Microsoft patches critical Entra ID flaw exploited in active attacks
Microsoft released a patch for a critical vulnerability in Entra ID that is actively exploited in targeted attacks, affecting identity and access management security.
Tag
4 results in the archive.
Microsoft released a patch for a critical vulnerability in Entra ID that is actively exploited in targeted attacks, affecting identity and access management security.
A crafted SVG submitted to Bing image search can execute commands as NT AUTHORITY\SYSTEM on Microsoft’s production servers, impacting multiple hosts with critical security implications.
Microsoft patched a critical SharePoint Server vulnerability, CVE-2026-50522, now actively exploited after a public proof-of-concept was released, enabling remote code execution via deserialization of untrusted data.
Microsoft Threat Intelligence uncovered ShinyHunters abusing OAuth in SaaS applications through vishing, supply chain attacks, and guest access misconfigurations, exposing new SaaS security risks.