Friday, April 24, 2026
HomeMicrosoft

Microsoft

New 0-Click NTLM Credential Leak Vulnerability Evades Microsoft’s CVE-2025-24054 Patch

A critical zero-click vulnerability that circumvents Microsoft's security patch for CVE-2025-24054, enabling attackers to extract NTLM credentials without any user interaction. The new vulnerability, assigned CVE-2025-50154, demonstrates that Microsoft's April security update was incomplete, leaving Windows systems vulnerable to credential theft and malicious...

Microsoft Teams RCE Vulnerability Lets Hackers Steal, Alter, and Erase Messages

Microsoft has disclosed a significant remote code execution vulnerability in Teams that could enable attackers to compromise enterprise communications and access sensitive data. The vulnerability, designated CVE-2025-53783, represents a serious security threat to organizations worldwide using the popular collaboration platform. The vulnerability stems from a...

CISA Issues Urgent Warning on Critical Microsoft Exchange Security Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive 25-02 on August 7, 2025, ordering federal agencies to immediately address a critical vulnerability in Microsoft Exchange hybrid deployments. The directive, responding to CVE-2025-53786, gives all Federal Civilian Executive Branch agencies until 9:00 AM...

New Microsoft Exchange Vulnerability Grants Attackers Admin Access

Microsoft and CISA have issued urgent security alerts regarding a newly discovered high-severity vulnerability in Exchange Server hybrid deployments that could enable attackers to escalate privileges and potentially compromise both on-premises and cloud infrastructure. The vulnerability, tracked as CVE-2025-53786, affects organizations running hybrid configurations...

Cyberattack Targets African Treasury, Corporations, and University via Microsoft SharePoint Zero-Day Vulnerability

A sophisticated global cyberattack exploiting critical vulnerabilities in Microsoft SharePoint servers has compromised approximately 400 entities worldwide, with significant impact across South African government agencies, corporations, and educational institutions. The breach, initially detected by Dutch cybersecurity firm Eye Security, represents one of the most...

Microsoft Teams Introduces 60-Second Silent Test Call Feature for IT Admins

Microsoft is set to introduce a revolutionary new feature that will allow IT administrators to proactively monitor network performance through silent test calls in Microsoft Teams. The feature, scheduled to roll out in September 2025, represents a significant advancement in network monitoring capabilities for...