Skip to content
Threat Note Threat Note

Aggregating Cyber Insights

  • Articles
  • Breaches
  • Learning
  • News
  • Podcast
  • Research
  • Toolkit
  • Vulnerabilities
  • Webinars
  • About Us

Microsoft threat intelligence

  • Home
  • Microsoft threat intelligence
From Cybersecurity Help – Microsoft’s April 2025 Patch Tuesday tackles over 130 bugs, including actively exploited zero-day
Posted inVulnerabilities

From Cybersecurity Help – Microsoft’s April 2025 Patch Tuesday tackles over 130 bugs, including actively exploited zero-day

Microsoft said the zero-day flaw has been exploited in the Storm-2460 ransomware attacks to deploy the PipeMagic malware.  ​ Read More  ​ 
Posted by Samir K April 9, 2025
From Security Week – Microsoft Using AI to Uncover Critical Bootloader Vulnerabilities
Posted inNews

From Security Week – Microsoft Using AI to Uncover Critical Bootloader Vulnerabilities

[[{"value":"Using the Security Copilot tool, Microsoft discovered 20 critical vulnerabilities in widely deployed open-source bootloaders. The post Microsoft Using AI to Uncover Critical Bootloader Vulnerabilities appeared first on SecurityWeek."}]] Read More  
Posted by shaikh Saqib April 2, 2025
From Cyber Security News – Microsoft Warns of Cyber Attack Mimic Booking .com To Deliver Password Stealing Malware
Posted inNews

From Cyber Security News – Microsoft Warns of Cyber Attack Mimic Booking .com To Deliver Password Stealing Malware

 Microsoft Threat Intelligence has identified an ongoing phishing campaign impersonating Booking.com to deliver credential-stealing malware. The campaign, which began in December 2024, targets hospitality organizations in North America, Oceania, Asia,…
Posted by shaikh Saqib March 14, 2025
From Security Week – Microsoft Warns of Hospitality Sector Attacks Involving ClickFix
Posted inNews

From Security Week – Microsoft Warns of Hospitality Sector Attacks Involving ClickFix

[[{"value":"A cybercrime group named Storm-1865 has targeted hospitality organizations via fake Booking.com emails and the use of social engineering. The post Microsoft Warns of Hospitality Sector Attacks Involving ClickFix appeared…
Posted by shaikh Saqib March 13, 2025
From Dark Reading – GitHub-Hosted Malware Infects 1M Windows Users
Posted inNews

From Dark Reading – GitHub-Hosted Malware Infects 1M Windows Users

Microsoft has identified a complex, malvertising-based attack chain that delivered Lumma and other infostealers to enterprise and consumer PC users; the campaign is unlikely the last of its kind. Read More  
Posted by shaikh Saqib March 10, 2025
From Cyber Security News – 1 Million Devices Infected by Malwares Hosted on GitHub, Microsoft Warns
Posted inNews

From Cyber Security News – 1 Million Devices Infected by Malwares Hosted on GitHub, Microsoft Warns

 Microsoft Threat Intelligence detected a large-scale malvertising campaign in early December 2024 that infected nearly one million devices globally in an opportunistic attack designed to steal information. The campaign impacted…
Posted by shaikh Saqib March 10, 2025
From Security Week – Exploited VMware ESXi Flaws Put Many at Risk of Ransomware, Other Attacks
Posted inNews

From Security Week – Exploited VMware ESXi Flaws Put Many at Risk of Ransomware, Other Attacks

[[{"value":"Scans show that tens of thousands of VMware ESXi instances are affected by CVE-2025-22224 and other vulnerabilities disclosed recently as zero-days. The post Exploited VMware ESXi Flaws Put Many at…
Posted by shaikh Saqib March 6, 2025
From Cyber Security News – 12 Chinese Hackers Charged For Cyber Attacks on U.S Treasury
Posted inNews

From Cyber Security News – 12 Chinese Hackers Charged For Cyber Attacks on U.S Treasury

