❌

Reading view

There are new articles available, click to refresh the page.

Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts

Threat actors are impersonating corporate IT helpdesk staff in an active social-engineering campaign that hijacks Microsoft 365 identities, establishes MFA persistence, and systematically collects data from SharePoint, OneDrive, and Exchange Online. Microsoft Security Research said it has observed the cloud-focused intrusions since May 2026. The activity is marked by unusual sign-ins, attacker-added authentication methods, extensive […]

The post Hackers Pose as IT Support to Hijack Microsoft 365 Accounts With Fake Passkey Alerts appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Windows BitLocker Flaw Lets Attackers Execute Code on Vulnerable Systems

Microsoft disclosed CVE-2026-69449, an Important-severity vulnerability in Windows BitLocker. This issue is classified as a heap-based buffer overflow (CWE-122) and may allow remote code execution (RCE). Microsoft released details about this vulnerability on September 8, 2026. The CVSS 3.1 base score is 6.7, with a temporal score of 5.8. Windows BitLocker Flaw The vulnerability uses […]

The post Windows BitLocker Flaw Lets Attackers Execute Code on Vulnerable Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs

A human-operated intrusion campaign in which attackers abuse Microsoft Teams external collaboration to impersonate internal IT or helpdesk staff, persuade employees to grant remote control of their PCs, and then move toward critical enterprise infrastructure. The campaign does not exploit a Microsoft Teams vulnerability. Instead, it weaponizes trust in familiar support workflows, combining Teams chats […]

The post Hackers Impersonate IT Support on Microsoft Teams to Take Control of Employee PCs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Steal Microsoft 365 Sessions to Hijack Accounts Even After MFA

Cybercriminals are using a rebranded Evilginx2 phishing-as-a-service platform dubbed BigBear 2.0 to intercept authenticated Microsoft 365 sessions, allowing them to take over accounts even after victims complete multi-factor authentication (MFA). CloudSEK’s TRIAD team uncovered the operation after gaining administrative access to its control panel in June 2026 The campaign demonstrates a critical reality for Microsoft […]

The post Hackers Steal Microsoft 365 Sessions to Hijack Accounts Even After MFA appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365

Switzerland’s Federal Chancellery is advancing a sovereign digital workplace initiative following a feasibility study that demonstrated how open-source collaboration and office software can effectively support essential workflows within the federal administration. This initiative, announced to the Federal Council on September 2, aims to establish an open-source workplace platform that will operate alongside Microsoft 365 without […]

The post Switzerland Builds Open-Source Workplace Platform to Operate Alongside Microsoft 365 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud

Microsoft is developing a new security feature for Teams messaging that will obscure QR codes sent by external users. This measure aims to help organizations reduce phishing and fraud risks associated with malicious QR code campaigns. Listed under Microsoft 365 Roadmap ID 570439, this feature is currently in development and is scheduled for rollout in […]

The post Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials

A Microsoft 365 email security-control bypass that lets attackers submit unauthenticated messages posing as internal users by leaving one SMTP field blank. The technique targets Exchange Online’s RejectDirectSend setting and does not represent a vulnerability in Microsoft software or in ReliaQuest systems; instead, it exposes a limitation in how the control evaluates Direct Send traffic. […]

The post Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks

Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026. This change aims to strengthen defenses against kernel-level attacks by ensuring that only trusted kernel-mode code and drivers can run on supported systems. Memory Integrity is a security feature built on Virtualization-based Security (VBS), a Windows […]

The post Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