BreachFeed
company

Microsoft

Tracked by 3 people · Cloud Provider

Track Microsoft

Incident history

SecurityWeek·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttxk2jt0c5yhmu2x8w609ul

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek.

The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttw21wa0apbhmu2sli1gtab

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic

The Hacker News·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttpeutg04fkhmu245n754si

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.

CSO Online·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015ehmu2flgk54ej

September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows

Possibly wormable bugs and two zero-day holes highlight the almost 1,000 fixes issued today by Microsoft in its September Patch Tuesday release. The 964 vulnerabilities, another record since Microsoft began using AI in the middle of the year to find holes, require customer action. Excluded are 174 third-party/open-source CVEs and 23 Chromium/Edge CVEs, as well as nine Microsoft mitigated vulnerabilities in applications like Azure, Entra, and Copilot Studio where no customer action is required.…

CyberScoop·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujqoav05gbhmu204hy4hs6

Microsoft discloses two actively exploited zero-days among 974 vulnerabilities

While the vendor hit another monthly record, it hasn’t resulted in a flood of active exploits. Researchers encourage customers to focus on their specific areas of risk and exposure. The post Microsoft discloses two actively exploited zero-days among 974 vulnerabilities appeared first on CyberScoop.

KrebsOnSecurity·3 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1ycq000uhnu2haz3qtce

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.

SecurityWeek·4 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1ye80014hnu2fymc6xbs

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities. The post Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek.