Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

24 / 195 results
Active filter:vendor: microsoft✕ clear
Chaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsershighperson_alertThreat Actor
person_alertThreat Actor

Chaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsers

Chaos is a ransomware group that operates through spam floods, vishing campaigns, Quick Assist abuse, and RMM tools for initial access and persistence. The group deploys custom tooling including the msaRAT Rust-based implant as a pre-ransomware stage…

Microsoft23 Jul · 11:11 UTC
Chaos ransomware gang deploys msaRAT backdoor via browser hijackinghighperson_alertThreat Actor
person_alertThreat Actor

Chaos ransomware gang deploys msaRAT backdoor via browser hijacking

Chaos is a ransomware gang that emerged in early 2025, distinct from the earlier same-named ransomware family active since 2021. The group has been linked to Iranian state-backed threat actor MuddyWater, who reportedly leveraged Chaos ransomware to d…

Google23 Jul · 07:59 UTC
Microsoft July 2026 Patch Tuesday: 569 vulnerabilities, 56 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft July 2026 Patch Tuesday: 569 vulnerabilities, 56 critical

Microsoft product portfolio (specific products and versions not disclosed in available data). 569 total vulnerabilities patched, including 56 rated critical severity.

Microsoft22 Jul · 12:32 UTC
Microsoft SharePoint RCE flaws actively exploited; immediate patching requiredcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE flaws actively exploited; immediate patching required

Microsoft SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Five critical vulnerabilities: CVE-2026-50522 (CVSS 9.8, deserialization RCE), CVE-2026-58644 (CVSS 9.8, unauthenticated RCE), CVE-2026-5…

Microsoft22 Jul · 08:39 UTC
Kratos Phishing Kit Dismantled After Stealing Microsoft 365 Sessionshighperson_alertThreat Actor
person_alertThreat Actor

Kratos Phishing Kit Dismantled After Stealing Microsoft 365 Sessions

The Kratos operator is an Indonesian individual arrested by local authorities for allegedly developing and operating the Kratos phishing-as-a-service (PhaaS) platform.

Microsoft22 Jul · 04:38 UTC
Azure DevOps MCP server flaw lets hidden PR comments hijack AI agentshighbug_reportVulnerability
bug_reportVulnerability

Azure DevOps MCP server flaw lets hidden PR comments hijack AI agents

Microsoft Azure DevOps MCP server versions up to and including v2.8.0 (released June 24, 2026). The flaw affects the repo_get_pull_request_by_id tool, which returns pull request descriptions without prompt-injection guardrails.

Microsoft22 Jul · 02:57 UTC
Microsoft SharePoint RCE CVE-2026-50522 actively exploited for persistencecriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE CVE-2026-50522 actively exploited for persistence

Microsoft SharePoint Server (specific versions not provided). Vulnerability enables remote code execution with machine key theft capability, allowing persistent access beyond patch deployment.

CVE-2026-5052221 Jul · 18:06 UTC
Microsoft SharePoint RCE (CVE-2026-50522) actively exploited after PoCcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE (CVE-2026-50522) actively exploited after PoC

Microsoft SharePoint Server (all versions prior to July 2026 patches). Vulnerability involves deserialization of untrusted data leading to unauthenticated remote code execution. CVSS 9.8 (Critical).

CVE-2026-5052221 Jul · 12:57 UTC
Windows LegacyHive zero-day enables privilege escalation, unofficial patches availablehighbug_reportVulnerability
bug_reportVulnerability

Windows LegacyHive zero-day enables privilege escalation, unofficial patches available

Microsoft Windows systems (all current versions). Specific affected versions not disclosed. Impacts up-to-date Windows installations. No CVE assigned yet.

Microsoft21 Jul · 06:06 UTC
HollowGraph malware abuses Microsoft 365 calendar for C2 and exfiltrationhighbug_reportVulnerability
bug_reportVulnerability

HollowGraph malware abuses Microsoft 365 calendar for C2 and exfiltration

Microsoft 365 environments with compromised mailboxes. Threat actors leverage Microsoft Graph API and calendar features to establish covert command-and-control channels.

Microsoft20 Jul · 15:43 UTC
AI-assisted phishing toolkit targets Windows users in Mexico via fake gov sitehighbug_reportVulnerability
bug_reportVulnerability

AI-assisted phishing toolkit targets Windows users in Mexico via fake gov site

Windows users in Mexico targeted via fake government ID-lookup website. Delivery mechanism uses WebDAV to distribute infostealer malware. Toolkit contains 1,048 files including phishing templates, droppers, and builder documentation.

Microsoft20 Jul · 15:29 UTC
HollowGraph Malware Uses Microsoft 365 Calendars for Covert C2highperson_alertThreat Actor
person_alertThreat Actor

HollowGraph Malware Uses Microsoft 365 Calendars for Covert C2

HollowGraph is a newly discovered espionage implant that leverages Microsoft 365 calendar infrastructure for command and control operations. The malware was identified and analyzed by Group-IB.

