search
Microsoft Research
Trends
- 1
Phishing is in the spotlight as new reports detail a wave of scams and malware campaigns. Russian state hackers are said to be using a technique called RedFlick to spread malware, while Ukrainian authorities warn consumers about fake electricity bills. Researchers also flagged a remote access trojan distributed through fake Microsoft Store pages, and a report finds phishing exposure nearing 70% across key US industries.
- 2Microsoft unveils Quine, an AI research system for biology●Introducing Quine: An AI research system designed for the complexity of biology
Microsoft has introduced Quine, a new AI research system built to handle the complexity of biology. The company positions the system as a tool for scientific research in the life sciences, where data and systems are unusually intricate. Details about its capabilities and availability have not yet been widely reported.
- 3Researcher says Microsoft left 17 trillion records exposed●I could've accessed 17T Microsoft records
A security researcher has published a write-up describing how they could have accessed 17 trillion Microsoft records through a vulnerability. The blog post walks through the flaw and how access was theoretically possible. Hacker News readers are discussing the finding, debating the scale of the exposure and how Microsoft handles responsible disclosure.
- 4Fake Microsoft login page hosted on Google Sites flagged as phishing●Possible Phishing 🎣 on: ⚠️hxxps[:]//sites[.]google[.]com/l0gin-microsoftwebonlne[.]app/78694856535?usp=sharing/ 🧬 Analys
Cybersecurity researchers are warning about a phishing site impersonating a Microsoft login page, hosted on a Google Sites address with a deceptive domain mimicking Microsoft's online sign-in. The link has been defanged for safety and submitted for technical analysis on the urlDNA scanning platform. The case highlights how attackers abuse legitimate services like Google Sites to host credential-stealing pages.
- 5Microsoft Defender exclusions abused to hide malware●# infosec # malware # antivirus Blog elhacker.NET: Usan exclusiones de Microsoft Defender para ocultar malware https://
Attackers are reportedly using Microsoft Defender's exclusion settings to conceal malware from antivirus scanning, according to a report by Spanish security blog elhacker.NET. By adding malicious files or folders to Defender's exclusion list, malware can run undetected on Windows systems. The technique highlights ongoing concerns that trusted security tools themselves can be manipulated by attackers to bypass endpoint protection.
- 6Four Spy Groups Used Same Chrome and Windows Exploit Kit Within a Week●Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week https:// thehackernews.com/2026/09/four -spy-
Security researchers report that four separate spyware groups deployed the same exploit kit targeting Google Chrome and Microsoft Windows, all within a single week. The finding suggests the groups are sharing or purchasing identical hacking tools rather than developing their own, raising fresh concerns about the proliferation of surveillance capabilities. Cybersecurity commentators are highlighting the case as evidence of a growing grey market for exploits used against journalists, dissidents and other targets.
- 7TA419 phishing campaign targeted AI-policy specialists●Proofpoint says TA419 impersonated AI-policy figures and used a real-time Microsoft 365 phishing proxy against fewer tha
Security firm Proofpoint reports that the threat group TA419 impersonated prominent AI-policy figures and used a real-time Microsoft 365 phishing proxy to steal authenticated login sessions. The highly targeted campaign hit fewer than ten specialists. Researchers say it shows how attackers can capture live sessions, though successful compromises and government attribution remain unclear.
- 8Microsoft Science President Peter Lee to Retire After 16 Years▼Microsoft Science president Peter Lee to retire after 16 years for ‘once-in-a-lifetime’ next move
Peter Lee, president of Microsoft Research and its science division, is retiring after 16 years at the company, saying he is leaving for a 'once-in-a-lifetime' next move. Lee oversaw Microsoft's research organisation through a period of major AI advances, and his departure raises questions about who will lead the company's scientific research efforts next.
- 9Microsoft details Zimbra flaw allowing code execution via email●Zimbra CVE-2026-73570 lets one crafted email run code. Microsoft details the Zimbra command injection attacks: web shell
Microsoft researchers have detailed attacks exploiting a Zimbra command injection vulnerability, CVE-2026-73570, in which a single crafted email is enough to run code on the mail server. The documented attacks involve deploying web shells, gaining root access, and stealing cryptographic keys. Security teams running Zimbra are being urged to patch and review their servers for signs of compromise.
- 10Microsoft Research Unveils Quine, a Multimodal Biology Model▼Microsoft Research Debuts Quine, a Multimodal World Model of Biology
Microsoft Research has introduced Quine, a multimodal world model of biology. According to a report by Unite.AI, the system is designed to integrate different types of biological data into a unified model. Details about its capabilities, benchmarks and intended applications remain limited in the initial coverage, and independent expert reaction has not yet been reported.
- 11Critical Zimbra flaw CVE-2026-73570 actively exploited●🤖 CVE-2026-73570 (CVSS 8.9): unauthenticated OS command injection in Zimbra Collaboration Suite via its SNMP service, no
A critical vulnerability, CVE-2026-73570 with a CVSS score of 8.9, in Zimbra Collaboration Suite allowed unauthenticated attackers to run operating system commands through its SNMP service. According to Microsoft Security Research, attackers exploited the flaw to deploy web shells and steal mailbox credentials. A patch has been released, and security teams are urged to update affected servers promptly.
- 12Microsoft rates Security Copilot prompt injection risk as Low●MSRC assessed an indirect prompt injection into Security Copilot as Low severity because consequential action still requ
Microsoft's Security Response Center assessed an indirect prompt injection into Security Copilot as Low severity, reasoning that consequential action still required downstream automation or human approval. Security researchers are pushing back, arguing that rationale becomes untenable as AI systems are increasingly designed to perceive, reason, and act autonomously, with less human oversight built in.
- 13
Peter Lee, who has led Microsoft's research and science operations, is stepping down from his role as president. The news was first reported by The Information. Lee has been a central figure in Microsoft's research organization, overseeing work spanning artificial intelligence and other scientific fields. Details on his departure and a successor have not yet been announced.
- 14Cybersecurity researchers flag suspected Office 365 phishing domain●Possible Phishing 🎣 on: ⚠️hxxp[:]//office365licensingsupport[.]com 🧬 Analysis at: https:// urldna.io/scan/6abd40193b7750
Security researchers are warning about a suspected phishing site at office365licensingsupport.com, a domain name that imitates Microsoft's Office 365 branding to trick users into handing over credentials. A public analysis of the domain has been shared via the URLdna scanning service, and warnings are circulating in infosec communities with the domain deliberately defanged to prevent accidental clicks.
- 15Microsoft Launches Quine AI for Scientific Discovery▼Microsoft Pushes AI Deeper Into Scientific Discovery With Quine
Microsoft has introduced Quine, an AI system aimed at advancing scientific discovery. According to HPCwire, the company is pushing artificial intelligence deeper into research workflows, positioning Quine as a tool to accelerate experimentation and analysis in the sciences. Details about its capabilities and target research fields remain limited, and reaction from the scientific community is still emerging.