Visualização normal

Antes de ontemGBHackers on Security | #1 Globally Trusted Cyber Security News Platform

Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud

Microsoft is developing a new security feature for Teams messaging that will obscure QR codes sent by external users. This measure aims to help organizations reduce phishing and fraud risks associated with malicious QR code campaigns. Listed under Microsoft 365 Roadmap ID 570439, this feature is currently in development and is scheduled for rollout in […]

The post Microsoft Teams Adds QR Code Protection to Block Phishing and Fraud appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials

A Microsoft 365 email security-control bypass that lets attackers submit unauthenticated messages posing as internal users by leaving one SMTP field blank. The technique targets Exchange Online’s RejectDirectSend setting and does not represent a vulnerability in Microsoft software or in ReliaQuest systems; instead, it exposes a limitation in how the control evaluates Direct Send traffic. […]

The post Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks

Microsoft will start automatically enabling Memory Integrity protection on eligible Windows devices through quality updates beginning in October 2026. This change aims to strengthen defenses against kernel-level attacks by ensuring that only trusted kernel-mode code and drivers can run on supported systems. Memory Integrity is a security feature built on Virtualization-based Security (VBS), a Windows […]

The post Microsoft to Automatically Enable Memory Integrity on Windows Devices to Block Kernel Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Defender Bug Triggers False “Antivirus Turned Off” Alerts on Windows

Microsoft has confirmed an issue with Microsoft Defender Antivirus that generates false notifications on Windows systems, claiming “Microsoft Defender Antivirus is turned off,” even though the protection is still operational. These alerts may appear after installing the latest Defender updates, potentially causing unnecessary concern for administrators who observe that Defender settings are healthy and security […]

The post Microsoft Defender Bug Triggers False “Antivirus Turned Off” Alerts on Windows appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud

A cluster of fraudulent websites impersonating Microsoft is using fake “security scans” to pressure victims into uninstalling antivirus products, disclosing personal and banking information, and granting remote access to their computers. The sites, branded as SysScan, claim to assess whether an antivirus product is functioning properly. Their conclusion is predetermined: the victim’s computer is allegedly […]

The post Scammers Impersonate Microsoft to Push Fake Security Scans and Refund Fraud appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Windows 11 Update Triggers Game Crashes on Systems With RGB Lighting Drivers

Microsoft is currently investigating a compatibility issue with Windows 11, in which certain games crash, freeze, or cause unexpected system restarts on devices equipped with RGB lighting hardware and related low-level drivers. This problem was reported following the release of Windows updates on August 11, 2026, including the KB5121003 update for OS Build 26100.9168. Microsoft […]

The post Windows 11 Update Triggers Game Crashes on Systems With RGB Lighting Drivers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud

Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise (BEC). The attackers used an adversary-in-the-middle (AiTM) phishing kit to capture an authenticated Microsoft 365 session token, bypass multi-factor authentication, and quietly redirect vendor payments to attacker-controlled bank accounts. The lure contained a “View […]

The post Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Windows 11 24H2 Home and Pro Support Ends in October 2026

Microsoft has issued a 60-day reminder that the Windows 11 version 24H2 Home and Pro editions will reach the end of updates on October 13, 2026. This date also marks the end of servicing for Windows 10 Enterprise LTSB 2016. As a result, both organizations and individual users must plan their upgrade or migration activities […]

The post Windows 11 24H2 Home and Pro Support Ends in October 2026 appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Links 30+ Domains to MacSync Stealer’s Credential-Theft and Data-Exfiltration Infrastructure

More than 30 domains tied to MacSync Stealer, exposing a rotating macOS-focused infrastructure that supports payload delivery, command-and-control, credential theft, staging, and chunked data exfiltration. The investigation shows why defenders should prioritize repeatable endpoint and network behavior over static domain-based detections. Observed executions originate from interactive zsh sessions and use curl to fetch payloads from […]

The post Microsoft Links 30+ Domains to MacSync Stealer’s Credential-Theft and Data-Exfiltration Infrastructure appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Misconfigured Microsoft Power Pages Likely Exposed 27 Million Records to ExfilSquad

A suspected Microsoft Power Pages configuration failure has been linked to the exposure of roughly 27 million records across 13 organizations, after the data-extortion group ExfilSquad published 382.64 GB of alleged victim data via torrent distribution. Researchers assessing the released material say the evidence points to publicly readable Microsoft Dataverse tables not a zero-day exploit, […]

The post Misconfigured Microsoft Power Pages Likely Exposed 27 Million Records to ExfilSquad appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft Exchange Server Vulnerabilities Allow DoS, Privilege Escalation, and RCE

Microsoft has released security updates that address six vulnerabilities in Exchange Server. These vulnerabilities include flaws that could allow remote code execution (RCE), privilege escalation, denial-of-service (DoS), spoofing, and bypass of security features. The vulnerabilities were disclosed on August 11, 2026, with CVE-2026-62913 receiving an update the following day. Microsoft Exchange Server Vulnerabilities The most […]

The post Microsoft Exchange Server Vulnerabilities Allow DoS, Privilege Escalation, and RCE appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Microsoft SharePoint RCE Vulnerability Lets Remote Attackers Execute Code

A newly disclosed vulnerability in Microsoft SharePoint Server, tracked as CVE-2026-63520, could allow attackers to execute arbitrary code remotely on affected systems. This flaw has a severity rating of 8.1 out of 10 according to CVSS v3.1. It affects supported versions of Microsoft SharePoint, as well as certain deployments of Microsoft Project Server and Microsoft […]

The post Microsoft SharePoint RCE Vulnerability Lets Remote Attackers Execute Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy Chaos Ransomware

Hackers are abusing Microsoft Teams voice calls and fake IT helpdesk personas to gain remote access to corporate endpoints, drop a custom post‑exploitation toolchain, and, in multiple cases rapidly pivot to Chaos ransomware deployment across North American organizations. Nearly 95% of observed intrusions hit North American targets, with services, manufacturing, energy, construction and IP‑focused legal […]

The post Hackers Pose as IT Helpdesk on Microsoft Teams to Deploy Chaos Ransomware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌
❌