cybersecurity

A collection of 554 posts
microsoft

Microsoft Sounds Alarm on Rising ACR Stealer Malware Campaigns

Microsoft reports a significant increase in attacks leveraging ACR Stealer, a malware-as-a-service operation that targets enterprise customers to harvest browser-stored passwords, authentication tokens, and sensitive documents. Between late April and mid-June, threat actors deploy the info-stealing payload using the ClickFix social-engineering technique, WebDAV servers, and the Microsoft HTML Application Host
1 min read
cisa

CISA Urges Immediate Patching of Actively Exploited SharePoint Vulnerabilities

CISA warns that attackers are actively exploiting three serious vulnerabilities in Internet-exposed, on-premises Microsoft SharePoint Server instances. These flaws, tracked as CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, affect all supported self-hosted versions of SharePoint Server. Attackers use them to bypass authentication, execute remote code, and establish persistence on compromised systems. According to
1 min read