Search
Articles · 10

Microsoft Office Excel Use-After-Free Flaw Rated CVSS 8.8
Microsoft disclosed CVE-2026-62870, a use-after-free vulnerability in Excel rated CVSS 8.8 that allows remote code execution over a network. The flaw affects multiple supported versions of Microsoft 365 Apps, Excel 2016, Office 2019, and LTSC editions and was published August 3, 2026.

Microsoft Edge CVE-2026-57990 Allows External File Access
Microsoft disclosed CVE-2026-57990, a high-severity vulnerability in Chromium-based Edge that lets unauthorized attackers disclose information by accessing external files or directories over a network. The CVSS 7.4 flaw, published July 26 2026, underscores the need for prompt patching in widely deployed browsers.

Microsoft Edge Origin Validation Flaw CVE-2026-57989 Rated High Severity
Microsoft disclosed CVE-2026-57989, a high-severity origin validation error in Chromium-based Edge that lets an unauthorized attacker disclose information over a network. The flaw is rated CVSS 7.4 and affects versions before 150.0.4078.99.

Critical CVE-2026-56163 Hits Azure Kubernetes Service
Microsoft disclosed CVE-2026-56163, a critical vulnerability in Azure Kubernetes Service with a CVSS 3.1 score of 10.0 that allows unauthorized network-based privilege elevation. The flaw was received from Microsoft on July 24, 2026 and requires immediate attention from Azure Kubernetes users to prevent high-impact compromise.

CISA Adds Actively Exploited SharePoint Flaw CVE-2026-50522 to KEV
CISA added the actively exploited Microsoft SharePoint deserialization vulnerability CVE-2026-50522 to its Known Exploited Vulnerabilities catalog on 2026-07-22 with a federal due date of 2026-07-25. Agencies and organizations must apply vendor mitigations per BOD 26-04 or discontinue use if patches are unavailable.

Microsoft Halts July 2026 Windows 11 Update Rollout on Select Dell Machines
Microsoft has suspended the July 2026 Windows 11 Patch Tuesday update on certain Dell models after it triggered unexpected shutdowns, sluggish performance, higher heat and fast battery drain. The flaw traces to an Intel driver clashing with a new USB-C Connection Manager interface; exact affected machines remain undisclosed while a fix is prepared.

Microsoft to cut 605 jobs in Redmond
Microsoft has filed notice to permanently lay off 605 workers at its Redmond headquarters effective September 4, 2026. Axios notes 493 Redmond + other WA sites for the 605 total. The cuts are part of a sweeping Xbox gaming division restructure inside a global plan targeting approximately 3,200 roles in FY2027.

Critical RCE Flaw in Windows GDI+ Carries 9.6 CVSS Score
Microsoft disclosed CVE-2026-50380, a critical heap-based buffer overflow in Windows GDI+ that enables remote code execution over a network with a 9.6 CVSS score. The flaw affects numerous Windows 10 and 11 releases and is being patched as part of the July 2026 Patch Tuesday.

Microsoft Secure Boot bypassed for 13 years via unrevoked shims
ESET researchers found that 11 defective Microsoft-signed shims allowed trivial bypasses of UEFI Secure Boot for 13 years until revocation in the June 2026 Patch Tuesday update. The flaw affects Windows and Linux devices alike and enables persistent bootkit installation with minimal attacker effort.

