search
Microsoft Security Research
Trends
- 1
Phishing is in the spotlight as new reports detail a wave of scams and malware campaigns. Russian state hackers are said to be using a technique called RedFlick to spread malware, while Ukrainian authorities warn consumers about fake electricity bills. Researchers also flagged a remote access trojan distributed through fake Microsoft Store pages, and a report finds phishing exposure nearing 70% across key US industries.
- 2Researcher says Microsoft left 17 trillion records exposed●I could've accessed 17T Microsoft records
A security researcher has published a write-up describing how they could have accessed 17 trillion Microsoft records through a vulnerability. The blog post walks through the flaw and how access was theoretically possible. Hacker News readers are discussing the finding, debating the scale of the exposure and how Microsoft handles responsible disclosure.
- 3Fake Microsoft login page hosted on Google Sites flagged as phishing●Possible Phishing 🎣 on: ⚠️hxxps[:]//sites[.]google[.]com/l0gin-microsoftwebonlne[.]app/78694856535?usp=sharing/ 🧬 Analys
Cybersecurity researchers are warning about a phishing site impersonating a Microsoft login page, hosted on a Google Sites address with a deceptive domain mimicking Microsoft's online sign-in. The link has been defanged for safety and submitted for technical analysis on the urlDNA scanning platform. The case highlights how attackers abuse legitimate services like Google Sites to host credential-stealing pages.
- 4Microsoft Defender exclusions abused to hide malware●# infosec # malware # antivirus Blog elhacker.NET: Usan exclusiones de Microsoft Defender para ocultar malware https://
Attackers are reportedly using Microsoft Defender's exclusion settings to conceal malware from antivirus scanning, according to a report by Spanish security blog elhacker.NET. By adding malicious files or folders to Defender's exclusion list, malware can run undetected on Windows systems. The technique highlights ongoing concerns that trusted security tools themselves can be manipulated by attackers to bypass endpoint protection.
- 5Four Spy Groups Used Same Chrome and Windows Exploit Kit Within a Week●Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week https:// thehackernews.com/2026/09/four -spy-
Security researchers report that four separate spyware groups deployed the same exploit kit targeting Google Chrome and Microsoft Windows, all within a single week. The finding suggests the groups are sharing or purchasing identical hacking tools rather than developing their own, raising fresh concerns about the proliferation of surveillance capabilities. Cybersecurity commentators are highlighting the case as evidence of a growing grey market for exploits used against journalists, dissidents and other targets.
- 6Microsoft details Zimbra flaw allowing code execution via email●Zimbra CVE-2026-73570 lets one crafted email run code. Microsoft details the Zimbra command injection attacks: web shell
Microsoft researchers have detailed attacks exploiting a Zimbra command injection vulnerability, CVE-2026-73570, in which a single crafted email is enough to run code on the mail server. The documented attacks involve deploying web shells, gaining root access, and stealing cryptographic keys. Security teams running Zimbra are being urged to patch and review their servers for signs of compromise.
- 7TA419 phishing campaign targeted AI-policy specialists●Proofpoint says TA419 impersonated AI-policy figures and used a real-time Microsoft 365 phishing proxy against fewer tha
Security firm Proofpoint reports that the threat group TA419 impersonated prominent AI-policy figures and used a real-time Microsoft 365 phishing proxy to steal authenticated login sessions. The highly targeted campaign hit fewer than ten specialists. Researchers say it shows how attackers can capture live sessions, though successful compromises and government attribution remain unclear.
- 8Critical Zimbra flaw CVE-2026-73570 actively exploited●🤖 CVE-2026-73570 (CVSS 8.9): unauthenticated OS command injection in Zimbra Collaboration Suite via its SNMP service, no
A critical vulnerability, CVE-2026-73570 with a CVSS score of 8.9, in Zimbra Collaboration Suite allowed unauthenticated attackers to run operating system commands through its SNMP service. According to Microsoft Security Research, attackers exploited the flaw to deploy web shells and steal mailbox credentials. A patch has been released, and security teams are urged to update affected servers promptly.
- 9Microsoft rates Security Copilot prompt injection risk as Low●MSRC assessed an indirect prompt injection into Security Copilot as Low severity because consequential action still requ
Microsoft's Security Response Center assessed an indirect prompt injection into Security Copilot as Low severity, reasoning that consequential action still required downstream automation or human approval. Security researchers are pushing back, arguing that rationale becomes untenable as AI systems are increasingly designed to perceive, reason, and act autonomously, with less human oversight built in.
- 10New Windows NCSI proxy authentication flaw detailed by researchers▼Microsoft Windows NCSI Cross-Context Proxy Authentication Coercion - ZDI-26-708 - Part 1: https:// pgj11.com/posts/Windo
Security researchers have published a two-part technical write-up of a Windows vulnerability tracked as ZDI-26-708, described as a cross-context proxy authentication coercion in the Network Connectivity Status Indicator (NCSI). The disclosure is circulating among security professionals sharing the detailed analysis. Details on affected versions and patches remain unclear from the discussion so far.
- 11Cybersecurity researchers flag suspected Office 365 phishing domain●Possible Phishing 🎣 on: ⚠️hxxp[:]//office365licensingsupport[.]com 🧬 Analysis at: https:// urldna.io/scan/6abd40193b7750
Security researchers are warning about a suspected phishing site at office365licensingsupport.com, a domain name that imitates Microsoft's Office 365 branding to trick users into handing over credentials. A public analysis of the domain has been shared via the URLdna scanning service, and warnings are circulating in infosec communities with the domain deliberately defanged to prevent accidental clicks.
- 12Microsoft details NeedyMantis malware used in targeted attacks●Posted yesterday, if you missed this. Microsoft: NeedyMantis: Unpacking a post-compromise malware family used in targete
Microsoft has published an analysis of NeedyMantis, a malware family deployed after attackers have already breached a network, with use in targeted operations against specific victims. The report breaks down how the malware behaves once inside a compromised environment. Security researchers and practitioners are sharing the findings, warning organisations to review the indicators of compromise Microsoft disclosed.
- 13Microsoft-linked network spotted announcing IP space from Oslo●ASN: AS8075 Location: Oslo, NO Added: 2026-09-25T18:01 # shodansafari # infosec
Autonomous System 8075, the network operated by Microsoft, was observed announcing IP address space located in Oslo, Norway. The observation was logged and shared on 25 September 2026 with the cybersecurity community under the tag #shodansafari. This type of sighting is used by security researchers to track how large cloud and technology providers extend their network presence into new regions and data centre locations.