SecNoteMorning brief
Latest sync Aug 28, 10:22 PM
1 down

Reading Queue

Help
TodayActionsStack WatchFeedIntelligence
More
VendorMalwareRed TeamAIGlobal RiskUSWorld
HelpMethodologySourcesPrivacy

Queue triage

All feed: 21 matches for "Microsoft"

Top item: CISA Adds Six Known Exploited Vulnerabilities to Catalog

Action filterAll items
Showing18Saved0Sources down1

Feed counts show matched items; visible rows may be lower when repeated EPSS/CVE-only items are grouped for readability.

Reading Queue

Showing 18 of 21 visible rows.

Current state
More filters
criticalVulnerabilityKnown exploitedActive exploit

CVE-2015-3246 — Red Hat Libuser Race Condition +5 more (CISA KEV)

CISA Advisories | Aug 26, 2026

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerabili...

Evidence and analyst toolsscore 124
Sourcerss | ok | CISA Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 26, 2026, 12:00 PM UTC
Score inputsbase score 124, priority score 134, critical severity, 6 CVEs, CISA Advisories feed item, Mentions CVE-2015-3246, CVE-2015-5287, Watchlist: CISA, KEV, Microsoft, Known exploited, Active exploit, RCE
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#CISA#KEV#Microsoft#Citrix#Linux
Sigma searchNuclei searchSentinel search
criticalVulnerabilityPatchRCE

CVE-2026-66323 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Microsoft MSRC Updates | Aug 28, 2026

Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Evidence and analyst toolsscore 93
Sourcerss | ok | Microsoft MSRC Updates
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 2:00 PM UTC
Score inputsbase score 93, priority score 111, critical severity, 1 CVE, Microsoft MSRC Updates feed item, Mentions CVE-2026-66323, Watchlist: Microsoft, Edge, Patch, RCE
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Microsoft#Edge#CVE-2026-66323#Microsoft MSRC Updates
Sigma searchNuclei searchSentinel search
criticalVulnerabilityPatchRCE

CVE-2026-66798 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Microsoft MSRC Updates | Aug 28, 2026

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Evidence and analyst toolsscore 93
Sourcerss | ok | Microsoft MSRC Updates
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 2:00 PM UTC
Score inputsbase score 93, priority score 111, critical severity, 1 CVE, Microsoft MSRC Updates feed item, Mentions CVE-2026-66798, Watchlist: Microsoft, Edge, Patch, RCE
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Microsoft#Edge#CVE-2026-66798#Microsoft MSRC Updates
Sigma searchNuclei searchSentinel search
criticalVulnerabilityPatchRCE

CVE-2026-70341 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Microsoft MSRC Updates | Aug 28, 2026

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

Evidence and analyst toolsscore 93
Sourcerss | ok | Microsoft MSRC Updates
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 2:00 PM UTC
Score inputsbase score 93, priority score 111, critical severity, 1 CVE, Microsoft MSRC Updates feed item, Mentions CVE-2026-70341, Watchlist: Microsoft, Edge, Patch, RCE
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Microsoft#Edge#CVE-2026-70341#Microsoft MSRC Updates
Sigma searchNuclei searchSentinel search
criticalVulnerabilityPatchRCE

CVE-2026-72984 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Microsoft MSRC Updates | Aug 28, 2026

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Evidence and analyst toolsscore 93
Sourcerss | ok | Microsoft MSRC Updates
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 2:00 PM UTC
Score inputsbase score 93, priority score 111, critical severity, 1 CVE, Microsoft MSRC Updates feed item, Mentions CVE-2026-72984, Watchlist: Microsoft, Edge, Patch, RCE
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Microsoft#Edge#CVE-2026-72984#Microsoft MSRC Updates
Sigma searchNuclei searchSentinel search
criticalVulnerabilityActive exploitPatch

Microsoft Plugs Nearly 400 Security Holes

KrebsOnSecurity | Aug 11, 2026

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

Evidence and analyst toolsscore 84
Sourcerss | ok | KrebsOnSecurity
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 11, 2026, 9:28 PM UTC
Score inputsbase score 84, priority score 58, critical severity, KrebsOnSecurity feed item, Watchlist: Microsoft, Windows, Active exploit, Patch
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Microsoft#Windows#KrebsOnSecurity
Sigma searchNuclei searchSentinel search
highVulnerabilityPatch

CVE-2026-70331 Microsoft Edge for iOS Spoofing Vulnerability

Microsoft MSRC Updates | Aug 28, 2026

Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

Evidence and analyst toolsscore 83
Sourcerss | ok | Microsoft MSRC Updates
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 2:00 PM UTC
Score inputsbase score 83, priority score 101, high severity, 1 CVE, Microsoft MSRC Updates feed item, AI relevance match, Mentions CVE-2026-70331, Patch
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Microsoft#Edge#LLM#CVE-2026-70331#Microsoft MSRC Updates
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2019-1068: Microsoft SQL Server - Microsoft SQL Server Remote Code Execution Vulnerability

