Friday, April 24, 2026
HomeMicrosoft

Microsoft

Microsoft Unveils Strategies to Combat Indirect Prompt Injection Attacks

Microsoft has unveiled a comprehensive defense-in-depth strategy to combat indirect prompt injection attacks, a growing cybersecurity threat targeting large language model (LLM) systems used in enterprise environments. The tech giant's multi-layered approach combines preventative techniques, real-time detection tools, and impact mitigation strategies to protect...

Brave Browser Blocks Microsoft Recall Feature by Default Over Privacy Issues

Brave browser has introduced a groundbreaking privacy feature in version 1.81 for Windows users, automatically blocking Microsoft's controversial Recall screenshot functionality from capturing browsing activity. This proactive measure represents the first major browser response to Microsoft's AI-powered feature that takes periodic screenshots of user...

Microsoft SharePoint Code Injection and Authentication Vulnerabilities Actively Exploited, CISA Issues Warning

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Microsoft SharePoint vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning organizations that the security vulnerability is being actively exploited by threat actors in the wild. The vulnerability, tracked as CVE-2025-49706, represents a...

Microsoft AppLocker Vulnerability Allows Malicious Apps to Bypass Restrictions

A configuration vulnerability in Microsoft's AppLocker security feature that could potentially allow certain applications to bypass system restrictions. The discovery centers around a seemingly minor numerical discrepancy in Microsoft's official documentation that creates an exploitable gap in the application control system, though the researchers...

Microsoft SharePoint Server 0-Day RCE Actively Exploited, CISA Issues Urgent Warning

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a critical zero-day vulnerability in Microsoft SharePoint Server that is being actively exploited by attackers in the wild. The vulnerability, tracked as CVE-2025-53770, allows unauthorized remote code execution through deserialization of...

Exploiting Microsoft Teams – A New Method for Deploying Matanbuchus Ransomware

Cybersecurity researchers have identified a sophisticated new attack campaign in which threat actors are exploiting Microsoft Teams to deploy the Matanbuchus 3.0 ransomware loader, representing a significant evolution in social engineering tactics. In a recent incident in July 2025, attackers successfully compromised a Morphisec...