BreachFeed
company

Microsoft

Tracked by 3 people · Cloud Provider

Track Microsoft

Incident history

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu74uev804sahmu2vfdrg3i6

A zero-click RCE flaw in AI coding agents could have exposed enterprise systems

Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vulnerable to a zero-click attack that enabled attackers to execute malicious code, even without developer interaction, by swapping a trusted plugin from an online marketplace for a malicious one, potentially giving them a foothold in enterprise development environments. Researchers at cybersecurity startup AIR found and reported the flaw, which they are calling…

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu73zlcv030yhmu2ycjtqhe9

GhostCode attackers abuse device codes to take over Microsoft 365 accounts

Microsoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakness in a legitimate device authorization flow. Researchers in eSentire’s threat response unit identified the campaign in late August 2026. The kit abuses Microsoft’s OAuth 2.0 device authorization grant flow, a legitimate mechanism designed to enable authentication from IoT devices, smart TVs, printers, or other devices that cannot easily support a conventional…

Bleeping Computer·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu718jan01wbhnu26bsbgzyr

Secure enterprise sharing with access reviews for Microsoft 365

Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. [...]

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmu70t32o00vuhnu2bjmb7uhl

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. "Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,"