Microsoft 365 for payroll email thefthighbug_reportVulnerability
bug_reportVulnerability

AitM phishing campaign targets Microsoft 365 for payroll email theft

Microsoft 365 accounts across healthcare, education, manufacturing, government, and professional services sectors in the U.S., Canada, and Europe. Hundreds of organizations targeted in July 2026, with focus on payroll, HR, and finance personnel.

Microsoft7 Aug · 08:38 UTC
Malware can abuse Windows Hello for Business keys for persistent Entra ID accesshighbug_reportVulnerability
bug_reportVulnerability

Malware can abuse Windows Hello for Business keys for persistent Entra ID access

Windows Hello for Business on all Windows versions with Entra ID integration. Affects organizations using Windows Hello for Business as phishing-resistant authentication. TPM-backed and non-TPM deployments both vulnerable.

Microsoft7 Aug · 06:52 UTC
Swiss government SharePoint breach exposes 200 accounts via July flawshighpublicGeopolitical
publicGeopolitical

Swiss government SharePoint breach exposes 200 accounts via July flaws

The breach of Switzerland's Federal Office for Information Technology and Telecommunication (BIT) represents a significant compromise of neutral state infrastructure.

Microsoft6 Aug · 16:14 UTC
Kali365 Campaign Weaponizes Microsoft Device Code Flow Against US Firmshighperson_alertThreat Actor
person_alertThreat Actor

Kali365 Campaign Weaponizes Microsoft Device Code Flow Against US Firms

Kali365 is a device code phishing campaign targeting US organizations through abuse of legitimate Microsoft authentication mechanisms. The campaign leverages a phishing kit designed to trick victims into approving attacker-controlled device codes on…

Microsoft5 Aug · 09:43 UTC
Greatness PhaaS Expands to AiTM and Device-Code Phishing via RingCentralhighperson_alertThreat Actor
person_alertThreat Actor

Greatness PhaaS Expands to AiTM and Device-Code Phishing via RingCentral

Greatness is a phishing-as-a-service (PhaaS) platform active since at least mid-2022, operated by cybercriminals who sell access for $289/month via a Telegram channel with thousands of subscribers.

Microsoft4 Aug · 19:45 UTC
Microsoft Defender auto-isolates endpoint in 128 seconds at QNEThighperson_alertThreat Actor
person_alertThreat Actor

Microsoft Defender auto-isolates endpoint in 128 seconds at QNET

No specific threat actor is identified in this incident. The attack represents a common adversary pattern: initial access achieved directly on an endpoint, followed by attempted multi-stage payload delivery using living-off-the-land techniques.

Microsoft4 Aug · 15:54 UTC
Midnight Blizzard targets hospitality Wi-Fi in CaptiveCrunch campaignhighperson_alertThreat Actor
person_alertThreat Actor

Midnight Blizzard targets hospitality Wi-Fi in CaptiveCrunch campaign

Midnight Blizzard (APT29, also tracked as Storm-2945, IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo) is a Russian-attributed advanced persistent threat group linked to intelligence collection operations.

Microsoft3 Aug · 22:17 UTC
DOUBLECUP loader-as-a-service delivers malware via ClickFix attackshighperson_alertThreat Actor
person_alertThreat Actor

DOUBLECUP loader-as-a-service delivers malware via ClickFix attacks

DOUBLECUP is a Russian loader-as-a-service platform that has operated since early June 2026. The service provides customers with licenses and a Go-based Windows tool for creating malicious ClickFix campaigns.

Microsoft3 Aug · 18:01 UTC
Storm-2945 Hijacks Hotel Wi-Fi to Deploy CornFlake Surveillance RAThighperson_alertThreat Actor
person_alertThreat Actor

Storm-2945 Hijacks Hotel Wi-Fi to Deploy CornFlake Surveillance RAT

Storm-2945 is assessed by Microsoft to be an operational sub-cluster of Midnight Blizzard (APT29, Cozy Bear), which the U.S. and U.K. governments attribute to Russia's Foreign Intelligence Service (SVR). The U.K.

Microsoft1 Aug · 04:29 UTC
Azure Cosmos DB sandbox escape exposed platform-wide key to all databasescriticalbug_reportVulnerability
bug_reportVulnerability

Azure Cosmos DB sandbox escape exposed platform-wide key to all databases

Microsoft Azure Cosmos DB, all customer tenants across all regions. Affects Gremlin, SQL, MongoDB, and Cassandra APIs. Vulnerability active from unknown date until July 2026 full remediation.