 The U.S. Department of Justice (DOJ) unsealed indictments today against 12 Chinese nationals linked to state-sponsored cyber espionage campaigns targeting the U.S. Treasury Department, religious organizations, media outlets, and critical…
Posted by shaikh Saqib March 6, 2025
From Cyber Security News – 41,500+ VMware ESXi Instances Vulnerable to Code Execution Attacks
Posted inNews

From Cyber Security News – 41,500+ VMware ESXi Instances Vulnerable to Code Execution Attacks

 Shadowserver observed that 41,500+ internet-exposed VMware ESXi hypervisors as of March 4, 2025, are vulnerable to CVE-2025-22224, a critical zero-day vulnerability actively exploited in attacks. Broadcom patched the vulnerability in…
Posted by shaikh Saqib March 6, 2025
From Cybersecurity Help – New XCSSET malware variant discovered targeting macOS users
Posted inVulnerabilities

From Cybersecurity Help – New XCSSET malware variant discovered targeting macOS users

The XCSSET variant comes with several enhanced features that make it harder to detect and mitigate.  ​ Read More  ​ 
Posted by shaikh Saqib February 19, 2025
From Cyber Security News – Hackers Abusing Microsoft Teams Meeting Invites to Trick Victims for Gaining Access
Posted inNews

From Cyber Security News – Hackers Abusing Microsoft Teams Meeting Invites to Trick Victims for Gaining Access

 In a sophisticated cyberattack campaign, a threat actor identified as Storm-2372 has been leveraging Microsoft Teams meeting invites to execute “device code phishing” attacks.  This campaign, observed since August 2024,…
Posted by shaikh Saqib February 17, 2025
From Cyber Security News – New Device Code Phishing Attack Exploit Device Code Authentication To Capture Authentication Tokens
Posted inNews

From Cyber Security News – New Device Code Phishing Attack Exploit Device Code Authentication To Capture Authentication Tokens

 A sophisticated phishing campaign, identified by Microsoft Threat Intelligence, has been exploiting a technique known as “device code phishing” to capture authentication tokens. This attack, attributed to a group called…
Posted by shaikh Saqib February 14, 2025
From Dark Reading – Microsoft: Russia’s Sandworm APT Exploits Edge Bugs Globally
Posted inNews

From Dark Reading – Microsoft: Russia’s Sandworm APT Exploits Edge Bugs Globally

Sandworm (aka Seashell Blizzard) has an initial access wing called "BadPilot" that uses standard intrusion tactics to spread Russia's tendrils around the world. Read More  
Posted by shaikh Saqib February 12, 2025
From Cybersecurity Help – Sandworm APT targets Ukraine with trojanized Microsoft KMS activation tools
Posted inVulnerabilities

From Cybersecurity Help – Sandworm APT targets Ukraine with trojanized Microsoft KMS activation tools

The attackers utilized a BACKORDER loader to deploy DarkCrystal RAT.  ​ Read More  ​ 
Posted by shaikh Saqib February 12, 2025
From Cybersecurity Help – North Korean Kimsuky adopted a new tactic to infiltrate targets
Posted inVulnerabilities

From Cybersecurity Help – North Korean Kimsuky adopted a new tactic to infiltrate targets

The new tactic involves the threat actor tricking individuals into executing PowerShell commands as administrators.  ​ Read More  ​ 
Posted by shaikh Saqib February 12, 2025

Posts pagination

1 2 Next page

Latest Posts

  • From Dark Reading – Has CISA Finally Found Its New Leader in Tom Parker?May 7, 2026
  • From Cyber Security News – New Ivanti EPMM 0-Day Vulnerability Actively Exploited in AttacksMay 7, 2026
  • From Cyber Security News – CISA Warns of Palo Alto PAN-OS Vulnerability Exploited to Gain Root AccessMay 7, 2026
  • From Cyber Security News – New Cisco Network Vulnerability Let Remote Attacker Cause DoS AttackMay 7, 2026
  • From Security Week – Palo Alto Zero-Day Exploited in Campaign Bearing Hallmarks of Chinese State HackingMay 7, 2026
Total Visitors
1495306

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • February 2023
  • December 2022
  • November 2022
  • May 2022
Copyright 2026 — Threat Note. All rights reserved. Bloghash WordPress Theme
Scroll to Top