Search
Articles · 47

Microsoft Office Excel Use-After-Free Flaw Rated CVSS 8.8
Microsoft disclosed CVE-2026-62870, a use-after-free vulnerability in Excel rated CVSS 8.8 that allows remote code execution over a network. The flaw affects multiple supported versions of Microsoft 365 Apps, Excel 2016, Office 2019, and LTSC editions and was published August 3, 2026.

Microsoft Edge CVE-2026-57990 Allows External File Access
Microsoft disclosed CVE-2026-57990, a high-severity vulnerability in Chromium-based Edge that lets unauthorized attackers disclose information by accessing external files or directories over a network. The CVSS 7.4 flaw, published July 26 2026, underscores the need for prompt patching in widely deployed browsers.

Microsoft Edge Origin Validation Flaw CVE-2026-57989 Rated High Severity
Microsoft disclosed CVE-2026-57989, a high-severity origin validation error in Chromium-based Edge that lets an unauthorized attacker disclose information over a network. The flaw is rated CVSS 7.4 and affects versions before 150.0.4078.99.

Critical CVE-2026-56163 Hits Azure Kubernetes Service
Microsoft disclosed CVE-2026-56163, a critical vulnerability in Azure Kubernetes Service with a CVSS 3.1 score of 10.0 that allows unauthorized network-based privilege elevation. The flaw was received from Microsoft on July 24, 2026 and requires immediate attention from Azure Kubernetes users to prevent high-impact compromise.

CISA Adds Actively Exploited SharePoint Flaw CVE-2026-50522 to KEV
CISA added the actively exploited Microsoft SharePoint deserialization vulnerability CVE-2026-50522 to its Known Exploited Vulnerabilities catalog on 2026-07-22 with a federal due date of 2026-07-25. Agencies and organizations must apply vendor mitigations per BOD 26-04 or discontinue use if patches are unavailable.

Microsoft Halts July 2026 Windows 11 Update Rollout on Select Dell Machines
Microsoft has suspended the July 2026 Windows 11 Patch Tuesday update on certain Dell models after it triggered unexpected shutdowns, sluggish performance, higher heat and fast battery drain. The flaw traces to an Intel driver clashing with a new USB-C Connection Manager interface; exact affected machines remain undisclosed while a fix is prepared.

Microsoft to cut 605 jobs in Redmond
Microsoft has filed notice to permanently lay off 605 workers at its Redmond headquarters effective September 4, 2026. Axios notes 493 Redmond + other WA sites for the 605 total. The cuts are part of a sweeping Xbox gaming division restructure inside a global plan targeting approximately 3,200 roles in FY2027.

Critical RCE Flaw in Windows GDI+ Carries 9.6 CVSS Score
Microsoft disclosed CVE-2026-50380, a critical heap-based buffer overflow in Windows GDI+ that enables remote code execution over a network with a 9.6 CVSS score. The flaw affects numerous Windows 10 and 11 releases and is being patched as part of the July 2026 Patch Tuesday.

Microsoft Secure Boot bypassed for 13 years via unrevoked shims
ESET researchers found that 11 defective Microsoft-signed shims allowed trivial bypasses of UEFI Secure Boot for 13 years until revocation in the June 2026 Patch Tuesday update. The flaw affects Windows and Linux devices alike and enables persistent bootkit installation with minimal attacker effort.

Microsoft tells Windows 10 holdouts they can keep using their PCs until 2027
Microsoft is now emailing Windows 10 users about the consumer Extended Security Updates extension to October 2027 while making no reference to Windows 11. The outreach recognizes ongoing hardware cost barriers and stalled adoption rates that still leave millions on the older platform.

Microsoft to expand Patch Tuesday security releases with AI
Microsoft is expanding the number of fixes delivered in each Patch Tuesday release for Windows 11 by using AI to surface potential security issues earlier. The adjustment comes amid rising AI-assisted vulnerability hunting and exploitation by both attackers and security researchers.

Microsoft patches Nightmare Eclipse's RoguePlanet Defender zero-day
Microsoft has fixed the RoguePlanet zero-day in Defender via an update to the Malware Protection Engine. The patch closes the latest vulnerability publicly disclosed by researcher Nightmare Eclipse, who has sparred with the company over its handling of bug reports all year.

CVE-2026-58525 Reserved by Microsoft, Details Under Embargo
NIST lists CVE-2026-58525 as reserved by Microsoft with details withheld until the embargo ends. The placeholder NVD entry directs to an MSRC link while providing no severity, affected products, or technical description.

