Microsoft Threat Intelligence
msft-ti · B · active
https://www.microsoft.com/en-us/security/blog/topic/threat-intelligence/
Microsoft Threat Intelligence Center reporting. 2026-05-08 audit: WebFetch returned 5 dated TI articles latest 2026-05-04 on AiTM phishing, Sapphire Sleet, Forest Blizzard. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch (listing) https://www.microsoft.com/en-us/security/blog/topic/threat-intelligence/ then webfetch per-article (URLs are /security/blog/YYYY/MM/DD/{slug}/).. AVOID: Nothing; WebFetch works cleanly on both listing and article. No bridge needed.. | 2026-07-05 admiralty audit: B, MSTIC original threat research from Microsoft telemetry. Reliability HIGH->B, status stays active. Distinct source from msrc-blog (PSIRT).
Cited in 66 entries
Citation cadence
Citation days per ISO week (19 weeks of coverage span, total 42).
- September 2026 Patch Tuesday: two actively exploited Windows privilege-escalation zero-days (CVE-2026-81963 Update Stack, CVE-2026-85880 ALPC)2026-09-09
- ASCII smuggling crosses over from AI prompt-injection research into mainstream phishing-filter evasion2026-09-04
- A Teams helpdesk-impersonation campaign installs a Node.js implant (Microsoft detection name: EtherRatz) via a silent MSI, then pivots over WinRM straight to domain controllers and certificate authorities2026-09-03
- TerminalFix: a ClickFix variant that pastes into Terminal or PowerShell instead of Windows' Run dialog, then chains DLL sideloading, steganographic payload delivery and a custom reverse-tunnel implant2026-08-31
- AI infrastructure as the new control plane: Microsoft confirms three separate intrusions against a LiteLLM gateway, a RAGFlow deployment and a Kestra orchestration environment, converging on credential theft and persistence, with compute monetisation in two of the three2026-08-31
- CVE-2026-62911, Microsoft Exchange Server MRSProxy: a missing channel-binding check lets a relayed Negotiate authentication take over every mailbox, public exploit code now live sixteen days after the patch2026-08-29
- A hijacked crates.io account added the first dependency arrayref has taken in ten years, and that dependency ran a backdoor at compile time; every machine that built an affected project during a ninety-minute window must be treated as compromised2026-08-23
- CVE-2026-69836, Microsoft corrected its own Entra ID CVSS 10.0 record from exploited to not-exploited within a day, and ENISA's exploited feed still says otherwise two days later2026-08-23
- ShieldBreak, a public proof-of-concept defeats Microsoft's July fix for the RoguePlanet Defender flaw, claims 100% reliability where the original was a coin flip, and now covers Windows Server 20252026-08-12
- Lazarus burned a Windows AFD.sys zero-day (CVE-2026-68820) on European defence targets, FudModule v3.1 blinds the endpoint, and the C2 is other people's Roundcube and WordPress servers2026-08-12
- NatJack, sharing a NAT table is a trust relationship nobody declared: five named primitives against NAT state, of which only the downstream TCP hijack got a CVE on each platform2026-08-10
- The macOS ClickFix chain now qualifies visitors server-side before showing the lure, with anti-analysis probes that detect a console rather than a sandbox2026-08-07
- CVE-2026-18556 / CVE-2026-18577, N-able N-central: unauthenticated admin access to the RMM console, exploited in the wild, and the day-one fix was itself bypassable2026-08-03
- CaptiveCrunch: an SVR-linked sub-cluster hijacks hotel and conference captive portals to serve fake update lures, a Go RAT and a token-stealing PowerShell module to travelling staff2026-08-01
- Unit 42 recovers a live autonomous-AI attack operation after it exposed its own home directory, the confirmed compromises came from manual Citrix NetScaler exploitation (CVE-2026-3055), not the agent2026-07-31
- LegacyHive: a public Windows technique that redirects a profile's Local AppData into the NT Object Manager namespace via offline hive edits, reproduced on fully patched systems2026-07-29
- Microsoft Email Threat Landscape Q2 2026: phishing moves off email into Teams vishing, and attachment lures drift PDF → DOCX2026-07-25
- CVE-2026-54121, Windows Server AD CS 'Certighost': low-priv domain user forges a DC certificate to DCSync, full PoC public (CVSS 8.8)2026-07-25
- Microsoft: two parallel ACR Stealer intrusion chains (WebDAV/rundll32/Python with blockchain dead-drop C2, and a fileless MSHTA/steganography chain) both rooted in ClickFix2026-07-17
- Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers, none exploiting a Salesforce vulnerability2026-07-14
- Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days, AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)2026-07-14
- AsyncAPI npm packages backdoored via a GitHub Actions pull_request_target token theft, delivering a multi-stage IPFS implant (M-RED-TEAM)2026-07-14
