Microsoft says its Azure cloud platform was hit by the largest of its kind DDoS attack from a Turbo Mirai-class IoT botnet, Aisuru, harnessing over 500,000 residential IPs.
Microsoft has banned the developer accounts of high-profile open-source projects, leaving them unable to publish software updates, exposing Windows users to various cyber threats.
Cybercriminals inserted malicious ads into Microsoft Bing Search AI chatbot to trick unsuspecting users into downloading trojanized software from spoofed domains.
Security firm disclosed a Microsoft data breach that exposed customer data affecting over 65,000 organizations in 111 countries. Microsoft expressed disappointment at the security firm for exaggerated numbers and releasing a search tool.
Microsoft’s recent deletion of its facial recognition database containing more than 10 million images of nearly 100,000 people could be their way to show need to regulate facial recognition technology.
Nation-state attacks on critical infrastructure and cyberespionage, and password attacks from ordinary cybercriminals increased tremendously within a year, according to Microsoft report.
Microsoft says many IoT and operational technology devices suffer from 25 IoT security critical vulnerabilities originating from vulnerable SDKs, RTOS, and the C standard library.
Microsoft 365 Defender researcher team discovered a privilege escalation vulnerability dubbed Nimbuspwn allowing an attacker to gain root privileges and deploy malicious payloads.
The back-and-forth over public disclosure policy does have substantial "gray area" and nuance. As Microsoft points out, the zero-day vulnerabilities that Chaotic Eclipse provided a "road map" to threat actors and some were almost immediately put to use in real-world attacks. On the other side of the coin, security researchers have long complained of unresponsive and heavy-handed communications from Microsoft.
Guardicore discovered that the Microsoft Exchange server’s Autodiscover feature design flaw leaked credentials of 100,000 users by trying to authenticate on untrusted third-party servers.