Microsoft accelerates Quantum Safe Program to 2029
Microsoft has moved its Quantum Safe Program target to 2029 because cryptographically relevant quantum computers could arrive sooner than previously expected. The update underscores the need for organizations to begin preparing now against harvest-now-decrypt-later attacks and future quantum decryption threats.

Microsoft cuts 4,800 jobs as new financial year starts
Microsoft eliminated approximately 4,800 roles on the first day of its new financial year, with the largest share coming from Xbox and commercial sales. The company cited industry-wide changes driven by AI, while noting that it has redeployed thousands of workers and used a voluntary retirement program to limit forced layoffs.

Microsoft assigns 6,000 workers and $2.5 billion to new AI client deployment subsidiary
Microsoft is committing $2.5 billion and reassigning 6,000 employees to its new Microsoft Frontier Co. subsidiary to help clients deploy artificial intelligence. The announcement follows similar forward deployed engineering initiatives launched this year by Amazon, Anthropic and OpenAI.

CISA Warns of Active Exploitation of SharePoint RCE Flaw
CISA warned Wednesday that attackers are exploiting CVE-2026-45659, a SharePoint RCE flaw patched by Microsoft in May, and added it to its KEV catalog on July 1 with a July 4 deadline for federal agencies. The deserialization vulnerability lets low-privileged authenticated users execute code remotely over the network, and more than 10,000 SharePoint servers remain exposed online.

Cloudflare to block mixed-purpose bots from ad-supported sites by default
Cloudflare will block mixed-use crawlers from ad-supported pages by default beginning September 15, 2026, aiming to protect publisher revenue from unpermitted AI training scrapes while still allowing search indexing. The policy affects bots from Apple, Google, and Microsoft that combine indexing with data harvesting and encourages clearer separation of those activities.

Microsoft pulls forward quantum-safe encryption deadline to 2029
Microsoft is accelerating its quantum-safe security roadmap to transition critical products and services to post-quantum cryptography by 2029. The move reflects advances in quantum computing that have shifted the risk horizon for "harvest now, decrypt later" attacks sooner than previously expected.

CISA Adds BlueHammer to KEV Catalog Over Ransomware Exploitation
CISA confirmed ransomware gangs are exploiting the BlueHammer Microsoft Defender privilege escalation vulnerability, CVE-2026-33825, previously abused in zero-day attacks. The KEV Catalog update highlights continued danger to federal networks and the urgency of patching.

Anthropic Claude Models Now Run on NVIDIA GB300 in Azure
Anthropic’s Claude models in Microsoft Foundry are now generally available on Microsoft Azure running on NVIDIA GB300 Blackwell Ultra GPUs. This gives Azure-native enterprises a new platform for building autonomous and domain-specific AI agents with enhanced performance and governed security.

Italy launches probe into Microsoft 365 price increases linked to AI
Italy's AGCM is investigating Microsoft over claims that fragmented notices left Microsoft 365 subscribers automatically moved to costlier plans once Copilot and Designer features were added without clear explanation of the changes.

Microsoft extends free Windows 10 security updates to 2027
Microsoft has extended free Windows 10 Extended Security Updates for personal devices by one year to October 12, 2027. The move gives users more time to transition amid hardware shortages and draws mixed reactions from consumer groups who say it comes too late.

Oracle's workforce shrinks by 21,000 amid AI-driven restructuring
Oracle reduced its global headcount by 21,000 to approximately 141,000 as of May 31, 2026, citing AI adoption among the factors. The job cuts freed resources for data-center construction serving clients including OpenAI and mirror similar workforce reductions at Microsoft and Meta.

Microsoft launches next Surface Pro and Laptop with Snapdragon X2
Microsoft has released the next Surface Pro and Surface Laptop powered by Snapdragon X2 processors, available immediately with business editions arriving July 14. The devices bring faster graphics performance, longer battery life and refined displays while continuing Surface's focus on hybrid AI workloads that span on-device and cloud processing.

Microsoft Edge shifts to two-week release cycle
Microsoft Edge is adopting a two-week release cycle for its Stable channel beginning with version 152 on August 27, while Extended Stable remains on an eight-week schedule. The shift delivers smaller, more frequent updates and faster security improvements to help organizations validate changes more easily.

Microsoft patches three Windows zero-days including BitLocker bypass
Microsoft patched GreenPlasma, MiniPlasma, and YellowKey zero-days in its June 2026 Patch Tuesday release, addressing SYSTEM privilege escalation and a BitLocker bypass. The flaws were disclosed by researcher Nightmare Eclipse in protest of Microsoft's vulnerability handling process.

