❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 23 July 2026GBHackers

Microsoft Adds Prompt Injection Protection to Defender for Office 365

By: Divya
23 July 2026 at 05:23

Microsoft has introduced prompt injection protection in Defender for Office 365, representing a significant advancement in securing enterprise email environments against emerging AI-targeted threats. As organizations increasingly adopt AI assistants like Microsoft 365 Copilot to summarize, triage, and respond to emails, attackers are shifting their tactics from traditional phishing methods to manipulating AI systems directly. […]

The post Microsoft Adds Prompt Injection Protection to Defender for Office 365 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Before yesterdayGBHackers

Microsoft Retires Copilot Podcasts and Removes Access to Previously Created Content

By: Divya
21 July 2026 at 08:23

Microsoft has announced that it will retire the Podcasts feature in its consumer Copilot app on August 18, 2026. This decision will permanently remove the ability to generate new AI-created podcasts, as well as access to all previously created content. This change affects all Copilot customers, including both free users and paid subscribers, and raises […]

The post Microsoft Retires Copilot Podcasts and Removes Access to Previously Created Content appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries

By: Divya
21 July 2026 at 07:54

Microsoft Defender XDR users may inadvertently overlook command-and-control (C2) traffic when searching for Internet-bound connections due to a specific behavior in how IP addresses are classified. This issue arises from Kusto Query Language (KQL) detections that depend solely on filtering by RemoteIPType == β€œPublic” in the DeviceNetworkEvents table. As a result, traffic destined for public […]

The post Microsoft Defender XDR Blind Spot Lets Public C2 Traffic Evade Detection Queries appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier

By: Divya
20 July 2026 at 06:47

Microsoft will stop delivering feature updates, bug fixes, and security patches for the OneDrive sync app on systems running Windows version 21H2 and earlier on August 15, 2026. This change was announced in the Microsoft 365 Message Center notification MC1426708 and leaves organizations with older Windows endpoints exposed to an increasingly unsupported file synchronization client, […]

The post Microsoft Ends OneDrive Sync App Security Updates on Windows 10 21H2 and Earlier appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues

By: Divya
20 July 2026 at 05:56

Microsoft has released KB5121767, an out-of-band (OOB) cumulative update for Windows 11 versions 22H2 and 21H2. This update addresses a system performance issue related to the Intel Innovation Platform Framework (Intel IPF) drivers. The update was made available on July 18, 2023, specifically for devices affected by this issue, which arose after installing recent Windows […]

The post Microsoft Releases Emergency Windows 11 Update to Fix Intel IPF Driver Performance Issues appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Kratos PhaaS Targets Microsoft 365 Users With SharePoint Links and Cloudflare Anti-Bot Checks

16 July 2026 at 02:36

Kratos, a subscription-based phishing-as-a-service platform, is targeting Microsoft 365 users in the United States, Europe, and other regions through campaigns designed to blend into ordinary document-sharing workflows. The operation abuses trusted services, including Microsoft SharePoint, OneDrive, Microsoft Forms, Canva, Tilda, and systeme.io, to deliver links that ultimately redirect recipients to credential-harvesting pages. Only 156 sessions […]

The post Kratos PhaaS Targets Microsoft 365 Users With SharePoint Links and Cloudflare Anti-Bot Checks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Fixes Multiple Windows RDP Flaws Exposing Sensitive Data Over the Network

By: Divya
15 July 2026 at 03:03

Microsoft has addressed multiple information-disclosure vulnerabilities in the Windows Remote Desktop Protocol (RDP). This widely used service enables remote administration and access to Windows systems. The five flaws could permit attackers to retrieve information from vulnerable hosts, potentially exposing data held in application memory during an RDP session. Microsoft Fixes Multiple Windows RDP Flaws All […]

The post Microsoft Fixes Multiple Windows RDP Flaws Exposing Sensitive Data Over the Network appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens

