Microsoft claims that its new passwordless methods reduce password use by over 20% and result in users signing in faster. The company added passkeys as an option for personal accounts along with a password manager for Windows Hello early last year.
A new phishing attack started to surface where hackers leverage on Microsoft OAuth apps to steal user credentials from SharePoint and OneDrive users using official Office 365 login page.
Microsoft Power Apps appears to list all data types as public unless the default settings are changed. The data leak exposed several coronavirus tracing and vaccination portals, as well as at least one job applicant database that contained social security numbers.
Microsoft has traced the signing key theft back to a "crash dump" error. A breach of a Microsoft engineer's work account by the Chinese hackers then yielded access to the crash dump and the embedded signing key.
Microsoft has released security patches for the zero-day vulnerability chain dubbed ToolShell, capable of remote code execution on SharePoint, resulting in the exploitation of at least 54 organizations worldwide.
Microsoft researchers say that Russian cyber attacks in March against a television broadcaster and a nuclear plant directly preceded military action directed at those targets.
Microsoft reported that the Russian hackers behind the devastating SolarWinds attack are employing similar tactics to worm their way into tech supply chains, looking to establish long-term footholds for espionage purposes.
The destructive malware that is currently being spread in Ukraine acts like ransomware in that it locks up target systems by encrypting key files, but there is no payment option.
Microsoft reports a long-term campaign by Chinese hackers that has burrowed into a number of different aspects of US critical infrastructure, with the eventual goal being the creation of a system of widespread disruption that could be 'switched on' during another global crisis or a conflict between the two nations.
Microsoft is now the first major tech company that says it plans to abide by the new CCPA not just in California, but also to honor California’s digital privacy law in every state where it operates in the United States.










