Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 139 results
Active filter:tag: #microsoft✕ clear
Coordinated attacks target AI infrastructure for credential theft and cryptomininghighbug_reportVulnerability
bug_reportVulnerability

Coordinated attacks target AI infrastructure for credential theft and cryptomining

AI infrastructure platforms: LiteLLM gateways (CVE-2026-42271, CVE-2026-48710), RAGFlow deployments, and Kestra workflow environments. All exposed instances with administrative surfaces reachable from the internet are at risk.

Microsoft26 Aug · 14:43 UTC
Microsoft SharePoint RCE chain (CVE-2026-55040 + CVE-2026-63520) exploitedhighbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE chain (CVE-2026-55040 + CVE-2026-63520) exploited

Microsoft SharePoint Server (on-premises). CVE-2026-55040: JWT authentication bypass. CVE-2026-63520: Business Connectivity Services RCE. Over 8,700 SharePoint servers exposed online. Specific vulnerable versions not disclosed in article.

Microsoft26 Aug · 12:47 UTC
NovaCookies PhaaS Toolkit Hijacks Microsoft 365 Sessions via DocuSignhighperson_alertThreat Actor
person_alertThreat Actor

NovaCookies PhaaS Toolkit Hijacks Microsoft 365 Sessions via DocuSign

NovaCookies is a subscription-based adversary-in-the-middle (AitM) phishing-as-a-service (PhaaS) platform priced at $320/month, advertised via Telegram.

Microsoft26 Aug · 11:44 UTC
Mirage2FA Campaign Hits 4,500 Orgs via Microsoft 365 AiTM Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Mirage2FA Campaign Hits 4,500 Orgs via Microsoft 365 AiTM Phishing

Mirage2FA is a commercial phishing-as-a-service (PhaaS) campaign active from 2024 to 2026, targeting Microsoft 365 accounts through adversary-in-the-middle (AiTM) techniques.

Microsoft25 Aug · 09:56 UTC
.NET Framework August 2026 updates break WPF printing and PDF exporthighbug_reportVulnerability
bug_reportVulnerability

.NET Framework August 2026 updates break WPF printing and PDF export

.NET Framework cumulative updates released August 2026 Patch Tuesday. Affects Windows Presentation Foundation (WPF) applications on Windows 10, Windows 11, Windows Server 2012 through Windows Server 2025.

Microsoft24 Aug · 10:40 UTC
WordlistLoader and SynkLoader malware target Windows via ClickFix and Teamshighbug_reportVulnerability
bug_reportVulnerability

WordlistLoader and SynkLoader malware target Windows via ClickFix and Teams

Windows endpoints exposed to ClearFake/ClickFix campaigns (WordlistLoader delivering Amatera Stealer) and Microsoft Teams phishing (SynkLoader credential theft).

Microsoft24 Aug · 10:35 UTC
SynkLoader malware spreads via Microsoft Teams phishing campaignshighbug_reportVulnerability
bug_reportVulnerability

SynkLoader malware spreads via Microsoft Teams phishing campaigns

Microsoft Teams users across all organizations. SynkLoader is a new credential-stealing malware family delivered through phishing messages on the Teams platform. No specific product versions or CVEs identified.

Microsoft21 Aug · 16:01 UTC
Microsoft Defender BTR.sys driver weaponized for kernel-level sabotagehighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender BTR.sys driver weaponized for kernel-level sabotage

Microsoft Defender BTR.sys driver on all Windows versions from Windows 7 through Windows 11 25H2. The driver is a required component shipped with every Windows installation and cannot be blocked without breaking Defender functionality.

Microsoft21 Aug · 13:52 UTC
Microsoft Entra ID deserialization flaw exploited; already patchedcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Entra ID deserialization flaw exploited; already patched

Microsoft Entra ID (formerly Azure Active Directory) cloud-based identity and access management platform. All versions prior to Microsoft's server-side patch.

Microsoft21 Aug · 09:04 UTC
Microsoft patches critical Entra ID RCE flaw (CVE-2026-69836, CVSS 10.0)criticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches critical Entra ID RCE flaw (CVE-2026-69836, CVSS 10.0)

Microsoft Entra ID (formerly Azure Active Directory), all versions. Cloud-based identity and access management service. Microsoft has already deployed server-side mitigations; no customer action required.

Microsoft21 Aug · 04:06 UTC
Microsoft April 2026 Patch Tuesday: 163 vulnerabilities, 8 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft April 2026 Patch Tuesday: 163 vulnerabilities, 8 critical

Microsoft products and services across the ecosystem. 163 total vulnerabilities patched, including 8 critical severity issues. Specific affected products, CVE identifiers, and version details not provided in source material.