13 July 2026 at 02:24

A misconfigured server in Budapest exposed a live phishing operation built to bypass Microsoft 365 multi-factor authentication and retain access to compromised accounts. The server, hosted at 185.163.204[.]7185.163.204[.]7185.163.204[.]7, was running python3 -m http.server 8080 with directory listing enabled, making its operational files publicly accessible. Researchers found phishing configurations, Telegram session artifacts, credential logs, RMM installers, […]

The post Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Tests AI-Powered Copilot Tool to Diagnose Windows 11 Performance Issues

By: Divya
13 July 2026 at 00:41

Microsoft is gradually rolling out an optional Copilot feature called PC Insights, which provides the AI assistant with access to real-time information about Windows 11 hardware and performance. This feature, first reported by Windows Latest, is currently being tested with users in the United States and is not yet widely available. PC Insights aims to […]

The post Microsoft Tests AI-Powered Copilot Tool to Diagnose Windows 11 Performance Issues appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Forg365 PhaaS Uses Telegram and AI Lures to Hijack Microsoft 365 Accounts

By: Divya
10 July 2026 at 08:58

Forg365 is a commercial phishing-as-a-service (PhaaS) platform specifically targeting Microsoft 365 users. It employs methods such as device-code phishing, adversary-in-the-middle (AiTM) workflows, AI-assisted lure generation, and token persistence tools. The platform’s onboarding process through Telegram, subscription model, and post-compromise features highlight how identity attacks on Microsoft 365 are becoming increasingly commercialized. Researchers from ZeroBEC have […]

The post Forg365 PhaaS Uses Telegram and AI Lures to Hijack Microsoft 365 Accounts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Uses AI-Powered Agentic Scanning to Find Windows Security Flaws and Accelerate Patching

By: Divya
10 July 2026 at 00:18

Microsoft is expanding its AI-driven vulnerability discovery across Windows, introducing a multi-model β€œagentic” scanning system designed to identify security flaws earlier and accelerate global patch deployment. AI-Powered Vulnerability DiscoveryΒ Β  At the core of this initiative is Microsoft Security’s Multi-Model Agentic Scanning Harness (MDASH), which combines multiple AI models, including third-party models, to analyze Windows codebases […]

The post Microsoft Uses AI-Powered Agentic Scanning to Find Windows Security Flaws and Accelerate Patching appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Entra Passkey Enrollment Abused in Operator-Controlled Vishing Campaign

9 July 2026 at 06:06

A focused vishing campaign that weaponizes Microsoft Entra passkey enrollment as a social-engineering vector to enable account takeover and downstream data extortion. The threat actor begins by registering domains that include the term β€œpasskey” (for example, assignpasskey[.]com, deploypasskey[.]com, passkeydeploy[.]com, passkeyadd[.]com, setpasskey[.]com) and creating per-target subdomains. Microsoft Entra ID login pages. Pages load generic Microsoft styling […]

The post Microsoft Entra Passkey Enrollment Abused in Operator-Controlled Vishing Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Introduces Execution Containers to Secure AI Agents on Windows

By: Divya
7 July 2026 at 04:34

Microsoft has introduced a new security architecture to safeguard autonomous AI agents on Windows, unveiling the Microsoft Execution Containers (MXC) SDK at Build 2026. The move reflects a growing industry concern: as AI agents evolve from passive assistants into autonomous systems capable of executing code, accessing files, and orchestrating workflows, they introduce significant security and […]

The post Microsoft Introduces Execution Containers to Secure AI Agents on Windows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Abuse Cross-Tenant Teams Chat to Deliver EtherRAT Through Malicious MSI Loader

7 July 2026 at 02:03

A coordinated social-engineering campaign observed in late June 2026 combined email phishing with an abused Microsoft Teams cross‑tenant chat to deliver a sophisticated EtherRAT implant via a malicious MSI loader. Initial access began with a targeted email masquerading as internal communication: an β€œEmployee Survey” HTML message containing a PDF lure. When the victim opened the […]

The post Hackers Abuse Cross-Tenant Teams Chat to Deliver EtherRAT Through Malicious MSI Loader appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