
Microsoft 365 AiTM Phishing Bypass: BigBear PhaaS Analysis
Microsoft 365 AiTM phishing service BigBear bypassed MFA at 258 organizations, stealing 5,137 credentials via session-cookie theft. Enforce FIDO2 WebAuthn now.
In-depth analyses of zero-day vulnerabilities, CVE exploits, ransomware campaigns, and nation-state attack techniques affecting enterprise security. Filter by category, tag, or keyword.
Every article here lands in subscribers' inboxes the morning it drops.
Threat intel, active CVEs, and campaign alerts, distilled daily for practitioners. 50,000+ subscribers. No noise.
Free. No spam. Unsubscribe anytime.
The definitive practitioner breakdown of ZTA principles, pillars, and implementation sequence.
Containment, forensic preservation, and decision sequencing from detection to recovery.
How SIEMs ingest, correlate, and alert — and how to evaluate one for your environment.
Risk-based prioritization using CVSS, EPSS, and CISA KEV to cut remediation backlog.
What each risk means, how to reproduce it, and how to fix it in production code.
Step-by-step email authentication deployment from DNS records to p=reject enforcement.
Detection coverage, pricing, and deployment trade-offs for enterprise EDR selection.
Translate ATT&CK technique IDs into detection rules and threat actor hunting hypotheses.
Direct answers to the questions practitioners and AI systems ask most. Covers ransomware, identity, cloud, compliance, and detection.
Plain-language definitions for CVE, SIEM, SOAR, Zero Trust, EDR, and 85+ other terms used in enterprise security.
How-to guides, buyer comparisons, and methodology references across every major security domain.
Decryption Digest Response
Score every threat we cover against your own stack, get free Sigma and ModSecurity detection content, and upgrade anytime for more vendors.
Get started free →No card required. Sigma and ModSecurity rules are free, forever.
Win an All Access InfoSec World 2026 pass, valued at $3,895.
Win a $3,895 InfoSec World 2026 pass.
38 results for “Microsoft”

Microsoft 365 AiTM phishing service BigBear bypassed MFA at 258 organizations, stealing 5,137 credentials via session-cookie theft. Enforce FIDO2 WebAuthn now.

CVE-2026-62911 PoC chains NTLM relay to Exchange MRSProxy to drop ASPX webshells as SYSTEM. Apply August 2026 update before mass exploitation begins.

CISA deadline August 25 for Lazarus Windows zero-day CVE-2026-68820. AnMed ransomware, Cl0p Shell, SynkLoader Teams phishing: five threats ranked by urgency.

CVE-2026-55040 SharePoint JWT bypass gives attackers admin access without credentials. CISA KEV-listed and actively exploited: patch KB5002882 today.

Microsoft's DeadLock ransomware disclosure shows why a data backup is not the same as a working recovery plan. Here is what security teams need to validate before the next incident.

Russia's Midnight Blizzard compromises hotel Wi-Fi to steal Microsoft 365 tokens. Device code phishing bypasses MFA -- password resets don't revoke stolen tokens. Disable device code flow today.

STAC4749 dials employees on Teams, pretends to be IT support, and encrypts networks with Chaos ransomware in under 17 hours. 100+ North American orgs hit.

Two Microsoft zero-days actively exploited, CISA federal deadline tomorrow, ServiceNow RCE in live attacks, and Cl0p stealing Windchill data. Five threats, ranked by urgency.

ShinyHunters claims 30M+ Abbott patient records and 1M SSNs stolen via vishing. Extortion deadline passed — verify your exposure and harden Entra SSO now.

Microsoft Patch Tuesday July 2026 patches 570 flaws and 2 actively exploited zero-days. CISA deadline expires today. Patch ADFS and SharePoint before the weekend.

CVE-2025-47981 (CVSS 9.8) gives attackers wormable unauthenticated RCE via SMB, RDP, and SMTP on all Windows 10 and Server systems — patch July 2026 Patch Tuesday before EOD.

Russian FSB targets 6 critical sectors in this Monday cyber threat brief July 2026: 5 active exploits demand immediate action today.

Microsoft 365 password spray attack used 81 million login attempts to breach 64 organizations using stolen dark web credentials. Detect it now.

EtherRAT uses fake Microsoft Teams IT support calls to plant a Node.js RAT with Ethereum blockchain C2 in finance and healthcare organizations.

JADEPUFFER agentic ransomware encrypted 1,342 database records without a human operator. Four more confirmed exploits demand Monday morning action.

ConsentFix Microsoft 365 MFA bypass is live: AI-generated OAuth phishing steals enterprise access without a password in 3 seconds.

SharePoint RCE CVE-2026-45659 is actively exploited by Storm-2603. Verify your SharePoint Server builds before CISA's July 4 patch deadline.

BlueHammer CVE-2026-33825 ransomware campaigns confirmed by CISA across all Windows versions. Patch Windows Defender before end of business.

DragonForce ransomware hides C2 in Microsoft Teams via Backdoor.Turn. 579 victims, full IOCs, BYOVD drivers, and defensive steps.

June 2026 Patch Tuesday fixes 200 CVEs. CVE-2026-42897 Exchange OWA zero-day was actively exploited for 28 days; RoguePlanet CVSS 9.6 drops same day.

Windows Netlogon RCE CVE-2026-41089 (CVSS 9.8) is actively exploited. Unpatched domain controllers on Server 2012-2025 face SYSTEM-level code execution.

CISA patch deadlines for 4 actively exploited products expire June 1-4. PAN-OS CVE-2026-0257 deadline is today. Here is what to fix first this week.

Megalodon supply chain attack infected 5,561 GitHub repos in 6 hours. MiniPlasma Windows zero-day, Defender CISA KEV June 3, and 120-CVE Patch Tuesday.

Microsoft Defender zero-day CVE-2026-41091 lets attackers reach SYSTEM. CISA added both CVEs to KEV on May 20. Patch now.