Microsoft packages laced with credential stealer for second time
Microsoft open-source packages were compromised with a self-replicating credential stealer that activates inside AI coding agents, marking the second supply-chain attack on the company’s repositories in recent weeks. The campaign exploited legitimate OIDC tokens and SLSA provenance to bypass detection and target cloud identities.

Build 2026: Microsoft Places Its Biggest Bet Yet on AI Agents
Microsoft opens Build 2026 with a sweeping slate of agent-focused announcements, including an in-house reasoning model, agent hardware, and Windows-native AI capabilities. The moves signal Redmond’s intent to own the infrastructure where autonomous AI workers operate.

Microsoft Launches MAI-Thinking-1 Advanced Reasoning Model
Microsoft announced MAI-Thinking-1 as its new flagship model at Build 2026 among several proprietary systems developed in-house. The releases mark continued progress toward independent AI development following last year’s initial models and a recent renegotiation with OpenAI intended to loosen ties.

Microsoft Exchange Online Outage Hits Mail Flow in North America and Germany
Microsoft is investigating a widespread Exchange Online outage disrupting mail flow for customers in North America and Germany. Users face significant sending and receiving delays with some messages undelivered for over an hour while engineers seek the root cause.

Microsoft Optimizes Windows 11 for Developers with Deeper Linux Ties
Microsoft announced optimizations to Windows 11 for developers at Build, including native Linux command-line utilities, WSL containers, an Intelligent Terminal, and simplified setup configurations. The updates deepen Linux integration to improve performance, reliability, and workflow consistency across environments.

Microsoft Investigates Teams and Office Web File Access Outage
Microsoft is investigating an ongoing incident that prevents users from opening files in Teams and Office for the web, including Excel. Initial analysis indicates a potential cross-service issue and the outage has been tagged as a critical incident.

FTC Probe Targets Microsoft Azure Cloud Practices
The FTC is investigating Microsoft over potentially exclusionary practices in Azure cloud services and its AI role, sending detailed demands to competitors. This marks the first major antitrust scrutiny of the company in more than 25 years.

Microsoft Outage Blocks MFA Setup and My Sign-Ins Access
Microsoft confirmed an ongoing outage preventing some users from setting up MFA or reaching the My Sign-Ins platform with 504 Gateway Timeout errors reported. The company has failed over to alternate infrastructure and is evaluating further steps as elevated error rates continue.

Microsoft and NVIDIA Launch RTX Spark Windows PCs
Microsoft and NVIDIA announced the world’s most powerful and efficient thin-and-light Windows PCs accelerated by RTX Spark at NVIDIA GTC. The platform delivers 1 petaflop of AI performance and is purpose-built for local agents with deep Windows scheduler and power optimizations.

Microsoft Launches Surface Laptop Ultra with NVIDIA Blackwell GPU
Microsoft introduced Surface Laptop Ultra, its most powerful laptop yet featuring a NVIDIA Blackwell RTX GPU, up to 128GB unified memory and 1 petaflop of AI compute. The device is purpose-built for creators, developers and AI builders running demanding local workloads with quiet operation and all-day battery life.

Microsoft Phases Out SMS Authentication for All Accounts
Microsoft is phasing out SMS authentication and account recovery for all personal Microsoft accounts, including those used with Xbox, citing it as a leading source of fraud. The change promotes more secure passwordless options like passkeys to counter phishing and SIM-swap attacks while simplifying access.

Microsoft Settles Activision Suit for $250 Million
Microsoft will pay $250 million to end a lawsuit filed by Swedish pension fund AP7 that alleged its $69 billion Activision Blizzard purchase was undervalued and rushed to dodge scandal fallout. The resolution also ends Bobby Kotick’s countersuit and includes a prior statement denying any substantiated claims of systemic misconduct.

Microsoft Lets Office Users Disable Floating Copilot Button
Microsoft plans Office updates next week that let people shift the floating Copilot button to the ribbon. The change responds to complaints, especially from Excel users who said the button blocked cells and could not be fully disabled.

GitHub Battles Outages, Hacks, and Talent Drain at Microsoft
GitHub is battling multiple outages, a remote code execution vulnerability, an internal hack, and a wave of executive departures nearly eight years after its $7.5 billion acquisition by Microsoft. Leadership changes that began with the former CEO's resignation last summer have triggered a talent exodus to a direct competitor and heightened concerns over falling behind in AI coding tools.

