Skip to content

Daily Threat Intel

Menu
  • Vulnerabilities
  • Malware
  • Breaches
  • Enterprise
  • Supply Chain
  • Emerging Threats
  • Cloud
  • About us
Menu

Tag: microsoft

12 Bugs in Microsoft’s April 2025 Update to Patch Now

Posted on April 8, 2025

Image source: QINQIE99,Shutterstock One of them is a 0-day that a threat actor is using in an ransomware campaign Microsoft has released fixes for 126 vulnerabilities in its April 2025 Patch Tuesday…

Share

2 Exploited and 3 Publicly Known Bugs in Microsoft’s Oct. Update to Patch Now

Posted on October 8, 2024

Image source: : Shutterstock Microsoft’s relatively moderate severity rating for the bugs belie the threat they present At least five of the 117 CVEs for which Microsoft released a patch this week…

Share

New Vuln Enables Admin Access on Domain-Joined ESXi Hypervisors

Posted on July 30, 2024

Image Source: Shutterstock Ransomware attackers are leveraging CVE-2024-37085 to drop Black Basta, Akira on vulnerable systems, Microsoft says. Ransomware operators are exploiting an authentication bypass vulnerability in ESXi hypervisors to gain full…

Share

These 5 Security Practices Can Help Protect Against 99% of Attacks: Do you Have Them?

Posted on October 6, 2023

Image source: Shutterstock Microsoft says telemetry from its Defender for Endpoint, Cloud Apps, Identity, Office 365 and other sources shows organizations can protect against almost all attacks with a few fundamental security…

Share

APT37 using South Korea stampede themed lure to exploit new IE zero-day flaw

Posted on December 8, 2022

Microsoft patched flaw after Google TAG researchers reported it to the company in October. Microsoft has patched a zero-day vulnerability in Internet Explorer’s Jscript engine after researchers from Google’s Threat Analysis Group…

Share

Russia’s Iridium group deploying new ransomware payload

Posted on November 10, 2022

Prestige ransomware marks dangerous shift in strategy for threat actor Microsoft says [299 words]. What: Security researchers at Microsoft have spotted Russia-based threat group Iridium dropping a new ransomware payload dubbed “Prestige”…

Share

Here’s what you need to know of the 4 zero-days in Microsoft’s Nov. update

Posted on November 8, 2022

Microsoft issued patches for of 62 vulnerabilities, nine of which are “Critical” severity and 53 “Important”. Four of the vulnerabilities in Microsoft November 2022 security update are zero-day flaws that are being…

Share

Microsoft leaked business transaction data on more than 65K prospective customers via misconfigured Azure storage bucket, threat intel vendor claims

Posted on October 19, 2022

Misconfigured and insecure cloud storage buckets—particularly AWS S3 buckets—pose a major data leak risk for organizations. In recent years hundreds of companies have had sensitive data exposed via this vector [292 words]….

Share

Zscaler releases technical details—and PoC—for now-patched Windows 0-day

Posted on October 14, 2022

Microsoft has rated the previously exploited CVE-2022-37969 as being of high-severity, so now might be a good time to patch (264 words). What: New technical details and proof-of-concept code have become available…

Share

Microsoft looking into reports of a third Exchange Server zero-day?

Posted on October 12, 2022

Security vendor that discovered bug recommends organizations limit IIS app operating privileges on Exchange Server [297 words] What: Microsoft apparently is looking into a report it received from South Korean cybersecurity vendor…

Share

Posts pagination

1 2 Next
  • 12 Bugs in Microsoft’s April 2025 Update to Patch Now
  • NSA, CISA, Others Warn About Fast Flux Threat: Here’s Why
  • Max Severity Bug Affects MITRE Caldera Adversary Emulation Platform
  • FBI: Russia’s APT29 May Exploit These 24 vulnerabilities-Be Aware
  • Ivanti’s New 0-Days Now in CISA’s Exploit Catalog
©2025 Daily Threat Intel | Design: Newspaperly WordPress Theme