Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

22 / 195 results
Active filter:vendor: microsoft✕ clear
BraZetsu malware framework enables Initial Access Broker marketplacehighbug_reportVulnerability
bug_reportVulnerability

BraZetsu malware framework enables Initial Access Broker marketplace

Windows hosts in Iberian Peninsula and Latin America, particularly Brazil. Primary targets: e-commerce, corporate, financial, industrial, and law enforcement sectors. Browsers affected: Google Chrome, Microsoft Edge, Brave, Vivaldi, Opera.

Microsoft3 Sep · 13:26 UTC
Attackers abuse Microsoft Teams external chat to impersonate IT supporthighbug_reportVulnerability
bug_reportVulnerability

Attackers abuse Microsoft Teams external chat to impersonate IT support

Microsoft Teams users in enterprise environments with external collaboration enabled. All organizations using Teams for business communication are at risk if users accept external contact requests and grant remote access via RMM tools or Quick Assist…

Microsoft2 Sep · 20:51 UTC
Silver Fox campaign uses fake installers to disable Windows Updatehighbug_reportVulnerability
bug_reportVulnerability

Silver Fox campaign uses fake installers to disable Windows Update

Windows systems globally, primarily China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.

Microsoft2 Sep · 14:41 UTC
Active malware campaign uses fake vendor sites to deliver Silver Fox malwarehighbug_reportVulnerability
bug_reportVulnerability

Active malware campaign uses fake vendor sites to deliver Silver Fox malware

Organizations with China-based operations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.

Microsoft1 Sep · 20:48 UTC
22K Exchange servers unpatched for CVE-2026-62911 auth bypass flawhighbug_reportVulnerability
bug_reportVulnerability

22K Exchange servers unpatched for CVE-2026-62911 auth bypass flaw

Microsoft Exchange Server 2016, 2019, and Subscription Edition (SE). Approximately 21,899 internet-exposed servers remain unpatched globally, with highest concentrations in the United States (6,200) and Germany (5,100).

Microsoft1 Sep · 10:38 UTC
ClickFix Operators Dominate Initial Access via Social Engineeringhighperson_alertThreat Actor
person_alertThreat Actor

ClickFix Operators Dominate Initial Access via Social Engineering

ClickFix operators are threat actors leveraging a social engineering technique that manipulates users into executing malicious commands through clipboard manipulation.

Microsoft1 Sep · 09:30 UTC
TerminalFix campaign uses fake CAPTCHAs to deploy reverse tunnelshighbug_reportVulnerability
bug_reportVulnerability

TerminalFix campaign uses fake CAPTCHAs to deploy reverse tunnels

Windows systems with PowerShell and Windows Terminal enabled. Targets organizations with Active Directory environments. Attack vector: compromised websites displaying fake Cloudflare CAPTCHA prompts.

Microsoft31 Aug · 16:51 UTC
Spring Ring Campaign Weaponizes Microsoft Teams for Vishing Attackshighperson_alertThreat Actor
person_alertThreat Actor

Spring Ring Campaign Weaponizes Microsoft Teams for Vishing Attacks

Spring Ring is a coordinated social engineering campaign identified between January and April 2026 that leverages external Microsoft Teams accounts to impersonate IT help desk personnel.

Microsoft31 Aug · 08:00 UTC
19 malicious Chrome/Edge extensions steal crypto and credentialshighbug_reportVulnerability
bug_reportVulnerability

19 malicious Chrome/Edge extensions steal crypto and credentials

Google Chrome and Microsoft Edge users who installed any of 19 malicious extensions, including "Enable Right Click & Copy" (70,000+ Chrome users, 10,000+ Edge users). Campaign active since early 2024.

Google30 Aug · 12:17 UTC
TerminalFix campaign uses fake CAPTCHAs to deploy reverse-tunnel backdoorhighbug_reportVulnerability
bug_reportVulnerability

TerminalFix campaign uses fake CAPTCHAs to deploy reverse-tunnel backdoor

Organizations across multiple sectors using Windows environments with PowerShell and Windows Terminal. Attack leverages compromised websites serving fake Cloudflare CAPTCHA pages to social engineer users into executing malicious PowerShell commands.

Microsoft30 Aug · 05:36 UTC
TerminalFix Campaign Deploys Multi-Stage Attacks via Fake CAPTCHAshighperson_alertThreat Actor
person_alertThreat Actor

TerminalFix Campaign Deploys Multi-Stage Attacks via Fake CAPTCHAs

TerminalFix is a coordinated campaign activity (variant of ClickFix social engineering technique) disclosed by Microsoft Threat Intelligence. The campaign targets organizations across multiple industries using compromised websites to deliver sophisti…

Microsoft29 Aug · 01:43 UTC
19 malicious Chrome/Edge extensions drain crypto wallets via auto-updateshighbug_reportVulnerability
bug_reportVulnerability

19 malicious Chrome/Edge extensions drain crypto wallets via auto-updates

19 browser extensions (18 Chrome, 1 Edge) published since February 2024, with "Enable Right Click & Copy — Smart Unlock + OCR" having 80,000 installs. Extensions either created by threat actor or purchased from legitimate owners.

