New Helix extortion group steals SharePoint data after compromising Microsoft 365 accounts through voice phishing and MFA ...
A new data-extortion group called Helix is using identity-focused tactics such as voice phishing (vishing), device code ...
ACR Stealer is targeting enterprises through ClickFix lures, PowerShell scripts, blockchain services, and malicious image ...
ACR Stealer campaigns use ClickFix lures, JPEG steganography, and WebDAV to steal browser tokens, passwords, PDFs, and synced ...
From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer ...
Microsoft is extending Dataverse into coding-agent marketplaces while expanding its MCP tools, certification program and governance controls.
An exposed attack server led Lexfo to three Microsoft 365 phishing operations using Evilginx and device code abuse to capture ...
Microsoft has published a warning enterprise customers after its Defender Experts observed increased ACR Stealer activity across customer environments from April through June 2026. ACR Stealer ...
Threat actors are exploiting CVE-2026-58644, a Microsoft SharePoint RCE vulnerability patched on the July 2026 Patch Tuesday.
Three actively exploited SharePoint vulnerabilities have landed in the KEV catalog, with security experts warning that ...
The Cybersecurity and Infrastructure Security Agency has issued an alert warning of four Microsoft SharePoint vulnerabilities ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results