Microsoft20 Jul · 12:33 UTC
ACR Stealer campaign targets Microsoft enterprise customershighbug_reportVulnerability
bug_reportVulnerability

ACR Stealer campaign targets Microsoft enterprise customers

Microsoft enterprise customers; targets browser-stored credentials, authentication tokens, and sensitive documents across enterprise environments

Microsoft18 Jul · 12:17 UTC
Windows zero-day LegacyHive enables privilege escalation on patched systemscriticalbug_reportVulnerability
bug_reportVulnerability

Windows zero-day LegacyHive enables privilege escalation on patched systems

All up-to-date Windows systems. Specific affected versions not disclosed. Exploit enables local privilege escalation from standard user to administrator level. No CVE assigned yet.

Microsoft17 Jul · 09:05 UTC
ACR Stealer campaign uses ClickFix social engineering to steal M365 datahighbug_reportVulnerability
bug_reportVulnerability

ACR Stealer campaign uses ClickFix social engineering to steal M365 data

Microsoft 365 enterprise users and organizations. ACR Stealer targets browser credentials, session tokens, and M365 documents. Active since 2024 with two documented delivery chains using ClickFix social engineering lures.

Microsoft17 Jul · 06:56 UTC
CISA: Microsoft SharePoint RCE CVE-2026-58644 actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

CISA: Microsoft SharePoint RCE CVE-2026-58644 actively exploited

Microsoft SharePoint Server (specific versions not disclosed). CVSS 9.8 critical remote code execution vulnerability.

CVE-2026-5864417 Jul · 04:42 UTC
Vishing Campaign Targets Microsoft 365 Users with Entra Passkey Scamhighperson_alertThreat Actor
person_alertThreat Actor

Vishing Campaign Targets Microsoft 365 Users with Entra Passkey Scam

The threat actor behind this campaign remains unattributed. The operation demonstrates sophistication in social engineering tactics, specifically targeting Microsoft 365 environments through voice-based phishing (vishing).

Microsoft8 Jul · 14:47 UTC
EvilTokens Ghost Phishing Campaign Targets US and European Businesseshighperson_alertThreat Actor
person_alertThreat Actor

EvilTokens Ghost Phishing Campaign Targets US and European Businesses

EvilTokens is a campaign leveraging "ghost phishing" techniques to target business entities across the United States and Europe. The campaign's primary motivation appears to be credential theft and unauthorized access to Microsoft 365 environments, w…

Microsoft8 Jul · 11:00 UTC
DEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishinghighperson_alertThreat Actor
person_alertThreat Actor

DEBULL Campaign Exploits Microsoft Device Code Flow for M365 Phishing

DEBULL is a phishing campaign active from late June through early July 2026, targeting Microsoft 365 accounts through abuse of Microsoft's legitimate device-code flow authentication mechanism.

Microsoft7 Jul · 13:14 UTC
Attackers impersonate IT support on Teams calls to deploy EtherRAThighbug_reportVulnerability
bug_reportVulnerability

Attackers impersonate IT support on Teams calls to deploy EtherRAT

Organizations using Microsoft Teams for internal communications. All industries are potential targets. The campaign exploits user trust in voice-based IT support interactions rather than a technical vulnerability in Teams itself.

Microsoft6 Jul · 18:23 UTC
EvilTokens Affiliate ARToken Exposes M365 Phishing-as-a-Service Platformhighperson_alertThreat Actor
person_alertThreat Actor

EvilTokens Affiliate ARToken Exposes M365 Phishing-as-a-Service Platform

EvilTokens is a threat actor operating a phishing-as-a-service (PhaaS) ecosystem targeting Microsoft 365 credentials. The group utilizes an affiliate model, with ARToken identified as one operational affiliate platform.

Microsoft3 Jul · 12:12 UTC
ConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token thefthighbug_reportVulnerability
bug_reportVulnerability

ConsentFix and ClickFix campaigns hijack M365 accounts via OAuth token theft

Microsoft 365 accounts across all organizations using OAuth authentication. Campaigns target users through social engineering to approve malicious OAuth consent prompts, bypassing MFA protections by stealing valid authentication tokens.

Microsoft2 Jul · 12:00 UTC
CISA: Active exploitation of RCE flaw in Microsoft SharePointhighbug_reportVulnerability
bug_reportVulnerability

CISA: Active exploitation of RCE flaw in Microsoft SharePoint

Microsoft SharePoint servers vulnerable prior to May 2024 security updates. Affects on-premises SharePoint deployments; unauthenticated remote code execution possible on unpatched systems.

Microsoft2 Jul · 08:52 UTC
Microsoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)criticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE flaw under active exploitation (CVE-2026-45659)

Microsoft SharePoint Server, all versions vulnerable to deserialization attacks. Specific affected versions not yet disclosed.

CVE-2026-456592 Jul · 03:46 UTC