Latest posts

Research, advisories, detections, and mitigation notes

Medium

VU#529388: Privilege escalation vulnerability via unprotected IOCTL interface in Pegatron Tdelo64.sys

Overview A privilege escalation vulnerability exists in the tdeio64.sys driver due to an unprotected input/output control (IOCTL) dispatch routine that fails to validate the origin and permissions of user-supplied requests. An unprivileged local attacker can abuse exposed IOCTL dispatch routines [RM1.1][MB1.2]to perform arbitrary kernel memory read and write operations, ultimately obtaining NT AUTHORITY\SYSTEM privileges and compromising the security of the affected system. Description The tdeio

CERT/CC Vulnerability Notes 1 min read 2026-07-15
Security News Threat Intelligence CERT/CC Vulnerability
Medium

Turning threat intelligence into decisive action with Defender Experts

Security teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a sprawling mix of third-party tools. The post Turning threat intelligence into decisive action with Defender Experts appeared first on Microsoft Security Blog .

Microsoft Security Blog 1 min read 2026-07-15
Security News Threat Intelligence
High

CISA KEV: Balbooa Forms CVE-2026-56291

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE.

CISA Known Exploited Vulnerabilities 1 min read 2026-07-11
Security News Threat Intelligence CISA KEV Vulnerability CVE-2026-56291
High

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

GigaWiper is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational platform. This blog analyzes how the malware incorporates code from several previously separate malware families and provides guidance to help defenders detect and defend against similar threats. The post GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware appeared first on Microsoft Security Blog .

Microsoft Security Blog 1 min read 2026-07-11
Security News Threat Intelligence malware
High

CISA KEV: JoomShaper SP Page Builder CVE-2026-48908

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

CISA Known Exploited Vulnerabilities 1 min read 2026-07-09
Security News Threat Intelligence CISA KEV Vulnerability CVE-2026-48908
Medium

Protecting Microsoft at AI speed: How SFI proactively hardens our cloud

At Microsoft we encompass these security requirements, along with threat knowledge, and operational frameworks in our Secure Future Initiative (SFI), to guide what a well-defended cloud service looks like. But defining the requirements is only the start. Meeting the requirements means continuously evaluating our live services against them, at AI speed. The post Protecting Microsoft at AI speed: How SFI proactively hardens our cloud appeared first on Microsoft Security Blog .

Microsoft Security Blog 1 min read 2026-07-09
Security News Threat Intelligence
Info

PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems

PolinRider expands across npm, Packagist, Go modules, and Chrome extensions, using hidden loaders to target developer environments.

Socket Blog 1 min read 2026-07-02
Security News Supply Chain Research npm composer
Medium

Unmasking the crawls with Attribution Business Insights

Cloudflare’s new Attribution Business Insights dashboard helps website owners understand crawler behavior, appetite, and potential value, fueling business-level conversations around crawl compensation.

Cloudflare Security Blog 1 min read 2026-07-02
Security News Threat Intelligence Cloudflare
Medium

Microsoft a Leader in The Forrester Wave™ for Endpoint Management Platforms

Microsoft named a Leader in the Forrester Wave™: Endpoint Management Platforms, Q2 2026, with the highest scores in the current offering and strategy categories. The post Microsoft a Leader in The Forrester Wave™ for Endpoint Management Platforms appeared first on Microsoft Security Blog .

Microsoft Security Blog 1 min read 2026-06-25
Security News Threat Intelligence
Medium

The post-quantum EO is an important milestone. Now it’s time to get to work

The new post-quantum executive order sets a 2030 migration deadline and establishes a powerful foundation for post-quantum resilience. We look at what it gets right, where it can go further, and our migration playbook for government and industry.

Cloudflare Security Blog 1 min read 2026-06-25
Security News Threat Intelligence Cloudflare
Medium

StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them

On June 24, 2026, Microsoft’s Digital Crimes Unit (DCU) facilitated the takedown, suspension, and blocking of domains that formed the backbone of the StealC and Amadey infrastructure. This blog is a technical breakdown of StealC and Amadey. The post StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them appeared first on Microsoft Security Blog .

Microsoft Security Blog 1 min read 2026-06-25
Security News Threat Intelligence
Medium

Unlocking the Cloudflare app ecosystem with OAuth for all

Self-Managed OAuth is now available to all developers on Cloudflare. Here's how we executed a zero-downtime migration of our core OAuth engine to make it happen.

Cloudflare Security Blog 1 min read 2026-06-25
Security News Threat Intelligence Cloudflare
Info

New CISA Guide Assists Federal Agencies with Transitioning to Modernized Zero Trust Architectures

CISA News reports a security-relevant update titled "New CISA Guide Assists Federal Agencies with Transitioning to Modernized Zero Trust Architectures". Operators should validate the source details, map any affected assets, and add SecOpsAI-specific detections or mitigations before publication.