Microsoft Patches Two Actively Exploited Defender Zero-Days
Microsoft began rolling out patches Wednesday for two zero-day vulnerabilities in Defender that attackers are actively exploiting to gain SYSTEM privileges or trigger denial-of-service conditions. CISA added the flaws, known as RedSun and UnDefend, to its Known Exploited Vulnerabilities catalog and gave federal agencies until June 3 to apply fixes.

Microsoft Launches Driver Quality Initiative for Windows
Microsoft launched the Driver Quality Initiative at WinHEC 2026 targeting improved driver quality, reliability and security. The program addresses an ecosystem of thousands of partners supporting tens of thousands of driver families that affect overall Windows stability and performance.

Microsoft Launches New Surface Pro, Laptop for Business with Intel Core Ultra
Microsoft announced new Surface Pro for Business and Surface Laptop for Business models powered by Intel Core Ultra Series 3 processors that are available today in select markets with significant graphics performance gains. The devices address IT challenges around AI workloads, security and investment decisions by integrating hardware, software and on-device AI capabilities.

Microsoft Lets Windows 11 Taskbar Sit on Any Edge
Microsoft announced it will let Windows 11 users position the taskbar on any screen edge while adding toggles and quality improvements to the Start menu. The updates restore capabilities removed at Windows 11 launch and focus on making the OS more personal.

Microsoft Phases Out SMS Authentication Over Fraud Concerns
Microsoft is phasing out SMS codes for login and recovery on personal accounts, citing the method as a leading source of fraud. The move accelerates the company's passwordless strategy centered on passkeys to counter threats and simplify access.

