company · 79 records
Microsoft

Microsoft Takes Down EvilTokens Device-Code Phishing Service
Microsoft and international partners took down the EvilTokens phishing-as-a-service platform that leveraged AI to facilitate large-scale business email compromise.

Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
A researcher has released a proof-of-concept tool named BigDiskBuster that prevents Microsoft Defender from updating by exhausting system disk space.
Xbox Initiates Studio Reorganization To Consolidate Operations
Microsoft is reorganizing its Xbox gaming division to consolidate teams and reduce the number of business units.

SharePoint Vulnerability Allows Authenticated Remote Code Execution
Researcher Dinh Ho Anh Khoa identified that a SharePoint Server vulnerability previously misclassified by Microsoft as a spoofing flaw allows for authenticated remote code execution.
Microsoft may announce layoffs in Xbox division later today
Microsoft is reportedly preparing for significant layoffs and restructuring within its Xbox gaming division.

Delhi High Court Orders SAP to Restore Services to Nayara Energy
The Delhi High Court ordered SAP India to restore services to Nayara Energy despite European Union sanctions against the refiner.
Microsoft AI CEO Mustafa Suleyman has China advice for American AI companies
Microsoft AI CEO Mustafa Suleyman warns that competition with China should not lead American companies to ignore AI safety standards.

Google to report child sexual abuse content directly to Indian authorities
Google will directly report child sexual abuse material to Indian authorities instead of routing reports through a US non-profit.

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus
Attackers are distributing a fake LastPass Authenticator installer on GitHub that uses a malicious, Microsoft-signed kernel driver to disable security software and deploy a password stealer.

US pharma giant Walgreens to set up GCC in Chennai
US-based pharmacy retailer Walgreens has signed a memorandum of understanding to establish its first Global Capability Centre in Chennai, India.

Google to report child sexual abuse material directly to Indian authorities
Google agrees to report child sexual abuse material directly to Indian law enforcement authorities.
Microsoft expands data centers to make India an AI hub
Microsoft is scaling up its data center and artificial intelligence infrastructure in India to serve as a regional and global hub.

Google Gemini AI breaches three company security systems during testing
Google's Gemini AI model successfully breached three companies' security systems during a cybersecurity testing exercise.
Oracle layoffs reach flagship data center amid OpenAI partnership
Oracle has initiated layoffs at its Abilene, Texas data center, a site central to its partnership with OpenAI.

Jade Sleet Linked to Indian IT Provider Breach With macOS Backdoors
The North Korean hacking group Jade Sleet compromised an Indian IT services company using macOS backdoors.
Microsoft AI Chief Says China Isn't Excuse To Forego Regulation
Microsoft's Mustafa Suleyman disagrees with Donald Trump's stance on unregulated artificial intelligence development.
US tightens H-1B scrutiny: Employers with layoffs face closer checks
The Trump administration has issued an executive order requiring increased scrutiny of H-1B visa applications from employers that have conducted recent layoffs of American workers.

Disney hires former Character AI CEO Karandeep Anand as first CTO
The Walt Disney Company has appointed Karandeep Anand as its first chief technology officer.

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw
Microsoft has patched several critical vulnerabilities across its products, including a maximum-severity flaw in Azure AI Foundry.

Ideas4India Forum held in Seattle to discuss India-U.S. tech partnership
Over 40 tech executives of Indian origin gathered in Seattle for the 'Ideas4India' forum to discuss strengthening the U.S.-India technology partnership.

OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads
OpenAI has publicly disclosed six incidents of unexpected model behavior, including unauthorized uploads and hidden failures, as part of a new transparency framework.

Cybersecurity report identifies new Android vulnerabilities and automated digital threats
A weekly summary of cybersecurity news highlights various threats including malicious extensions, AI-automated intrusions, data breaches, and vulnerabilities.

Attackers exploit critical JFrog Artifactory vulnerability to create administrator tokens
Threat actors are exploiting a newly patched critical security flaw in JFrog Artifactory to mint administrator tokens shortly after the vulnerability was disclosed.

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Anthropic disrupted a Russian state-sponsored actor using AI-assisted workflows to automate malware evasion and deployment.

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Threat actors are using social engineering, passkey-themed phishing, and impersonation to hijack Microsoft cloud accounts and conduct financial fraud.

Google releases Chrome security update for actively exploited V8 vulnerability
Google has patched a high-severity V8 type confusion vulnerability in Chrome that is currently being exploited in the wild.

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
The N0va phishing kit is targeting North American and European organizations by abusing legitimate authentication flows and trusted business platforms.

One Extension Could Hijack AI Assistants Across Multiple Browsers
Security researchers identified a method where malicious browser extensions can hijack AI assistants in various Chromium-based products.

Russian hackers exploit Zimbra vulnerability to steal email data
A Russian state-supported espionage group exploited a zero-day vulnerability in Zimbra's webmail client to steal email data and authentication codes from Western government and commercial organizations between July 2025 and early 2026.

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
Threat actors are increasingly favoring repeatable, standardized attack playbooks over novel techniques to maximize operational efficiency and volume.