Vendor

Microsoft

Microsoft news

Severity: Informational

tenfold CE: Our free Identity Governance tool just got 2 new features

tenfold has added shared content governance and real-time event auditing to its free Community Edition for organizations with under 150 users. The new features help teams manage Microsoft 365 sharing and investigate suspicious identity activity.

Severity: ElevatedAction: Be aware

Chrome Dev for Desktop Update

The Dev channel has been updated to 157.0.8081.0 for Windows, Mac and Linux. A partial list of changes is available in the Git log . Interested in switching release channels? Find out how . If you find a new issue, please let us know by filing a bug . The community help forum is also a great place to reach out for help or learn about common issues. Chrome Release Team Google Chrome…

Severity: ElevatedAction: Be aware

Extended Stable Update for Desktop

The Extended Stable channel has been updated to 152.0.7977.152 for Windows and Mac which will roll out over the coming days/weeks. A full list of changes in this build is available in the log . Interested in switching release channels? Find out how here . If you find a new issue, please let us know by filing a bug . The community help forum is also a great place to reach out for help or learn about common…

Severity: ElevatedAction: Patch

Chrome for Android Update

Hi, everyone! We've just released Chrome 154 (154.0.8037.126) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Android releases contain the same security fixes as their corresponding Desktop releases (Windows &…

Severity: ElevatedAction: Be aware

Stable Channel Update for Desktop

The Stable channel has been updated to 154.0.8037.97/.98 for Windows and Mac and 154.0.8037.97 to Linux which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log Security changes will be updated shortly Interested in switching release channels? Find out how here . If you find a new issue, please let us know by filing a bug . The community help forum is also a…

Severity: Informational

Microsoft enables Windows settings backup by default for orgs

Microsoft announced that Windows settings backup and restore is now enabled by default on all Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems upgraded to Windows 11 26H2.

Severity: ElevatedAction: Be aware

Early Stable Update for Desktop

The Stable channel has been updated to 155.0.8059.26/.27 for Windows and Mac a s part of our early stable release to a small percentage of users. A full list of changes in this build is available in the log . You can find more details about early Stable releases here . Interested in switching release channels? Find out how here . If you find a new issue, please let us know by filing a bug . The community help…

Severity: ElevatedAction: Be aware

Chrome Beta for Desktop Update

The Chrome team is excited to announce the promotion of Chrome 156 to the Beta channel for Windows, Mac and Linux. Chrome 156.0.8078.4 contains our usual under-the-hood performance and stability tweaks, but there are also some cool new features to explore - please head to the Chromium blog to learn more! A partial list of changes is available in the Git log . Interested in switching release channels? Find out how…

Severity: ElevatedAction: Patch

Chrome for Android Update

Hi, everyone! We've just released Chrome 154 (154.0.8037.92) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log . If you find a new issue, please let us know by filing a bug . Android releases contain the same security fixes as their corresponding Desktop releases (Windows &…

Severity: HighAction: Be aware

Storm-3168: Agentic-driven cloud attacks using compromised service principals

Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders.

Severity: ElevatedAction: Be aware

Chrome Dev for Desktop Update

The Dev channel has been updated to 156.0.8072.0 for Windows, Mac and Linux. A partial list of changes is available in the Git log . Interested in switching release channels? Find out how . If you find a new issue, please let us know by filing a bug . The community help forum is also a great place to reach out for help or learn about common issues. Chrome Release Team Google Chrome…

Severity: HighAction: PatchExploitation: ExploitedCISA KEV

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the…

Why it matters

CISA lists this as exploited in the wild. Unpatched SharePoint and RouterOS systems are exposed to active attacks now.

Patch

Apply the vendor's security update for SharePoint and RouterOS.

Severity: HighAction: PatchExploitation: ExploitedCISA KEV

Microsoft SharePoint Code Injection Vulnerability (CVE-2026-65660) is being actively exploited, CISA warns

CISA added CVE-2026-65660 (Microsoft SharePoint) to its Known Exploited Vulnerabilities catalog on September 25, 2026, which means there is reliable evidence of exploitation in the wild. Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network.

Why it matters

CISA lists this as exploited in the wild. Unpatched SharePoint systems are exposed to active attacks now.

Patch

Apply the vendor's security update for SharePoint.

Severity: Informational

EDR Evasion Stack Helps Process Injection Slip Past Defenses

A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.

Recent intelligence

The latest developments from the last 30 days, newest first.

  1. Coverage

    tenfold CE: Our free Identity Governance tool just got 2 new features

    Basis: Reporting by BleepingComputer

  2. Coverage

    Chrome Dev for Desktop Update

    Basis: Google Chrome Releases (vendor advisory)

  3. Coverage

    Warlock ransomware breach SharePoint in water, telecom operator attacks

    Basis: Reporting by BleepingComputer

  4. Coverage

    Extended Stable Update for Desktop

    Basis: Google Chrome Releases (vendor advisory)

  5. Coverage

    'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries

    Basis: Reporting by The Record by Recorded Future News

  6. Coverage

    Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

    Basis: Reporting by SecurityWeek

  7. Coverage

    Chrome for Android Update

    Basis: Google Chrome Releases (vendor advisory)