Microsoft19 Aug · 11:46 UTC
CISA flags 4 critical flaws in macOS, SharePoint, vCenter, IKE under attackcriticalbug_reportVulnerability
bug_reportVulnerability

CISA flags 4 critical flaws in macOS, SharePoint, vCenter, IKE under attack

Apple macOS (CVE-2026-65400, Screen Sharing authentication bypass), Microsoft SharePoint (CVE-2026-55040, weak authentication), Broadcom VMware vCenter (CVE-2026-59310, path traversal RCE), Microsoft IKE Service Extensions (CVE-2026-33824, double fre…

CVE-2026-6540019 Aug · 09:01 UTC
Windows IKE Extension RCE (CVE-2026-33824) actively exploitedcriticalbug_reportVulnerability
bug_reportVulnerability

Windows IKE Extension RCE (CVE-2026-33824) actively exploited

All supported Windows 10, Windows 11, and Windows Server versions. The vulnerability affects the Windows Internet Key Exchange (IKE) Service Extensions (MS-IKEE) component accessible via UDP ports 500 and 4500.

Microsoft19 Aug · 08:12 UTC
MacSync Stealer campaign uses 30+ rotating domains to target macOS usershighbug_reportVulnerability
bug_reportVulnerability

MacSync Stealer campaign uses 30+ rotating domains to target macOS users

macOS systems, all versions. Primary targets: users with AWS credentials, SSH keys, Kubernetes configs, browser credentials, and Keychain data. Organizations with macOS endpoints in development, DevOps, and cloud administration roles face elevated ri…

Microsoft19 Aug · 04:01 UTC
Microsoft Copilot Personal flaws enable one-click data exfiltration via URLhighbug_reportVulnerability
bug_reportVulnerability

Microsoft Copilot Personal flaws enable one-click data exfiltration via URL

Microsoft Copilot Personal (consumer assistant at copilot.microsoft.com). Research does not indicate Microsoft 365 Copilot is affected. Vulnerability tracked as CVE-2026-24301. Patched August 18, 2026.

Microsoft18 Aug · 15:47 UTC
MacSync Stealer targets macOS via ClickFix, rotates 30+ domainshighbug_reportVulnerability
bug_reportVulnerability

MacSync Stealer targets macOS via ClickFix, rotates 30+ domains

macOS devices. No specific version restrictions identified. Targets Keychain, browser data, credentials, SSH keys, and sensitive user files. Delivered via ClickFix social engineering (malicious Terminal commands).

Microsoft18 Aug · 15:08 UTC
TWINLOOT Implant Abuses Microsoft 365 Services for C2 and Lateral Movementhighperson_alertThreat Actor
person_alertThreat Actor

TWINLOOT Implant Abuses Microsoft 365 Services for C2 and Lateral Movement

No specific threat actor has been attributed to TWINLOOT operations. The malware was discovered by Ontinue's Cyber Defense Center during investigation of an ongoing campaign in July 2026.

Microsoft18 Aug · 10:38 UTC
CVE-2025-60710: Windows Task Host Flaw Exploited by Ransomware Gangshighperson_alertThreat Actor
person_alertThreat Actor

CVE-2025-60710: Windows Task Host Flaw Exploited by Ransomware Gangs

No specific threat actor or ransomware gang has been publicly attributed to the exploitation of CVE-2025-60710. CISA confirmed that multiple ransomware operators are actively exploiting this vulnerability in the wild as of August 2026.

Microsoft18 Aug · 08:32 UTC
Microsoft Defender ShieldBreak zero-day grants SYSTEM privileges on Windowshighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender ShieldBreak zero-day grants SYSTEM privileges on Windows

Microsoft Defender on Windows 10, Windows 11 (including 25H2 and Canary), and Windows Server 2025. All fully patched systems with Defender enabled are vulnerable.

CVE-2026-6941417 Aug · 07:05 UTC
Microsoft patches LegacyHive Windows zero-day granting admin privilegeshighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches LegacyHive Windows zero-day granting admin privileges

Windows User Profile Service in Windows 10 version 2004 and later, Windows Server 2022 and later. Tracked as CVE-2026-62832. All Windows systems running affected versions are vulnerable.

