Tag: Microsoft

MSPs
Cloud liberation: What Microsoft’s deal with CISPE means for MSPs

Cloud liberation: What Microsoft’s deal with CISPE means for MSPs

Managed service providers (MSPs) in Europe are closely watching how a settlement between Microsoft and the Cloud Infrastructure Services Providers in Europe (CISPE) coalition will impact pricing and availability of cloud services.  Under the agreement, cloud service providers (CSPs) that are...

/ July 31, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Microsoft SharePoint zero-day vulnerability

Cybersecurity Threat Advisory: Microsoft SharePoint zero-day vulnerability

Attackers are actively exploiting CVE-2025-53770, a critical zero-day vulnerability in Microsoft SharePoint, to execute remote code without authentication. This flaw allows attackers to deploy persistent malware and potentially exfiltrate sensitive data from unpatched on-premises environments. Review the full details in...

/ July 22, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Severe WebDAV vulnerability

Cybersecurity Threat Advisory: Severe WebDAV vulnerability

Microsoft has disclosed a serious zero-day vulnerability in the Web Distributed Authoring and Versioning (WebDAV) protocol, identified as CVE-2025-33053, with a CVSS score of 8.8. Actively exploited by the Stealth Falcon APT group, this vulnerability enables remote code execution (RCE)...

/ June 30, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: New RAT malware

Cybersecurity Threat Advisory: New RAT malware

Microsoft has issued a warning about a new, sophisticated remote access trojan (RAT) called StilachiRAT. Threat actors are actively using StilachiRAT to evade detection to establish persistent access to compromised systems. Continue reading this Cybersecurity Threat Advisory to protect your...

/ March 20, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Azure vulnerabilities

Cybersecurity Threat Advisory: Critical Azure vulnerabilities

Microsoft revealed two critical vulnerabilities in Microsoft Azure AI Face Service, a cloud-based facial recognition tool. They enable attackers to bypass authentication. Review the details within this Cybersecurity Threat Advisory to discover the key steps to safeguard your environment. What...

/ February 6, 2025
Tech Time Warp
Tech Time Warp: 50 Years of the Microsoft brand

Tech Time Warp: 50 Years of the Microsoft brand

On Jan. 2, 1975, Microsoft co-founders Bill Gates and Paul Allen wrote a letter to MITS, the manufacturer of the Altair computer. Inspired by a Popular Electronics article about the Altair 8800, Gates and Allen—who were geeking out on microprocessors...

/ January 3, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Windows kernel vulnerability

Cybersecurity Threat Advisory: Critical Windows kernel vulnerability

A pointer dereference weakness was discovered within the Microsoft Kernel Streaming Service that would allow an attacker to escalate their privileges to SYSTEM without any user interaction being required. Review the details in this Cybersecurity Threat Advisory to learn how...

/ December 20, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: CRON#TRAP phishing campaign

Cybersecurity Threat Advisory: CRON#TRAP phishing campaign

A new phishing campaign, identified as CRON#TRAP, are targeting Windows systems with a preloaded Linux virtual machine (VM) to evade detection to conduct malicious acts.  Continue reading this Cybersecurity Threat Advisory to learn how to protect against this phishing campaign....

/ November 6, 2024 / 1 Comment
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Exploited Microsoft zero-day flaw

Cybersecurity Threat Advisory: Exploited Microsoft zero-day flaw

The hacker group Lazarus recently exploited a patched, zero-day flaw in Microsoft Windows. The vulnerability, tracked as CVE-2024-38193 with a CVSS score of 7.8, is a Bring Your Own Vulnerable Driver (BYOVD) vulnerability for Winsock. Continue reading this Cybersecurity Threat...

/ August 21, 2024
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Active exploitation of Microsoft vulnerabilities

Cybersecurity Threat Advisory: Active exploitation of Microsoft vulnerabilities

This Cybersecurity Threat Advisory highlights a new attack technique exploiting vulnerabilities in Microsoft Management Console (MMC). By creating malicious management saved console (MSC) files that appear legitimate, attackers can bypass traditional security measures and exploit the targeted MMC. Barracuda MSP...

/ June 26, 2024