  8. Coverage

    Stable Channel Update for Desktop

    Basis: Google Chrome Releases (vendor advisory)

Actively exploited

All 389 →

Microsoft SharePoint

Microsoft SharePoint Code Injection Vulnerability

Added Sep 25, 2026Fed. due Sep 28, 2026Coverage →

Microsoft Windows

Microsoft Windows Link Following Vulnerability

Added Sep 8, 2026Fed. due Sep 22, 2026

Microsoft Windows

Microsoft Windows Heap-Based Buffer Overflow Vulnerability

Added Sep 8, 2026Fed. due Sep 22, 2026

Microsoft SQL Server

Microsoft SQL Server Remote Code Execution Vulnerability

Added Aug 26, 2026Fed. due Aug 29, 2026

Microsoft Internet Key Exchange (IKE) Service Extensions

Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

Added Aug 18, 2026Fed. due Aug 21, 2026

Microsoft SharePoint

Microsoft SharePoint Weak Authentication Vulnerability

Added Aug 18, 2026Fed. due Aug 21, 2026

Microsoft Windows Ancillary Function Driver for WinSock

Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Added Aug 11, 2026Fed. due Aug 25, 2026

Microsoft SharePoint

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Added Jul 22, 2026Fed. due Jul 25, 2026

Microsoft SharePoint

Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Added Jul 16, 2026Fed. due Jul 19, 2026

Microsoft SharePoint Server

Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

Added Jul 14, 2026Fed. due Jul 17, 2026

Microsoft Active Directory Federation Services

Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Added Jul 14, 2026Fed. due Jul 28, 2026
CVE-2026-45659RansomwareCVSS 8.8

Microsoft SharePoint Server

Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

Added Jul 1, 2026Fed. due Jul 4, 2026

Microsoft Windows

Microsoft Windows Buffer Overflow Vulnerability

Added May 20, 2026Fed. due Jun 3, 2026

Microsoft DirectX

Microsoft DirectX NULL Byte Overwrite Vulnerability

Added May 20, 2026Fed. due Jun 3, 2026

Microsoft Internet Explorer

Microsoft Internet Explorer Use-After-Free Vulnerability

Added May 20, 2026Fed. due Jun 3, 2026

Microsoft Internet Explorer

Microsoft Internet Explorer Use-After-Free Vulnerability

Added May 20, 2026Fed. due Jun 3, 2026

Microsoft Defender

Microsoft Defender Link Following Vulnerability

Added May 20, 2026Fed. due Jun 3, 2026

Microsoft Defender

Microsoft Defender Denial of Service Vulnerability

Added May 20, 2026Fed. due Jun 3, 2026

Microsoft Microsoft

Microsoft Exchange Server Cross-Site Scripting Vulnerability

Added May 15, 2026Fed. due May 29, 2026

Microsoft Windows

Microsoft Windows Protection Mechanism Failure Vulnerability

Added Apr 28, 2026Fed. due May 12, 2026

Products

Windows · 172 KEVInternet Explorer · 36 KEVOffice · 29 KEVWin32k · 25 KEVExchange Server · 17 KEVSharePoint · 10 KEVDefender · 5 KEVSharePoint Server · 5 KEVOpen Management Infrastructure (OMI) · 4 KEVWord · 4 KEVActive Directory · 3 KEVExcel · 3 KEV.NET Framework · 3 KEVSilverlight · 3 KEVDirectX Graphics Kernel (DXGKRNL) · 2 KEVEdge and Internet Explorer · 2 KEVEnhanced Cryptographic Provider · 2 KEVGraphics Device Interface (GDI) · 2 KEVMicrosoft Edge · 2 KEVMSHTML · 2 KEVPowerPoint · 2 KEVSMBv1 · 2 KEVSMBv1 server · 2 KEVSQL Server · 2 KEVWindows · 2 KEVXML Core Services · 2 KEVActive Directory Federation Services · 1 KEVAncillary Function Driver (afd.sys) · 1 KEVATM Font Driver · 1 KEVClient-Server Run-time Subsystem (CSRSS) · 1 KEVConfiguration Manager · 1 KEVDirectX · 1 KEVDWM Core Library · 1 KEVExchange · 1 KEVForefront Threat Management Gateway (TMG) · 1 KEVGraphics Component · 1 KEVHTTP Protocol Stack · 1 KEVHTTP.sys · 1 KEVHyper-V RemoteFX · 1 KEVInput Method Editor (IME) Japanese · 1 KEVInternet Explorer and Edge · 1 KEVInternet Explorer Scripting Engine · 1 KEVInternet Information Services (IIS) · 1 KEVInternet Key Exchange (IKE) Service Extensions · 1 KEVKerberos Key Distribution Center (KDC) · 1 KEVMalware Protection Engine · 1 KEVMicrosoft · 1 KEVMicrosoft 365 · 1 KEVMSCOMCTL.OCX · 1 KEV.NET Core and Visual Studio · 1 KEV.NET Framework, SharePoint, Visual Studio · 1 KEVNetlogon · 1 KEVOffice and WordPad · 1 KEVOffice Outlook · 1 KEVPartner Center · 1 KEVPower Pages · 1 KEVProject · 1 KEVPublisher · 1 KEVRemote Desktop Services · 1 KEVSkype for Business · 1 KEV