Vulnerabilities
Max-Severity Microsoft Exchange CVE-2026-42897 Actively Exploited by Laundry Bear
Email open, half-click, mailbox held after password reset — Exchange on the wire this week.
Security intelligence, vulnerability research, and configuration guidance focused on the Microsoft 365 productivity suite, specifically regarding Entra ID (formerly Azure AD), Exchange Online, and tenant-wide security governance.
Vulnerabilities
Email open, half-click, mailbox held after password reset — Exchange on the wire this week.
Cloud & Identity
One key, any database — the Cosmos DB exposure lands this week.
Artificial Intelligence (AI)
Hidden prompts tucked inside a Word document can be copied into the new files Microsoft Copilot for Word generates — a propagation The Register nicknames a "Word worm." A defender-focused look at the mechanism, the disclosure, and what stays unconfirmed.
Artificial Intelligence (AI)
More AI, more acronyms — Microsoft's cybersecurity AI debut lands this week, and it arrives wrapped in a vendor benchmark claim that tops Anthropic and OpenAI.
Vulnerabilities
From advisory to public proof-of-concept — the critical AD CS "Certighost" domain-takeover flaw (CVE-2026-54121) goes public this week, with the fix already shipped in Microsoft's July 2026 update.
Vulnerabilities
An Active Directory privilege-escalation research disclosure — defender review across AD environments this week, with Microsoft's July 2026 update the confirmed fix.
Vulnerabilities
Researchers at XBOW disclosed two Bing Images flaws that let crafted SVG files run commands as SYSTEM on Microsoft's own servers. Microsoft fixed both server-side before the details went public — this is primarily a vendor-fix story, with limited consumer action.
Vulnerabilities
SharePoint's fourth actively-exploited flaw in a month lands with a machine-key-theft twist — defender teams patch AND rotate this week.
Policy & Government
A major PhaaS takedown lands with an international arrest — Microsoft 365 defender teams review sector-advisory posture this week.
Threat Intelligence
A novel Microsoft 365 calendar-abuse malware framework — defender detection-engineering review this week.
Vulnerabilities
Rapid7 goes deep on the SharePoint CVSS-9.8 RCE — defender-team detection-engineering review this weekend.
Threat Intelligence
Another named stealer joins the ClickFix pattern — a defender posture review across Microsoft 365 environments after Microsoft's published analysis this week.