Microsoft says the maximum-severity Entra ID flaw is fully mitigated and needs no customer action.
XM Cyber chains four SCCM flaws to SYSTEM using a $58 certificate.
Attackers are exploiting a critical SharePoint authentication bypass days after Rapid7 shipped proof-of-concept code.
Microsoft's August update batch closes 398 flaws led by a WinSock driver zero-day already under attack.
Swiss federal IT office BIT resets roughly 200 accounts after a Microsoft SharePoint credential theft.
Malware can borrow Windows Hello for Business keys to open a 90-day persistence channel into Entra ID.
Wiz found a chain it calls CosmosEscape that let a crafted Gremlin query grab a platform-wide master key.
Microsoft unveiled MAI-Cyber-1-Flash, its first specialized cybersecurity AI model, scoring 96% on CyberGym benchmarks and cutting vulnerability discovery costs by…