Microsoft tells Windows 10 holdouts they can keep using their PCs until 2027
Microsoft is now emailing Windows 10 users about the consumer Extended Security Updates extension to October 2027 while making no reference to Windows 11. The outreach recognizes ongoing hardware cost barriers and stalled adoption rates that still leave millions on the older platform.
From the feed · 46
58 extensions still rely on Manifest V2 in the Edge Add-On Store, with only three lacking MV3 alternatives as Microsoft ends support for the older platform. Users can move to uBlock Origin Lite or similar replacements.
Compromised websites are pulling malicious instructions from the BNB Chain to deliver malware through fake CAPTCHA prompts. Microsoft says the attacks trick visitors into running the payloads on Windows devices.
Microsoft Edge is advancing its extensions platform to Manifest Version 3, the Chromium standard it first committed to in 2020. The move follows ongoing work with developers to update the ecosystem.
18 months after launch, Microsoft has retired the Teams Live chat widget for website support. The feature is now in the company's growing list of discontinued experiments.
An attacker reportedly phished access to a US defense supplier's Microsoft 365 account, reaching engineering files and potentially export-controlled technical data.
Microsoft disclosed critical vulnerability CVE-2026-59115 in the Entra Provisioning Service. The path traversal issue enables an authorized attacker to elevate privileges over a network. It receives a CVSS score of 9.9 and was published on August 6, 2026.
Microsoft Teams has a CVSS 7.5 vulnerability from improper cryptographic signature verification. An attacker can spoof identities over the network without authentication.
200 accounts were compromised after hackers exploited vulnerabilities in Switzerland's federal Microsoft SharePoint servers.
Microsoft 365 Copilot reached hundreds of millions of users with agent reasoning. The Work IQ Developer Tools preview now supplies the missing layer for building production agents on top of it.
Microsoft EVP Charles Lamanna is building a Copilot Super App as a single front door for the company's AI products. The effort aims to consolidate its expanding lineup and establish Microsoft as the Copilot company.
Microsoft removed domain exclusion from Microsoft 365 Copilot days after adding the option. An allow list approach may prove more practical for admins.
Microsoft quantum chief Zulfi Alam says his team does not need to prove it engineered a new state of matter. He views external validation as unnecessary for the company's computing push.
Microsoft removed its 32 GB RAM recommendation from Windows 11 guidance. 8 GB laptops are returning to the Surface lineup.
Microsoft is directing its developers to default to OpenAI's top model in GitHub Copilot. The move leverages existing IP rights in the partnership as part of an internal efficiency effort.
A macOS ClickFix campaign now routes infostealer lures through browser-fingerprinting gates instead of serving them openly. The shift complicates infrastructure detection while opening new defender telemetry paths.
Microsoft is reportedly telling engineers to curb excessive token consumption in Copilot projects, shifting emphasis to measurable results instead of high usage figures.
£270 million in pre-owned Microsoft licenses now sits at the center of a tribunal review that also touches a multibillion-pound class action. The cases center on how reseller claims intersect with broader licensing disputes.
Greatness phishing-as-a-service has added RingCentral spoofing to its adversary-in-the-middle and device-code attacks against Microsoft 365 accounts.
Microsoft is extending Zero Trust controls to AI agents and DevSecOps pipelines with new tools and implementation guidance.
Microsoft Defender isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage ransomware attack before the payload could persist or spread.
$20M in Microsoft bug bounties is now in reach this year as AI tools push vulnerability reports higher and the company widens payout rules to match the volume.
Microsoft tied a global campaign targeting hotel Wi-Fi networks to Russian actor Midnight Blizzard, with custom malware used to access Microsoft 365 accounts.
CVSS 7.4 type confusion flaw CVE-2026-66321 in Microsoft Edge allows remote attackers to execute code over the network.
CVSS 8.1 origin validation error in Microsoft Edge allows an unauthorized attacker to disclose information over a network.
CVSS 7.4 vulnerability CVE-2026-65802 hits Microsoft Edge for Android. External control of file name or path lets an unauthorized attacker disclose information over a network.
Apple proposed a project plan on June 26 to add iPhone-to-Windows copy and paste in the EU. Microsoft had requested the feature through Apple's DMA interoperability system, with evaluation underway since March.
8 GB Windows 11 systems will get memory reductions from Microsoft by the end of 2026. The company is addressing the OS's current RAM demands on that hardware tier.
Microsoft Teams is rolling out interface safeguards that block accidental clicks from ending a video call or triggering other unintended actions. The changes target common meeting mishaps in the desktop app.
Microsoft and Amazon beat cloud revenue expectations in their latest quarterly results, lifting stocks. Record AI spending reduces free cash flow at both firms. Microsoft's headcount declines for the first time since 2016, with R&D roles hit hardest.
Storm-2945, a Midnight Blizzard sub-cluster, has compromised hotel sign-in portals since May 2026 to deliver malware to travelers and steal credentials in an operation called CaptiveCrunch.
Optics and advanced packaging now lead the OCP APAC Summit agenda, with TSMC, Applied Materials, Advantest, and ASE sharing the stage alongside Microsoft, Nvidia, and Google. Servers have moved to the background.
Microsoft's headcount fell to 223,000 as of June 30, down 5,000 from a year earlier and the first annual decline since 2016. Product R&D roles drove most of the drop for the second straight year.
Founder lineages for 625 Washington tech companies trace primarily to Microsoft and the University of Washington. Emerging hubs are mostly out-of-state firms with local engineering centers.
Kremlin-linked hackers are exploiting a Microsoft Exchange flaw to plant backdoors that survive credential rotation and disk re-imaging on unpatched servers.
Microsoft revenue reached $331.8 billion for the fiscal year ended June 30, up 18% or $50.1 billion. A table in the 10-K filing breaks out the segments driving and dragging that total.
Microsoft's July 2026 security updates focus on protecting AI workloads, deploying AI for threat defense, and hardening the infrastructure those systems rely on. The changes target both new AI-specific risks and core operational controls.
Attackers are impersonating IT support in Microsoft Teams calls to obtain remote access and deploy Chaos ransomware against North American organizations.
Microsoft added a Copilot button directly beside the ribbon in classic Outlook. The placement aims to drive consistency but leaves admins with new questions on visibility controls.
Connecting to a hotel Wi-Fi network can expose a Microsoft 365 account to attackers with no clicks or links required. The network itself handles the compromise.
88 new data centers anchor Microsoft's AI infrastructure expansion, announced with fiscal 2026 revenue above $331 billion, Microsoft Cloud above $214 billion, and Azure above $100 billion.
Security researcher Håkon Måløy disclosed multiple vulnerabilities in Microsoft Copilot that could let hidden instructions turn Office documents into an AI-like worm. The flaws rely on carefully crafted prompts embedded as white text.
Microsoft called FY26 a record year on strong demand across the Microsoft Cloud and shared three highlights.
Microsoft's profit jumped 31.6% as the company increased its AI spending. The results show continued heavy investment in data centers and model infrastructure.
Satya Nadella said Copilot is evolving rapidly from chat to Cowork to Autopilots. Microsoft will combine these experiences, including code, into one super app for consumer and commercial use this year.
Meta and Microsoft both flagged sharply rising AI infrastructure costs in their latest quarterly updates.