Microsoft13 Aug · 15:46 UTC
SharePoint CVE-2026-55040 exploited in wild after PoC releasecriticalbug_reportVulnerability
bug_reportVulnerability

SharePoint CVE-2026-55040 exploited in wild after PoC release

Microsoft SharePoint servers not patched with July 2026 Patch Tuesday updates. All unpatched SharePoint instances are vulnerable to authentication bypass allowing unauthenticated remote attackers to impersonate any site user or administrator.

CVE-2026-5504013 Aug · 04:09 UTC
Lazarus Exploits Windows Zero-Day in Operation Dream Job Campaigncriticalperson_alertThreat Actor
person_alertThreat Actor

Lazarus Exploits Windows Zero-Day in Operation Dream Job Campaign

Lazarus Group is a North Korean state-sponsored advanced persistent threat (APT) actor attributed to Pyongyang-backed cyber operations. The group conducts cyber espionage and financially motivated campaigns targeting organizations worldwide.

Microsoft12 Aug · 15:39 UTC
Plug and Pwn attacks exploit Windows Plug and Play for SYSTEM accesshighbug_reportVulnerability
bug_reportVulnerability

Plug and Pwn attacks exploit Windows Plug and Play for SYSTEM access

All Windows systems (including fully patched Windows 11) that support Plug and Play device installation. Specific vulnerable vendor packages include Sierra Wireless and Sony FeliCa software.

Microsoft12 Aug · 14:05 UTC
Lazarus Exploits Windows Zero-Day in Operation Dream Job Campaigncriticalperson_alertThreat Actor
person_alertThreat Actor

Lazarus Exploits Windows Zero-Day in Operation Dream Job Campaign

Lazarus is a North Korean state-sponsored advanced persistent threat (APT) group linked to the Reconnaissance General Bureau. The group is financially and strategically motivated, conducting espionage operations targeting defense and critical infrast…

CVE-2026-6882012 Aug · 13:38 UTC
Microsoft SharePoint JWT auth bypass exploited in wild after PoC releasecriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint JWT auth bypass exploited in wild after PoC release

Microsoft SharePoint Enterprise Server 2016 and SharePoint Server 2019. CVE-2026-55040 is a critical authentication bypass in JWT token validation allowing unauthenticated attackers to impersonate SharePoint users or administrators.

Microsoft12 Aug · 10:25 UTC
Microsoft August 2026 Patch Tuesday: 398 vulnerabilities, 42 criticalcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft August 2026 Patch Tuesday: 398 vulnerabilities, 42 critical

Microsoft products and services across the ecosystem. Specific affected products, versions, and CVE identifiers not disclosed in available information. 398 total vulnerabilities addressed, including 42 rated critical severity.

Microsoft12 Aug · 10:11 UTC
ShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM accesshighbug_reportVulnerability
bug_reportVulnerability

ShieldBreak zero-day bypasses Microsoft Defender patch, grants SYSTEM access

Microsoft Defender for Windows on Windows 11 25H2, Windows Server 2025, and Windows 10 (all editions). The vulnerability bypasses the patch for CVE-2026-50656 (RoguePlanet) in the Microsoft Malware Protection Engine (mpengine.dll).

CVE-2026-5065612 Aug · 04:41 UTC
Microsoft patches 398 flaws including one actively exploited zero-dayhighbug_reportVulnerability
bug_reportVulnerability

Microsoft patches 398 flaws including one actively exploited zero-day

Microsoft Windows operating systems and supported software. All Windows endpoints are affected. Critical focus: CVE-2026-68820 (afd.sys driver privilege escalation, actively exploited), CVE-2026-62832 (Windows User Profile Service privilege escalatio…

Microsoft11 Aug · 19:28 UTC
Windows kernel driver zero-day CVE-2026-68820 exploited by Lazarus APTcriticalbug_reportVulnerability
bug_reportVulnerability

Windows kernel driver zero-day CVE-2026-68820 exploited by Lazarus APT

Windows kernel driver afd.sys (Ancillary Function Driver for WinSock) across all supported Windows versions. CVE-2026-68820 is a use-after-free vulnerability enabling local privilege escalation to SYSTEM level. CVSS 7.0.

CVE-2026-6882011 Aug · 18:10 UTC
Microsoft patches 400 flaws including 3 zero-days, one exploited by Lazaruscriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches 400 flaws including 3 zero-days, one exploited by Lazarus

All supported Windows versions (Windows 10, Windows 11). Three zero-day vulnerabilities: CVE-2026-68820 (Windows AFD.sys driver, actively exploited by Lazarus APT), CVE-2026-62832 (Windows User Profile Service, publicly disclosed as "LegacyHive"), an…

Microsoft11 Aug · 16:08 UTC