CISA News 1 min read 2026-06-25
Security News Threat Intelligence CISA
Medium

CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms

Learn how CNAPP platforms are helping organizations prioritize exploitable risks, reduce exposure, and operationalize security across the application lifecycle. The post CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms appeared first on Microsoft Security Blog .

Microsoft Security Blog 1 min read 2026-06-25
Security News Threat Intelligence
Medium

Critical Chaos-Mesh vulnerabilities Kubernetes cluster takeover

External security-news item queued for analyst review.

JFrog Security Research 1 min read 2026-06-04
Security News Supply Chain Research
High

Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign

A large-scale npm supply chain attack compromised over 90 versions of @redhat-cloud-services packages, silently infecting CI/CD environments and developer systems. The malicious code steals credentials from GitHub, cloud platforms, and local machines, then spreads like a worm by republishing trusted packages. Discover how the attack works, what data is at risk, and the steps you can take to protect your organization. The post Preinstall to persistence: Inside the Red Hat npm Miasma credential-st

Microsoft Security Blog 1 min read 2026-06-04
Security News Threat Intelligence npm github supply-chain attack
High

CISA KEV: Mirasvit Full Page Cache Warmer CVE-2026-45247

Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.

CISA Known Exploited Vulnerabilities 1 min read 2026-06-04
Security News Threat Intelligence CISA KEV Vulnerability CVE-2026-45247
Medium

Microsoft Build 2026: Securing code, agents, and models across the development lifecycle

Discover how Microsoft enables fast, secure AI development with MDASH and new security capabilities. The post Microsoft Build 2026: Securing code, agents, and models across the development lifecycle appeared first on Microsoft Security Blog .

Microsoft Security Blog 1 min read 2026-06-02
Security News Threat Intelligence
High

CISA KEV: Oracle WebLogic Server CVE-2024-21182

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.

CISA Known Exploited Vulnerabilities 1 min read 2026-06-01
Security News Threat Intelligence CISA KEV Vulnerability CVE-2024-21182
Medium

The Gentlemen ransomware: Dissecting a self-propagating Go encryptor

Microsoft Threat Intelligence presents a comprehensive analysis of The Gentlemen, a Go-based ransomware deployed by affiliates of Storm-2697 that combines per-file ephemeral key encryption with an aggressive self-propagation module to deploy itself across an entire network using series of simultaneous lateral movement techniques per target. The post The Gentlemen ransomware: Dissecting a self-propagating Go encryptor appeared first on Microsoft Security Blog .

Microsoft Security Blog 1 min read 2026-06-01
Security News Threat Intelligence
Medium

From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities

Microsoft exposes a cryptojacking campaign using SEO poisoning and ScreenConnect to target high-performance PCs, with malicious sites also surfaced through AI chatbots. The post From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities appeared first on Microsoft Security Blog .

Microsoft Security Blog 1 min read 2026-06-01
Security News Threat Intelligence
High

CISA KEV: Palo Alto Networks PAN-OS CVE-2026-0257

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.

CISA Known Exploited Vulnerabilities 1 min read 2026-05-31
Security News Threat Intelligence CISA KEV Vulnerability CVE-2026-0257
Medium

Google Workspace’s continuous approach to mitigating indirect prompt injections

Google Online Security Blog reports a security-relevant update titled "Google Workspace’s continuous approach to mitigating indirect prompt injections". Operators should validate the source details, map any affected assets, and add SecOpsAI-specific detections or mitigations before publication.

Google Online Security Blog 1 min read 2026-05-31
Security News Threat Intelligence Google
High

CISA Enhances Known Exploited Vulnerabilities Catalog to Include New Nomination Form

CISA News reports a security-relevant update titled "CISA Enhances Known Exploited Vulnerabilities Catalog to Include New Nomination Form". Operators should validate the source details, map any affected assets, and add SecOpsAI-specific detections or mitigations before publication.

CISA News 1 min read 2026-05-22
Security News Threat Intelligence CISA CISA KEV
Medium

Post-quantum encryption for Cloudflare IPsec is generally available

Cloudflare IPsec now has generally available support for post-quantum encryption via hybrid ML-KEM. We’ve confirmed interoperability with Cisco and Fortinet.

Cloudflare Security Blog 1 min read 2026-05-22
Security News Threat Intelligence Cloudflare
Critical

Mini Shai-Hulud crosses npm and PyPI: advisory protection for removed artifacts

Mini Shai-Hulud affected npm and PyPI packages, including removed artifacts that now receive source-backed SecOpsAI advisory detections.

SecOpsAI Threat Research 4 min read 2026-05-12
Supply Chain Advisories Detection Engineering Mitigation