- GigaWiper: a Golang backdoor that folds a disk wiper, fake-ransomware encryptor and secure-wipe module into one modular implant2026-07-11
- CVE-2026-50656, Microsoft Defender engine 'RoguePlanet' local privilege escalation now patched; NCSC-CH tracks the ongoing 'Nightmare Eclipse' zero-day series2026-07-09
- CVE-2026-45659, Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed2026-07-02
- A malicious "Perplexity AI" Chrome extension intercepted every address-bar keystroke via a search-suggest override2026-06-30
- Microsoft: "Photo ZIP" phishing laundered through Calendly drops Node.js TonRAT against European hospitality front desks2026-06-27
- Operation Endgame dismantles the Amadey and StealC malware-as-a-service backbone2026-06-25
- AutoJack; Microsoft shows a single web page can drive host RCE through an AI agent's local MCP server2026-06-20
- Nightmare/Chaotic Eclipse zero-day wave; the Defender LPE now carries a CVE, a public PoC, and Microsoft's "Exploitation More Likely" rating, with no patch2026-06-19
- Microsoft details a USB-LNK worm with Tor hidden-service C2 driving a cryptocurrency clipboard hijacker2026-06-19
- Mastra npm supply-chain compromise (easy-day-js)2026-06-18
- Varonis "SearchLeak" (CVE-2026-42824): one-click M365 Copilot data exfiltration, now patched2026-06-16
- The Gentlemen ransomware: 478 claimed leak-site victims, self-propagating Go encryptor, operator publicly named2026-06-12
- June 2026 Patch Tuesday: four CVSS ≥ 9.1 criticals, Windows kernel TCP/IP RCE, Nuance PowerScribe, Azure Stack Edge, Exchange Online2026-06-12
- CVE-2026-25089, Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)2026-06-12
- CVE-2026-47344 et al. TYPO3 core June release: 13 CVEs across every supported branch (10.4 ELTS → 14.3 LTS)2026-06-10
- CVE-2026-47291, Microsoft June Patch Tuesday: HTTP.sys pre-auth RCE (CVSS 9.8) headlines the largest-ever release (198 CVEs)2026-06-10
- Microsoft Threat Intelligence: AI-brand impersonation drives Lumma Stealer and Vidar delivery via signed binaries2026-06-09
- Two concurrent npm dependency-confusion campaigns target internal corporate namespaces2026-06-01
- Nightmare Eclipse / Chaotic Eclipse, Microsoft's Digital Crimes Unit threatens criminal action; GreenPlasma and MiniPlasma (cldflt.sys SYSTEM escalation) remain unpatched; researcher announces July 14 drop2026-05-30
- The Gentlemen ransomware, Microsoft publishes full technical dissection of the Storm-2697 Go-encryptor2026-05-29
- FortiClient EMS CVE-2026-35616 + EKZ Infostealer kill chain2026-05-29
- Microsoft Defender Experts, AI-chatbot search-poisoning extends SEO-poisoning lure; GPU-utility lookalikes drop ScreenConnect, then process-hollowed miners under signed Microsoft binary2026-05-28
- Keycloak 26.6.2, 16 CVEs including OIDC session fixation (CVE-2026-7507), WebAuthn execute-actions token replay (CVE-2026-37982), introspection audience bypass (CVE-2026-37979) and cross-realm IDOR in Authorization Services (CVE-2026-4630)2026-05-21
- CVE-2026-42822, Microsoft Azure Local Disconnected Operations (ALDO): CVSS 10.0 unauthenticated network elevation-of-privilege, "Exploitation More Likely"2026-05-21
- vm2 Node.js sandbox, 12 critical CVEs (CVE-2026-43997 / 43999 / 44005 / 44006 / 44008 / 44009 et al.), sandbox escape to host RCE, upgrade to ≥ 3.11.42026-05-20
- Storm-2949 SSPR-to-Key-Vault Azure kill chain2026-05-20
- Microsoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operations2026-05-20
- CVE-2026-45584, Microsoft Defender Engine heap-buffer-overflow RCE over network2026-05-20
- CVE-2026-41091, Microsoft Defender Engine link-following EoP, actively exploited2026-05-20
- Tycoon2FA after the March 2026 takedown, OAuth Device Authorization Grant abuse on Microsoft 3652026-05-18
- CVE-2026-42897 Exchange OWA, EM Service auto-mitigation depends on outbound connectivity to officemitigations.microsoft.com2026-05-18
- Exchange CVE-2026-42897, Pwn2Own DEVCORE three-bug SYSTEM RCE chain emerges alongside active OWA-XSS exploitation2026-05-17
- Microsoft Exchange CVE-2026-42897: Active Exploitation Without a Patch2026-05-16
- CVE-2026-42897, Microsoft Exchange Server 2016 / 2019 / SE: stored XSS in OWA, actively exploited, no permanent patch2026-05-16
- AMD-SB-7052 / CVE-2025-54518, AMD Zen 2 µop-cache corruption / SoC isolation failure: local privilege escalation (CVSS 7.3), microcode mitigation in May 2026 Windows update and Xen XSA-4902026-05-16
- Windows BitLocker "YellowKey" and CTFMON "GreenPlasma" zero-days: public PoC, no patch, TPM-only BitLocker bypassed2026-05-15
- CVE-2026-46300, Linux kernel: local privilege escalation via xfrm ESP-in-TCP ("Fragnesia"), PoC public2026-05-15
- Microsoft MDASH, multi-model agentic vulnerability-discovery harness finds 16 Windows CVEs in network-stack kernel components2026-05-13
- + 6 earlier entries