BTC$63,057+0.34% LTC$44.05+1.12% XMR$412.08+4.33%
TorPortal TorPortalMarkets, mirrors, dark web news
News › Company

News tagged Microsoft

Every TorPortal story that mentions Microsoft. 60 stories, newest first. Category: company.

Latest coverage of Microsoft

Click a headline for the full story or jump to the original.

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
BleepingComputer · Aug 13, 2026 · 1 min read

Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt

An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking.
Microsoft patches LegacyHive Windows zero-day vulnerability
BleepingComputer · Aug 13, 2026 · 1 min read

Microsoft patches LegacyHive Windows zero-day vulnerability

Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday.
AI 'watermark removers' flood the web. Almost none can prove they work.
BleepingComputer · Aug 13, 2026 · 1 min read

AI 'watermark removers' flood the web. Almost none can prove they work.

Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and paid AI detection evasion services. None of the tools' claims…
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
BleepingComputer · Aug 12, 2026 · 1 min read

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges.
Lazarus hackers exploited Windows zero-day to target defense firms
BleepingComputer · Aug 12, 2026 · 1 min read

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign.
Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery
The Record · Aug 12, 2026 · 3 min read

Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery

This month’s update features about five times the volume of patches Microsoft was shipping in a typical month before AI-assisted vulnerability discovery took hold.
Hackers leverage new Microsoft SharePoint exploit in attacks
BleepingComputer · Aug 12, 2026 · 1 min read

Hackers leverage new Microsoft SharePoint exploit in attacks

Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday.
CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
The Record · Aug 12, 2026 · 3 min read

CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign

Researchers disclosed the bug to Microsoft after examining a long-running campaign by North Korean hackers to exploit the job application process.
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
BleepingComputer · Aug 12, 2026 · 1 min read

New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges

Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldBreak" after Microsoft released the August 2026 Patch Tuesday security updates.
DeadLock ransomware uses blockchain to resist infrastructure takedown
BleepingComputer · Aug 11, 2026 · 1 min read

DeadLock ransomware uses blockchain to resist infrastructure takedown

The DeadLock ransomware operation is using a decentralized infrastructure that relies on blockchain-backed services to protect its communication with victims and data-leak activity.
Microsoft Plugs Nearly 400 Security Holes
Krebs on Security · Aug 11, 2026 · 4 min read

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly…
Microsoft releases Windows 10 KB5120249 extended security update
BleepingComputer · Aug 11, 2026 · 1 min read

Microsoft releases Windows 10 KB5120249 extended security update

Microsoft has released Windows 10 KB5120249 Extended Security Updates for versions 22H2 and 21H2 to fix security vulnerabilities and bugs.
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
BleepingComputer · Aug 11, 2026 · 1 min read

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities.
Windows 11 KB5121003 & KB5120240 cumulative updates released
BleepingComputer · Aug 11, 2026 · 1 min read

Windows 11 KB5121003 & KB5120240 cumulative updates released

Microsoft has released Windows 11 KB5121003 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features.
Wesco confirms security incident after ExfilSquad claims data theft
BleepingComputer · Aug 11, 2026 · 1 min read

Wesco confirms security incident after ExfilSquad claims data theft

Global supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident.
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
BleepingComputer · Aug 11, 2026 · 1 min read

CISA: Microsoft SharePoint flaw now exploited in ransomware attacks

CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
New Passkey Attacks Can Recover Synced Private Keys
DarkDotWeb · Aug 11, 2026 · 4 min read

New Passkey Attacks Can Recover Synced Private Keys

Researchers found attacks that can recover synced passkeys or abuse Windows authentication on compromised systems without breaking passkey cryptography.
New StormEncryptor ransomware used by former Medusa affiliate
BleepingComputer · Aug 10, 2026 · 1 min read

New StormEncryptor ransomware used by former Medusa affiliate

A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor.
China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns
The Record · Aug 10, 2026 · 3 min read

China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns

A China-linked threat actor is believed to be exploiting a critical vulnerability affecting cybersecurity software from the company N-able.
Hackers breach TrueConf to trojanize client installers with backdoors
BleepingComputer · Aug 8, 2026 · 1 min read