Microsoft30 Jul · 11:34 UTC
Russian APT exploits OWA XSS flaw for persistent mailbox accesshighbug_reportVulnerability
bug_reportVulnerability

Russian APT exploits OWA XSS flaw for persistent mailbox access

Microsoft Outlook Web Access (OWA) vulnerable to CVE-2026-42897 (CVSS 8.1), a cross-site scripting flaw. Targets include U.S. and European government entities, telecommunications, financial, hospitality, and aerospace sectors.

Microsoft30 Jul · 05:40 UTC
Laundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoorcriticalperson_alertThreat Actor
person_alertThreat Actor

Laundry Bear exploits Exchange OWA zero-day to deploy OWAReaper backdoor

Laundry Bear (also tracked as Void Blizzard, TA488 by Proofpoint) is a Russian state-sponsored threat actor focused on long-term email intelligence collection.

Microsoft29 Jul · 21:44 UTC
Certighost PoC released: AD CS flaw enables domain takeover via rogue CAhighbug_reportVulnerability
bug_reportVulnerability

Certighost PoC released: AD CS flaw enables domain takeover via rogue CA

Microsoft Active Directory Certificate Services (AD CS) in Windows domains. CVE-2026-54121 patched in July 2026 Patch Tuesday. Affects environments using AD CS for certificate-based authentication where attackers have low-privileged domain user acces…

Microsoft27 Jul · 19:00 UTC
Operation BlueDash: Phishing Campaign Delivers RMM Tools via Fake Teamshighperson_alertThreat Actor
person_alertThreat Actor

Operation BlueDash: Phishing Campaign Delivers RMM Tools via Fake Teams

Operation BlueDash is a phishing campaign attributed with moderate-to-high confidence to a threat actor group operating from Nigeria. The attribution is based on analysis of infrastructure, code history, and a GitHub environment used to operate the c…

Microsoft27 Jul · 10:37 UTC
DNS hijacking on hotel Wi-Fi redirects users to fake Microsoft 365 loginshighbug_reportVulnerability
bug_reportVulnerability

DNS hijacking on hotel Wi-Fi redirects users to fake Microsoft 365 logins

Wi-Fi gateways at hotels and conference centers in multiple U.S. cities, India, and Saudi Arabia. Targets traveling employees from financial services, professional services, legal, healthcare, energy, and retail sectors accessing Microsoft 365.

Microsoft24 Jul · 15:50 UTC
BlueNoroff Phishing Kit Profiles Crypto Wallets Before Malware Deliveryhighperson_alertThreat Actor
person_alertThreat Actor

BlueNoroff Phishing Kit Profiles Crypto Wallets Before Malware Delivery

BlueNoroff (also tracked as APT38, NICKEL GLADSTONE, BeagleBoyz, Stardust Chollima) is a North Korean state-sponsored threat actor attributed to financially motivated operations targeting the cryptocurrency and technology sectors.

Zoom24 Jul · 13:12 UTC
Certighost exploit public for AD CS flaw allowing DC impersonationhighbug_reportVulnerability
bug_reportVulnerability

Certighost exploit public for AD CS flaw allowing DC impersonation

Microsoft Active Directory Certificate Services (AD CS) on Windows Server 2012 through 2025 (including Server Core) and Windows 10 versions 1607 and 1809. Environments with Enterprise CA and default Machine certificate template are vulnerable.

Microsoft24 Jul · 12:15 UTC
Bing Images SVG flaw allowed unauthenticated RCE as SYSTEM on serverscriticalbug_reportVulnerability
bug_reportVulnerability

Bing Images SVG flaw allowed unauthenticated RCE as SYSTEM on servers

Microsoft Bing Images service (CVE-2026-32194, CVE-2026-32191). Both Windows Server 2022 and Linux image-processing workers. Vulnerability exploitable via public "Search by Image" upload and URL-based image crawler.

CVE-2026-3219424 Jul · 09:45 UTC
Bing malvertising pushes fake Claude installer delivering SectopRAThighbug_reportVulnerability
bug_reportVulnerability

Bing malvertising pushes fake Claude installer delivering SectopRAT

Microsoft Bing search users seeking Claude AI desktop app. Malicious Claude Artifact hosted on legitimate claude.ai domain (removed by Anthropic). At least 29 organizations compromised July 21-22, 2026.

Microsoft23 Jul · 17:48 UTC
Microsoft 365 outage disrupts cloud services across North AmericahighpublicGeopolitical
publicGeopolitical

Microsoft 365 outage disrupts cloud services across North America

The incident represents a technical service disruption affecting critical cloud infrastructure rather than a geopolitical cyber event. Microsoft 365's position as backbone infrastructure for government, defense, and commercial operations in North Ame…

Microsoft23 Jul · 13:34 UTC