MiniPlasma Zero-Day Grants SYSTEM Access on Fully Patched Windows
A researcher known as Chaotic Eclipse has published a MiniPlasma PoC that reuses a 2020 Cloud Filter driver flaw to grant SYSTEM privileges on the latest patched Windows 11. The release forms part of an ongoing series of Windows zero-days whose author alleges poor treatment by Microsoft’s vulnerability handling program.
From the feed · 46
58 extensions still rely on Manifest V2 in the Edge Add-On Store, with only three lacking MV3 alternatives as Microsoft ends support for the older platform. Users can move to uBlock Origin Lite or similar replacements.
Compromised websites are pulling malicious instructions from the BNB Chain to deliver malware through fake CAPTCHA prompts. Microsoft says the attacks trick visitors into running the payloads on Windows devices.
Microsoft Edge is advancing its extensions platform to Manifest Version 3, the Chromium standard it first committed to in 2020. The move follows ongoing work with developers to update the ecosystem.
18 months after launch, Microsoft has retired the Teams Live chat widget for website support. The feature is now in the company's growing list of discontinued experiments.
An attacker reportedly phished access to a US defense supplier's Microsoft 365 account, reaching engineering files and potentially export-controlled technical data.
Microsoft disclosed critical vulnerability CVE-2026-59115 in the Entra Provisioning Service. The path traversal issue enables an authorized attacker to elevate privileges over a network. It receives a CVSS score of 9.9 and was published on August 6, 2026.
Microsoft Teams has a CVSS 7.5 vulnerability from improper cryptographic signature verification. An attacker can spoof identities over the network without authentication.
200 accounts were compromised after hackers exploited vulnerabilities in Switzerland's federal Microsoft SharePoint servers.
Microsoft 365 Copilot reached hundreds of millions of users with agent reasoning. The Work IQ Developer Tools preview now supplies the missing layer for building production agents on top of it.
Microsoft EVP Charles Lamanna is building a Copilot Super App as a single front door for the company's AI products. The effort aims to consolidate its expanding lineup and establish Microsoft as the Copilot company.
Microsoft removed domain exclusion from Microsoft 365 Copilot days after adding the option. An allow list approach may prove more practical for admins.
Microsoft quantum chief Zulfi Alam says his team does not need to prove it engineered a new state of matter. He views external validation as unnecessary for the company's computing push.
Microsoft removed its 32 GB RAM recommendation from Windows 11 guidance. 8 GB laptops are returning to the Surface lineup.
Microsoft is directing its developers to default to OpenAI's top model in GitHub Copilot. The move leverages existing IP rights in the partnership as part of an internal efficiency effort.
A macOS ClickFix campaign now routes infostealer lures through browser-fingerprinting gates instead of serving them openly. The shift complicates infrastructure detection while opening new defender telemetry paths.
Microsoft is reportedly telling engineers to curb excessive token consumption in Copilot projects, shifting emphasis to measurable results instead of high usage figures.
£270 million in pre-owned Microsoft licenses now sits at the center of a tribunal review that also touches a multibillion-pound class action. The cases center on how reseller claims intersect with broader licensing disputes.
Greatness phishing-as-a-service has added RingCentral spoofing to its adversary-in-the-middle and device-code attacks against Microsoft 365 accounts.
Microsoft is extending Zero Trust controls to AI agents and DevSecOps pipelines with new tools and implementation guidance.
Microsoft Defender isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage ransomware attack before the payload could persist or spread.
$20M in Microsoft bug bounties is now in reach this year as AI tools push vulnerability reports higher and the company widens payout rules to match the volume.
Microsoft tied a global campaign targeting hotel Wi-Fi networks to Russian actor Midnight Blizzard, with custom malware used to access Microsoft 365 accounts.
CVSS 7.4 type confusion flaw CVE-2026-66321 in Microsoft Edge allows remote attackers to execute code over the network.
CVSS 8.1 origin validation error in Microsoft Edge allows an unauthorized attacker to disclose information over a network.
CVSS 7.4 vulnerability CVE-2026-65802 hits Microsoft Edge for Android. External control of file name or path lets an unauthorized attacker disclose information over a network.
Apple proposed a project plan on June 26 to add iPhone-to-Windows copy and paste in the EU. Microsoft had requested the feature through Apple's DMA interoperability system, with evaluation underway since March.
8 GB Windows 11 systems will get memory reductions from Microsoft by the end of 2026. The company is addressing the OS's current RAM demands on that hardware tier.
Microsoft Teams is rolling out interface safeguards that block accidental clicks from ending a video call or triggering other unintended actions. The changes target common meeting mishaps in the desktop app.
Microsoft and Amazon beat cloud revenue expectations in their latest quarterly results, lifting stocks. Record AI spending reduces free cash flow at both firms. Microsoft's headcount declines for the first time since 2016, with R&D roles hit hardest.
Storm-2945, a Midnight Blizzard sub-cluster, has compromised hotel sign-in portals since May 2026 to deliver malware to travelers and steal credentials in an operation called CaptiveCrunch.
Optics and advanced packaging now lead the OCP APAC Summit agenda, with TSMC, Applied Materials, Advantest, and ASE sharing the stage alongside Microsoft, Nvidia, and Google. Servers have moved to the background.
Microsoft's headcount fell to 223,000 as of June 30, down 5,000 from a year earlier and the first annual decline since 2016. Product R&D roles drove most of the drop for the second straight year.
Founder lineages for 625 Washington tech companies trace primarily to Microsoft and the University of Washington. Emerging hubs are mostly out-of-state firms with local engineering centers.
Kremlin-linked hackers are exploiting a Microsoft Exchange flaw to plant backdoors that survive credential rotation and disk re-imaging on unpatched servers.
Microsoft revenue reached $331.8 billion for the fiscal year ended June 30, up 18% or $50.1 billion. A table in the 10-K filing breaks out the segments driving and dragging that total.
Microsoft's July 2026 security updates focus on protecting AI workloads, deploying AI for threat defense, and hardening the infrastructure those systems rely on. The changes target both new AI-specific risks and core operational controls.
Attackers are impersonating IT support in Microsoft Teams calls to obtain remote access and deploy Chaos ransomware against North American organizations.
Microsoft added a Copilot button directly beside the ribbon in classic Outlook. The placement aims to drive consistency but leaves admins with new questions on visibility controls.
Connecting to a hotel Wi-Fi network can expose a Microsoft 365 account to attackers with no clicks or links required. The network itself handles the compromise.
88 new data centers anchor Microsoft's AI infrastructure expansion, announced with fiscal 2026 revenue above $331 billion, Microsoft Cloud above $214 billion, and Azure above $100 billion.
Security researcher Håkon Måløy disclosed multiple vulnerabilities in Microsoft Copilot that could let hidden instructions turn Office documents into an AI-like worm. The flaws rely on carefully crafted prompts embedded as white text.
Microsoft called FY26 a record year on strong demand across the Microsoft Cloud and shared three highlights.
Microsoft's profit jumped 31.6% as the company increased its AI spending. The results show continued heavy investment in data centers and model infrastructure.
Satya Nadella said Copilot is evolving rapidly from chat to Cowork to Autopilots. Microsoft will combine these experiences, including code, into one super app for consumer and commercial use this year.
Meta and Microsoft both flagged sharply rising AI infrastructure costs in their latest quarterly updates.