New Helix extortion group steals SharePoint data after compromising Microsoft 365 accounts through voice phishing and MFA ...
ACR Stealer is targeting enterprises through ClickFix lures, PowerShell scripts, blockchain services, and malicious image ...
A new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code ...
From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer ...
Microsoft is extending Dataverse into coding-agent marketplaces while expanding its MCP tools, certification program and governance controls.
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication ...
Threat actors are exploiting CVE-2026-58644, a Microsoft SharePoint RCE vulnerability patched on the July 2026 Patch Tuesday.
This recap covers exploited flaws, exposed systems, malware campaigns, weak defaults, and the security gaps demanding ...
Three actively exploited SharePoint vulnerabilities have landed in the KEV catalog, with security experts warning that ...
The Cybersecurity and Infrastructure Security Agency has issued an alert warning of four Microsoft SharePoint vulnerabilities ...
Microsoft has warned that attackers are varying their post-exploitation techniques while relying on the same ClickFix lure, ...
As AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure.