Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

19 / 139 results
Active filter:tag: #microsoft✕ clear
OP-512 Targets IIS Servers with Custom Web Shell Frameworkhighperson_alertThreat Actor
person_alertThreat Actor

OP-512 Targets IIS Servers with Custom Web Shell Framework

OP-512 is a previously unreported threat cluster assessed by ReliaQuest with moderate to high confidence to be linked to China. The actor demonstrates espionage-focused objectives, leveraging custom web shell frameworks to compromise Microsoft Intern…

Microsoft5 Jun · 10:33 UTC
Windows Netlogon RCE under active exploitation after patch releasecriticalbug_reportVulnerability
bug_reportVulnerability

Windows Netlogon RCE under active exploitation after patch release

Microsoft Windows Netlogon service, all versions prior to recent patch. Affects domain controllers and systems with Netlogon service enabled. Specific CVE and affected version details not provided in alert.

Microsoft1 Jun · 10:30 UTC
Microsoft May 2026 Patch Tuesday: 118 vulnerabilities, 16 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft May 2026 Patch Tuesday: 118 vulnerabilities, 16 critical

Microsoft products and services across the ecosystem. 118 total vulnerabilities: 16 critical severity, 102 important severity. Specific affected products and CVE identifiers not yet detailed in available information.

Microsoft29 May · 14:06 UTC
Storm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilitieshighperson_alertThreat Actor
person_alertThreat Actor

Storm-2697 Deploys The Gentlemen Go-Based Ransomware with Worm Capabilities

Storm-2697 is a threat actor tracked by Microsoft Threat Intelligence that operates as a ransomware affiliate group. The actor deploys The Gentlemen ransomware, a sophisticated Go-based encryption tool, suggesting technical proficiency in modern prog…

Microsoft28 May · 13:00 UTC
Microsoft SharePoint RCE vulnerability requires immediate patchingcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE vulnerability requires immediate patching

Microsoft SharePoint Server (specific versions not disclosed in advisory). Organizations running on-premises SharePoint deployments are affected. SharePoint Online managed by Microsoft likely already patched.

Microsoft27 May · 14:23 UTC
AI chatbot abuse delivers cryptojacking malware via social engineeringhighbug_reportVulnerability
bug_reportVulnerability

AI chatbot abuse delivers cryptojacking malware via social engineering

Users of AI chatbots (platform-agnostic); Windows systems targeted for cryptojacking payload deployment. Campaign actively observed by Microsoft; no specific product vulnerability, relies on social engineering.

Microsoft27 May · 05:45 UTC
Cryptojacking campaign uses SEO poisoning and ScreenConnect for GPU mininghighbug_reportVulnerability
bug_reportVulnerability

Cryptojacking campaign uses SEO poisoning and ScreenConnect for GPU mining

Organizations using ScreenConnect remote access software; high-performance PCs with GPUs; users searching for compromised topics via search engines and AI chatbots. Campaign leverages Microsoft .NET utilities for execution.

Microsoft26 May · 19:35 UTC
Microsoft patches SharePoint RCE flaw via unsafe deserializationhighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches SharePoint RCE flaw via unsafe deserialization

Microsoft SharePoint Server (specific versions not disclosed). Vulnerability involves deserialization of untrusted data leading to remote code execution with CVSS 8.8.

CVE-2026-4565926 May · 09:49 UTC
Windows Server 2016 domain controller lookups fail after KB5087537 updatehighbug_reportVulnerability
bug_reportVulnerability

Windows Server 2016 domain controller lookups fail after KB5087537 update

Windows Server 2016 domain controllers running KB5087537 (May 2026 security update). Impacts Active Directory domain controller lookup functionality and domain connectivity.

Microsoft26 May · 05:41 UTC
FBI warns of Kali365 phishing-as-a-service targeting Microsoft 365highperson_alertThreat Actor
person_alertThreat Actor

FBI warns of Kali365 phishing-as-a-service targeting Microsoft 365

Kali365 is a phishing-as-a-service (PhaaS) platform that enables threat actors to conduct credential harvesting and account takeover operations against Microsoft 365 users.

Microsoft25 May · 10:45 UTC
F5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movementhighperson_alertThreat Actor
person_alertThreat Actor

F5 BIG-IP Exploitation Leads to Confluence Compromise and Lateral Movement

The threat actor behind this campaign remains unattributed. Motivation appears to be credential theft and network persistence within enterprise environments.

F522 May · 14:53 UTC
Microsoft Defender privilege escalation CVE-2026-41091 under active exploithighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender privilege escalation CVE-2026-41091 under active exploit

Microsoft Defender on Windows systems. Specific product versions not disclosed. Vulnerability allows local attackers to escalate privileges to SYSTEM level through improper link resolution handling.

CVE-2026-4109121 May · 08:55 UTC
Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operationcriticalperson_alertThreat Actor
person_alertThreat Actor

Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Operation

Fox Tempest is a threat actor attributed by Microsoft as operating a malware-signing-as-a-service (MSaaS) business model. The actor exploited Microsoft's Artifact Signing system to provide malicious code signing services to other cybercriminals, enab…

Microsoft20 May · 12:36 UTC
Webworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph APIhighperson_alertThreat Actor
person_alertThreat Actor

Webworm Deploys EchoCreep and GraphWorm Backdoors via Discord and Graph API

Webworm is a China-aligned advanced persistent threat (APT) actor first documented by Symantec in September 2022, with activity traced back to at least 2022.

Microsoft20 May · 10:51 UTC
Microsoft mitigates YellowKey BitLocker bypass (CVE-2026-45585)highbug_reportVulnerability
bug_reportVulnerability

Microsoft mitigates YellowKey BitLocker bypass (CVE-2026-45585)

Microsoft BitLocker on Windows systems. Specific affected versions not disclosed. Vulnerability allows bypass of BitLocker disk encryption protections.

CVE-2026-4558520 May · 06:28 UTC
Microsoft mitigates YellowKey BitLocker zero-day bypass vulnerabilityhighbug_reportVulnerability
bug_reportVulnerability

Microsoft mitigates YellowKey BitLocker zero-day bypass vulnerability

Windows BitLocker across all supported Windows versions. The vulnerability allows unauthorized access to BitLocker-protected drives. No CVE assigned yet.

Microsoft20 May · 05:31 UTC
Microsoft sees rise in privilege escalation and identity abuse flawshighbug_reportVulnerability
bug_reportVulnerability

Microsoft sees rise in privilege escalation and identity abuse flaws

Microsoft products and services experiencing increased critical vulnerabilities focused on privilege escalation and identity abuse. Specific affected products and versions not detailed in available data.

Microsoft19 May · 12:00 UTC
Microsoft Exchange Server XSS flaw actively exploited for session hijackingcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Exchange Server XSS flaw actively exploited for session hijacking

Microsoft Exchange Server (specific versions not disclosed). Cross-Site Scripting vulnerability enabling spoofing and session hijacking. No CVE assigned yet.

Microsoft18 May · 13:25 UTC
Microsoft patches critical WSUS RCE flaw with public PoC exploitcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches critical WSUS RCE flaw with public PoC exploit

Windows Server Update Service (WSUS) on Windows Server. Specific versions not disclosed in out-of-band update. Affects organizations running WSUS infrastructure for Windows update management.

Microsoft24 Oct · 16:42 UTC