search
Microsoft Security Research
Trends
- 1
Phishing is in the spotlight as new reports detail a wave of scams and malware campaigns. Russian state hackers are said to be using a technique called RedFlick to spread malware, while Ukrainian authorities warn consumers about fake electricity bills. Researchers also flagged a remote access trojan distributed through fake Microsoft Store pages, and a report finds phishing exposure nearing 70% across key US industries.
- 2Researcher says Microsoft left 17 trillion records exposed●I could've accessed 17T Microsoft records
A security researcher has published a write-up describing how they could have accessed 17 trillion Microsoft records through a vulnerability. The blog post walks through the flaw and how access was theoretically possible. Hacker News readers are discussing the finding, debating the scale of the exposure and how Microsoft handles responsible disclosure.
- 3Four Spy Groups Used Same Chrome and Windows Exploit Kit Within a Week●Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week https:// thehackernews.com/2026/09/four -spy-
Security researchers report that four separate spyware groups deployed the same exploit kit targeting Google Chrome and Microsoft Windows, all within a single week. The finding suggests the groups are sharing or purchasing identical hacking tools rather than developing their own, raising fresh concerns about the proliferation of surveillance capabilities. Cybersecurity commentators are highlighting the case as evidence of a growing grey market for exploits used against journalists, dissidents and other targets.
- 4Microsoft details Zimbra flaw allowing code execution via email●Zimbra CVE-2026-73570 lets one crafted email run code. Microsoft details the Zimbra command injection attacks: web shell
Microsoft researchers have detailed attacks exploiting a Zimbra command injection vulnerability, CVE-2026-73570, in which a single crafted email is enough to run code on the mail server. The documented attacks involve deploying web shells, gaining root access, and stealing cryptographic keys. Security teams running Zimbra are being urged to patch and review their servers for signs of compromise.
- 5TA419 phishing campaign targeted AI-policy specialists●Proofpoint says TA419 impersonated AI-policy figures and used a real-time Microsoft 365 phishing proxy against fewer tha
Security firm Proofpoint reports that the threat group TA419 impersonated prominent AI-policy figures and used a real-time Microsoft 365 phishing proxy to steal authenticated login sessions. The highly targeted campaign hit fewer than ten specialists. Researchers say it shows how attackers can capture live sessions, though successful compromises and government attribution remain unclear.
- 6Critical Zimbra flaw CVE-2026-73570 actively exploited●🤖 CVE-2026-73570 (CVSS 8.9): unauthenticated OS command injection in Zimbra Collaboration Suite via its SNMP service, no
A critical vulnerability, CVE-2026-73570 with a CVSS score of 8.9, in Zimbra Collaboration Suite allowed unauthenticated attackers to run operating system commands through its SNMP service. According to Microsoft Security Research, attackers exploited the flaw to deploy web shells and steal mailbox credentials. A patch has been released, and security teams are urged to update affected servers promptly.
- 7Microsoft rates Security Copilot prompt injection risk as Low●MSRC assessed an indirect prompt injection into Security Copilot as Low severity because consequential action still requ
Microsoft's Security Response Center assessed an indirect prompt injection into Security Copilot as Low severity, reasoning that consequential action still required downstream automation or human approval. Security researchers are pushing back, arguing that rationale becomes untenable as AI systems are increasingly designed to perceive, reason, and act autonomously, with less human oversight built in.
- 8New Windows NCSI proxy authentication flaw detailed by researchers▼Microsoft Windows NCSI Cross-Context Proxy Authentication Coercion - ZDI-26-708 - Part 1: https:// pgj11.com/posts/Windo
Security researchers have published a two-part technical write-up of a Windows vulnerability tracked as ZDI-26-708, described as a cross-context proxy authentication coercion in the Network Connectivity Status Indicator (NCSI). The disclosure is circulating among security professionals sharing the detailed analysis. Details on affected versions and patches remain unclear from the discussion so far.
- 9Cybersecurity researchers flag suspected Office 365 phishing domain●Possible Phishing 🎣 on: ⚠️hxxp[:]//office365licensingsupport[.]com 🧬 Analysis at: https:// urldna.io/scan/6abd40193b7750
Security researchers are warning about a suspected phishing site at office365licensingsupport.com, a domain name that imitates Microsoft's Office 365 branding to trick users into handing over credentials. A public analysis of the domain has been shared via the URLdna scanning service, and warnings are circulating in infosec communities with the domain deliberately defanged to prevent accidental clicks.
- 10Microsoft details NeedyMantis malware used in targeted attacks●Posted yesterday, if you missed this. Microsoft: NeedyMantis: Unpacking a post-compromise malware family used in targete
Microsoft has published an analysis of NeedyMantis, a malware family deployed after attackers have already breached a network, with use in targeted operations against specific victims. The report breaks down how the malware behaves once inside a compromised environment. Security researchers and practitioners are sharing the findings, warning organisations to review the indicators of compromise Microsoft disclosed.
- 11Microsoft-linked network spotted announcing IP space from Oslo●ASN: AS8075 Location: Oslo, NO Added: 2026-09-25T18:01 # shodansafari # infosec
Autonomous System 8075, the network operated by Microsoft, was observed announcing IP address space located in Oslo, Norway. The observation was logged and shared on 25 September 2026 with the cybersecurity community under the tag #shodansafari. This type of sighting is used by security researchers to track how large cloud and technology providers extend their network presence into new regions and data centre locations.