Google28 Aug · 13:27 UTC
Coordinated attacks target AI infrastructure for credential theft and cryptomininghighbug_reportVulnerability
bug_reportVulnerability

Coordinated attacks target AI infrastructure for credential theft and cryptomining

AI infrastructure platforms: LiteLLM gateways (CVE-2026-42271, CVE-2026-48710), RAGFlow deployments, and Kestra workflow environments. All exposed instances with administrative surfaces reachable from the internet are at risk.

Microsoft26 Aug · 14:43 UTC
Microsoft SharePoint RCE chain (CVE-2026-55040 + CVE-2026-63520) exploitedhighbug_reportVulnerability
bug_reportVulnerability

Microsoft SharePoint RCE chain (CVE-2026-55040 + CVE-2026-63520) exploited

Microsoft SharePoint Server (on-premises). CVE-2026-55040: JWT authentication bypass. CVE-2026-63520: Business Connectivity Services RCE. Over 8,700 SharePoint servers exposed online. Specific vulnerable versions not disclosed in article.

Microsoft26 Aug · 12:47 UTC
NovaCookies PhaaS Toolkit Hijacks Microsoft 365 Sessions via DocuSignhighperson_alertThreat Actor
person_alertThreat Actor

NovaCookies PhaaS Toolkit Hijacks Microsoft 365 Sessions via DocuSign

NovaCookies is a subscription-based adversary-in-the-middle (AitM) phishing-as-a-service (PhaaS) platform priced at $320/month, advertised via Telegram.

Microsoft26 Aug · 11:44 UTC
Mirage2FA Campaign Hits 4,500 Orgs via Microsoft 365 AiTM Phishinghighperson_alertThreat Actor
person_alertThreat Actor

Mirage2FA Campaign Hits 4,500 Orgs via Microsoft 365 AiTM Phishing

Mirage2FA is a commercial phishing-as-a-service (PhaaS) campaign active from 2024 to 2026, targeting Microsoft 365 accounts through adversary-in-the-middle (AiTM) techniques.

Microsoft25 Aug · 09:56 UTC
.NET Framework August 2026 updates break WPF printing and PDF exporthighbug_reportVulnerability
bug_reportVulnerability

.NET Framework August 2026 updates break WPF printing and PDF export

.NET Framework cumulative updates released August 2026 Patch Tuesday. Affects Windows Presentation Foundation (WPF) applications on Windows 10, Windows 11, Windows Server 2012 through Windows Server 2025.

Microsoft24 Aug · 10:40 UTC
WordlistLoader and SynkLoader malware target Windows via ClickFix and Teamshighbug_reportVulnerability
bug_reportVulnerability

WordlistLoader and SynkLoader malware target Windows via ClickFix and Teams

Windows endpoints exposed to ClearFake/ClickFix campaigns (WordlistLoader delivering Amatera Stealer) and Microsoft Teams phishing (SynkLoader credential theft).

Microsoft24 Aug · 10:35 UTC
SynkLoader malware spreads via Microsoft Teams phishing campaignshighbug_reportVulnerability
bug_reportVulnerability

SynkLoader malware spreads via Microsoft Teams phishing campaigns

Microsoft Teams users across all organizations. SynkLoader is a new credential-stealing malware family delivered through phishing messages on the Teams platform. No specific product versions or CVEs identified.

Microsoft21 Aug · 16:01 UTC
Microsoft Defender BTR.sys driver weaponized for kernel-level sabotagehighbug_reportVulnerability
bug_reportVulnerability

Microsoft Defender BTR.sys driver weaponized for kernel-level sabotage

Microsoft Defender BTR.sys driver on all Windows versions from Windows 7 through Windows 11 25H2. The driver is a required component shipped with every Windows installation and cannot be blocked without breaking Defender functionality.

Microsoft21 Aug · 13:52 UTC
Microsoft Entra ID deserialization flaw exploited; already patchedcriticalbug_reportVulnerability
bug_reportVulnerability

Microsoft Entra ID deserialization flaw exploited; already patched

Microsoft Entra ID (formerly Azure Active Directory) cloud-based identity and access management platform. All versions prior to Microsoft's server-side patch.

Microsoft21 Aug · 09:04 UTC
Microsoft patches critical Entra ID RCE flaw (CVE-2026-69836, CVSS 10.0)criticalbug_reportVulnerability
bug_reportVulnerability

Microsoft patches critical Entra ID RCE flaw (CVE-2026-69836, CVSS 10.0)

Microsoft Entra ID (formerly Azure Active Directory), all versions. Cloud-based identity and access management service. Microsoft has already deployed server-side mitigations; no customer action required.

Microsoft21 Aug · 04:06 UTC