Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports

Filtered Reports

6 / 96 results
Active filter:vendor: microsoft✕ clear
Webworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph APIhighperson_alertThreat Actor
person_alertThreat Actor

Webworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph API

Webworm is a China-aligned advanced persistent threat (APT) actor first documented by Symantec in September 2022, with activity traced back to at least 2022.

Microsoft10:51 UTC
Microsoft mitigates YellowKey BitLocker bypass (CVE-2026-45585)highbug_reportVulnerability
bug_reportVulnerability

Microsoft mitigates YellowKey BitLocker bypass (CVE-2026-45585)

Microsoft BitLocker on Windows systems. Specific affected versions not disclosed. Vulnerability allows bypass of BitLocker disk encryption protections.

CVE-2026-4558506:28 UTC
Microsoft mitigates YellowKey BitLocker zero-day bypass vulnerabilityhighbug_reportVulnerability
bug_reportVulnerability

Microsoft mitigates YellowKey BitLocker zero-day bypass vulnerability

Windows BitLocker across all supported Windows versions. The vulnerability allows unauthorized access to BitLocker-protected drives. No CVE assigned yet.

Microsoft05:31 UTC
Microsoft sees rise in privilege escalation and identity abuse flawshighbug_reportVulnerability
bug_reportVulnerability

Microsoft sees rise in privilege escalation and identity abuse flaws

Microsoft products and services experiencing increased critical vulnerabilities focused on privilege escalation and identity abuse. Specific affected products and versions not detailed in available data.

Microsoft12:00 UTC
Microsoft Exchange Server XSS flaw actively exploited for session hijackingcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Exchange Server XSS flaw actively exploited for session hijacking

Microsoft Exchange Server (specific versions not disclosed). Cross-Site Scripting vulnerability enabling spoofing and session hijacking. No CVE assigned yet.

Microsoft13:25 UTC
Microsoft patches critical WSUS RCE flaw with public PoC exploitcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches critical WSUS RCE flaw with public PoC exploit

Windows Server Update Service (WSUS) on Windows Server. Specific versions not disclosed in out-of-band update. Affects organizations running WSUS infrastructure for Windows update management.

Microsoft16:42 UTC