Hackers breach TrueConf to trojanize client installers with backdoors

The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors.
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
BleepingComputer · Aug 6, 2026 · 1 min read

Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile threat actors.
Swiss government SharePoint breach compromised 200 accounts
BleepingComputer · Aug 6, 2026 · 1 min read

Swiss government SharePoint breach compromised 200 accounts

Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts.
How AI-powered phishing killed blocklists for good
BleepingComputer · Aug 5, 2026 · 8 min read

How AI-powered phishing killed blocklists for good

AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense…
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
BleepingComputer · Aug 4, 2026 · 1 min read

Phishing service spoofs RingCentral to steal Microsoft 365 accounts

The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts.
New XCSSET variant targets macOS devs via compromised Xcode projects
BleepingComputer · Aug 4, 2026 · 1 min read

New XCSSET variant targets macOS devs via compromised Xcode projects

A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories.
Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected
The Record · Aug 4, 2026 · 2 min read

Swiss IT agency hacked, 200 accounts compromised, SharePoint vulns suspected

The Federal Office for Information Technology and Communications (BIT) said specialists detected anomalies in on-premises Microsoft servers. The Swiss agency could not confirm exactly how the hackers got in.
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
BleepingComputer · Aug 4, 2026 · 1 min read

Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29.
Fake Roblox Xeno script launcher pushes infostealer, RAT malware
BleepingComputer · Aug 3, 2026 · 1 min read

Fake Roblox Xeno script launcher pushes infostealer, RAT malware

Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information.
Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says
The Record · Aug 3, 2026 · 3 min read

Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says

Russian state-sponsored hackers have been compromising hotel Wi-Fi networks around the world to steal travelers' login credentials and infect devices with espionage malware, Microsoft said.
Fake Wi-Fi Updates Deploy CornFlake RAT
DarkDotWeb · Aug 3, 2026 · 4 min read

Fake Wi-Fi Updates Deploy CornFlake RAT

Hackers hijack hospitality Wi-Fi portals to deliver CornFlake RAT, steal Microsoft 365 tokens and target travelers.
BleepingComputer · Jul 30, 2026 · 1 min read

ShinyHunters claims Brinks Home breach, threatens to leak stolen data

Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data.
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
BleepingComputer · Jul 30, 2026 · 1 min read

Microsoft Teams vishing attacks lead to Chaos ransomware attacks

Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations.
After the Break-In: What Attackers Do Once They're Already Inside
BleepingComputer · Jul 30, 2026 · 1 min read

After the Break-In: What Attackers Do Once They're Already Inside

Attackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and why defenders must investigate the…
North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
The Record · Jul 30, 2026 · 4 min read

North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn

Cyberattack tools and infrastructure used by North Korea’s Lazarus Group appear to have been shared with ransomware criminals targeting South Korean organizations — further evidence of deepening entanglement between Pyongyang-backed…
North Korean hackers behind major open-source supply chain attacks, Amazon says
The Record · Jul 30, 2026 · 2 min read

North Korean hackers behind major open-source supply chain attacks, Amazon says

A North Korea-linked hacker group was behind several high-profile compromises of open-source software libraries used by developers worldwide, researchers have found.
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
BleepingComputer · Jul 29, 2026 · 1 min read

Russian hackers exploit Exchange OWA zero-day for long-term mailbox access

The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper.
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
BleepingComputer · Jul 29, 2026 · 1 min read

Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare

Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters.
Laundry Bear’s webmail hackers had more in store after February, report says
The Record · Jul 29, 2026 · 2 min read

Laundry Bear’s webmail hackers had more in store after February, report says

Researchers say the Russian state-linked hacking group tracked as Laundry Bear recently began exploiting a bug in Microsoft Outlook Web Access.
Windows 11 KB5101684 update released with 42 changes and fixes
BleepingComputer · Jul 29, 2026 · 1 min read

Windows 11 KB5101684 update released with 42 changes and fixes

​​Microsoft has released the KB5101684 preview cumulative update for Windows 11 24H2 and 25H2, which 42 bug fixes and additional feature improvements for the operating system.
New Certighost PoC exploit lets attackers hijack Windows domains
BleepingComputer · Jul 27, 2026 · 1 min read

New Certighost PoC exploit lets attackers hijack Windows domains

A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain.
Shadow AI agents are multiplying. Here's how to find and secure them.
BleepingComputer · Jul 27, 2026 · 1 min read

Shadow AI agents are multiplying. Here's how to find and secure them.

Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and govern AI agents before unmanaged permissions and autonomous…
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
BleepingComputer · Jul 25, 2026 · 1 min read

Steam forum ClickFix attacks infect gamers with XMRig cryptominers

Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers.
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
BleepingComputer · Jul 24, 2026 · 1 min read

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages.
Microsoft blames massive Microsoft 365 outage on maintenance bug
BleepingComputer · Jul 24, 2026 · 1 min read

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services.
International alert spotlights Russia-linked attacks on Zimbra webmail
The Record · Jul 23, 2026 · 2 min read

International alert spotlights Russia-linked attacks on Zimbra webmail

A Kremlin-backed group known as Laundry Bear has been using a zero-click phishing technique to break into Zimbra webmail accounts worldwide, the U.S. and other nations said.
Russian hackers exploit Zimbra zero-click flaw for email theft
BleepingComputer · Jul 23, 2026 · 1 min read

Russian hackers exploit Zimbra zero-click flaw for email theft

CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a…
Microsoft 365 outage affects Teams, SharePoint and other services
BleepingComputer · Jul 23, 2026 · 1 min read

Microsoft 365 outage affects Teams, SharePoint and other services

Microsoft is impacted by a massive outage affecting Teams and Microsoft 365 services, primarily affecting users in North America.
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
BleepingComputer · Jul 23, 2026 · 1 min read

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers.
Microsoft working to fix Exchange Online mailbox quarantine issue
BleepingComputer · Jul 23, 2026 · 1 min read

Microsoft working to fix Exchange Online mailbox quarantine issue

Microsoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers' mailboxes since Sunday.
BleepingComputer · Jul 22, 2026 · 1 min read

How enterprise GenAI can amplify ransomware risk — and how to contain it

Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled…
Microsoft to stop Exchange 2016 / 2019 security updates in October
BleepingComputer · Jul 22, 2026 · 1 min read

Microsoft to stop Exchange 2016 / 2019 security updates in October

Microsoft has reminded customers that it will stop shipping security updates for Exchange 2016 and 2019 through the Extended Security Update (ESU) program in October.
Police dismantle Kratos phishing platform, arrest developer
BleepingComputer · Jul 21, 2026 · 1 min read

Police dismantle Kratos phishing platform, arrest developer

Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia.
Critical SharePoint RCE flaw exploited to steal machine keys
BleepingComputer · Jul 21, 2026 · 1 min read

Critical SharePoint RCE flaw exploited to steal machine keys

Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched.
Closing the Identity Gaps in Critical Infrastructure Security
BleepingComputer · Jul 21, 2026 · 1 min read

Closing the Identity Gaps in Critical Infrastructure Security

Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical…
Microsoft shares manual fix for WSUS sync delays and timeouts
BleepingComputer · Jul 21, 2026 · 1 min read

Microsoft shares manual fix for WSUS sync delays and timeouts

Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out.
Windows LegacyHive zero-day flaw gets free, unofficial patches
BleepingComputer · Jul 21, 2026 · 1 min read

Windows LegacyHive zero-day flaw gets free, unofficial patches

Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems.
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
BleepingComputer · Jul 20, 2026 · 1 min read

New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfiltrate stolen data.
Microsoft confirms Windows Server Update Services sync delays
BleepingComputer · Jul 20, 2026 · 1 min read

Microsoft confirms Windows Server Update Services sync delays

Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week.
Windows KB5121767 OOB update fixes shutdowns on some Dell PCs
BleepingComputer · Jul 20, 2026 · 1 min read

Windows KB5121767 OOB update fixes shutdowns on some Dell PCs

Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates.
Microsoft warns of surge in ACR Stealer attacks on customers
BleepingComputer · Jul 18, 2026 · 1 min read

Microsoft warns of surge in ACR Stealer attacks on customers

Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers.

← All news