Live
CVE-2026-42824: Microsoft Shuts Down ‘SearchLeak’ Attack Chain in Copilot·MSFT +2.1%FBI Warns Kali365 Phishing Kit Exploits Microsoft Device Code Flow to Slip Past MFA·NVDA +0.2%Copilot Studio's maker auth model enables prompt injection attacks across enterprise tools and connectors.·GOOGL +1.7%Microsoft's zero-trust stack gives every AI agent in Windows 365 a unique identity.·AMZN +1.1%Nation-state groups exploit weak M365 admin controls—eight-step blueprint to prevent full tenant takeover·MSFT +2.1%Pax8 Partners Gain Recurring Revenue with inforcer Copilot Readiness Service·NVDA +0.2%Microsoft 365 Baseline Security Mode: One-Click Hardening with Legacy Exclusions·GOOGL +1.7%Microsoft Teams Phishing Attack Bypasses MFA via Fake IT Chat·AMZN +1.1%CVE-2026-42824: Microsoft Shuts Down ‘SearchLeak’ Attack Chain in Copilot·MSFT +2.1%FBI Warns Kali365 Phishing Kit Exploits Microsoft Device Code Flow to Slip Past MFA·NVDA +0.2%Copilot Studio's maker auth model enables prompt injection attacks across enterprise tools and connectors.·GOOGL +1.7%Microsoft's zero-trust stack gives every AI agent in Windows 365 a unique identity.·AMZN +1.1%Nation-state groups exploit weak M365 admin controls—eight-step blueprint to prevent full tenant takeover·MSFT +2.1%Pax8 Partners Gain Recurring Revenue with inforcer Copilot Readiness Service·NVDA +0.2%Microsoft 365 Baseline Security Mode: One-Click Hardening with Legacy Exclusions·GOOGL +1.7%Microsoft Teams Phishing Attack Bypasses MFA via Fake IT Chat·AMZN +1.1%

Microsoft 365 Security

The latest Microsoft 365 Security coverage — news, analysis, and updates from the WindowsNews.AI desk.

12 stories in view AI assisted desk updated 9:50 PM
Latest Most Read Breaking
Sort
Ai Governance · Ai Security

CVE-2026-42824: Microsoft Shuts Down ‘SearchLeak’ Attack Chain in Copilot

Microsoft has rolled out a critical security update for Microsoft 365 Copilot that neutralizes a one-click data-exfiltration attack chain that researchers at Varonis dubbed “SearchLeak.” The...

Advertisement
Cloud Configuration Drift · Entra Id Governance

Nation-state groups exploit weak M365 admin controls—eight-step blueprint to prevent full tenant takeover

By 2026, a single compromised Microsoft 365 global administrator account hands an attacker the keys to read every email, exfiltrate terabytes of sensitive files and disable every security control...

SE Security Desk·5w ago
Cloud Governance · Copilot Readiness

Pax8 Partners Gain Recurring Revenue with inforcer Copilot Readiness Service

Pax8 announced on June 9, 2026, that it will integrate inforcer into its cloud marketplace this summer, giving managed service providers (MSPs) a streamlined way to deliver Microsoft 365 security,...

AI AI & Copilot Desk·6w ago
Conditional Access · Microsoft 365 Security

Microsoft 365 Baseline Security Mode: One-Click Hardening with Legacy Exclusions

Microsoft has quietly rolled out Baseline Security Mode, a new opt-in feature in the Microsoft 365 admin center that allows organizations to apply a comprehensive set of security recommendations with...

SE Security Desk·6w ago
Identity Attack Surface · Mfa Phishing

Microsoft Teams Phishing Attack Bypasses MFA via Fake IT Chat

Attackers are exploiting Microsoft Teams to pose as IT support, trick users into granting external access, and bypass multi-factor authentication protections. On June 8, 2026, Palo Alto Networks'...

SE Security Desk·6w ago
Identity Security · Incident Response

Inforcer Debuts Microsoft 365 Threat Detection Platform for MSPs

Inforcer on June 8, 2026, unveiled a dedicated threat detection and response platform engineered specifically for managed service providers (MSPs) safeguarding Microsoft 365 environments. The launch...

SE Security Desk·6w ago
Byod Device Governance · Microsoft 365 Security

Fire and Emergency NZ Blocks Document Downloads to Personal Devices from June 2026

{ "title": "Fire and Emergency NZ Blocks Downloads to Personal Devices (Browser-Only Access)", "content": "Fire and Emergency New Zealand (FENZ) has announced it will prevent users from...

SE Security Desk·6w ago
Ai Governance · Compliance Retention

AI Governance: Monitoring Human-AI and Agent-to-Agent Conversations in Microsoft 365

Theta Lake dropped a bombshell on the compliance world this week. The California-based collaboration security vendor declared that organizations must start treating “aiComms”—human-to-AI and...

AI AI & Copilot Desk·6w ago
Cve-2026-48579 · Exchange Online

CVE-2026-48579 Exchange Online Info Disclosure: What Administrators Need to Know

Microsoft has officially listed CVE-2026-48579 as an information disclosure vulnerability affecting Microsoft Exchange Online, according to a recent entry in the Security Update Guide. The...

SE Security Desk·6w ago