Friday, April 24, 2026
HomeMicrosoft

Microsoft

Microsoft Defender for Office 365 Unveils Enhanced Dashboard with Comprehensive Threat Insights

Microsoft has announced two major initiatives aimed at increasing transparency in email security effectiveness, addressing the growing challenge faced by chief information security officers (CISOs) in making data-driven cybersecurity decisions. The company is launching a new customer-facing dashboard for Microsoft Defender for Office 365...

Microsoft Entra ID Vulnerability Enables Privilege Escalation to Global Administrator

A critical vulnerability in Microsoft's Entra ID (formerly Azure Active Directory) that allows attackers to escalate privileges and impersonate any user with Global Administrator privileges. The privilege escalation technique leverages a fundamental weakness in how Microsoft's first-party applications handle authentication credentials. Attackers who compromise...

Microsoft Honors Top MSRC Security Researchers

Microsoft has announced its annual recognition of the top 100 security researchers through the Microsoft Security Response Center (MSRC) Researcher Recognition Program. The program publicly acknowledges security researchers who contribute to customer protection by discovering and reporting security vulnerabilities through Coordinated Vulnerability Disclosure. The 2025...

Unveiling the Power of Microsoft Security Copilot – Enhancing Security and IT Operations with Intune and Entra

Microsoft has announced that Security Copilot capabilities in Microsoft Intune and Microsoft Entra have transitioned from preview to general availability, marking a significant milestone in AI-powered security operations. This advancement brings artificial intelligence directly into the daily workflows of IT and security professionals, delivering...

Microsoft Issues Warning on Expired Windows Secure Boot Certificate

Microsoft has issued an urgent warning to Windows users about upcoming Secure Boot certificate expirations that could significantly impact device security and functionality. The company released an out-of-band update on July 13, 2025, addressing immediate technical issues while highlighting a critical timeline for certificate...

New Microsoft 365 Vulnerability – LFI Flaw Allows Attackers to Extract Sensitive Server Data via PDF Export

A security researcher has disclosed a significant Local File Inclusion (LFI) vulnerability in Microsoft Graph APIs that allowed attackers to extract sensitive server-side files through the platform's document conversion feature. The flaw, which Microsoft has since patched, earned the researcher a $3,000 bounty through...