CISA KEV | Aug 26, 2026

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 26, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 92, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: Microsoft, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#Microsoft#SQL Server
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions - Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability

CISA KEV | Aug 18, 2026

Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 18, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 36, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: Microsoft, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#Microsoft#Internet Key Exchange (IKE) Service Extensions
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2026-55040: Microsoft SharePoint - Microsoft SharePoint Weak Authentication Vulnerability

CISA KEV | Aug 18, 2026

Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 18, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 36, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: Microsoft, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#Microsoft#SharePoint
Sigma searchNuclei searchSentinel search
highVulnerabilityKnown exploited

CVE-2026-68820: Microsoft Windows Ancillary Function Driver for WinSock - Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

CISA KEV | Aug 11, 2026

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

Evidence and analyst toolsscore 82
Sourcestructured | ok | CISA KEV
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 11, 2026, 12:00 AM UTC
Score inputsbase score 82, priority score 25, high severity, 1 CVE, CISA Known Exploited Vulnerabilities entry, Vendor: Microsoft, Known exploited
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#KEV#Microsoft#Windows Ancillary Function Driver for WinSock
Sigma searchNuclei searchSentinel search
highVulnerabilityPatch

CVE-2026-58616 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Microsoft MSRC Updates | Aug 28, 2026

Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.

Evidence and analyst toolsscore 71
Sourcerss | ok | Microsoft MSRC Updates
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 2:00 PM UTC
Score inputsbase score 71, priority score 89, high severity, 1 CVE, Microsoft MSRC Updates feed item, Mentions CVE-2026-58616, Watchlist: Microsoft, Edge, Patch
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Microsoft#Edge#CVE-2026-58616#Microsoft MSRC Updates
Sigma searchNuclei searchSentinel search
highVulnerabilityPatch

CVE-2026-62904 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

Microsoft MSRC Updates | Aug 28, 2026

Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

Evidence and analyst toolsscore 71
Sourcerss | ok | Microsoft MSRC Updates
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 2:00 PM UTC
Score inputsbase score 71, priority score 89, high severity, 1 CVE, Microsoft MSRC Updates feed item, Mentions CVE-2026-62904, Watchlist: Microsoft, Edge, Patch
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Microsoft#Edge#CVE-2026-62904#Microsoft MSRC Updates
Sigma searchNuclei searchSentinel search
highVulnerabilityPatch

CVE-2026-66324 Microsoft Edge (Chromium-based) Spoofing Vulnerability

Microsoft MSRC Updates | Aug 28, 2026

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Evidence and analyst toolsscore 71
Sourcerss | ok | Microsoft MSRC Updates
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 2:00 PM UTC
Score inputsbase score 71, priority score 89, high severity, 1 CVE, Microsoft MSRC Updates feed item, Mentions CVE-2026-66324, Watchlist: Microsoft, Edge, Patch
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Microsoft#Edge#CVE-2026-66324#Microsoft MSRC Updates
Sigma searchNuclei searchSentinel search
highVulnerabilityPatch

Chromium: CVE-2026-78891 Buffer overflow in WebRTC

Microsoft MSRC Updates | Aug 28, 2026

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Evidence and analyst toolsscore 71
Sourcerss | ok | Microsoft MSRC Updates
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 2:00 PM UTC
Score inputsbase score 71, priority score 89, high severity, 1 CVE, Microsoft MSRC Updates feed item, Mentions CVE-2026-78891, Watchlist: Microsoft, Chrome, Edge, Patch
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Microsoft#Chrome#Edge#CVE-2026-78891#Microsoft MSRC Updates
Sigma searchNuclei searchSentinel search
highVulnerabilityPatch

Chromium: CVE-2026-78892 Incorrect authorization in Chromoting

Microsoft MSRC Updates | Aug 28, 2026

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Evidence and analyst toolsscore 71
Sourcerss | ok | Microsoft MSRC Updates
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 2:00 PM UTC
Score inputsbase score 71, priority score 89, high severity, 1 CVE, Microsoft MSRC Updates feed item, Mentions CVE-2026-78892, Watchlist: Microsoft, Chrome, Edge, Patch
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Microsoft#Chrome#Edge#CVE-2026-78892#Microsoft MSRC Updates
Sigma searchNuclei searchSentinel search
highVulnerabilityPatch

Microsoft Patches a Record 570 Security Flaws

KrebsOnSecurity | Jul 14, 2026

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attr...

Evidence and analyst toolsscore 64
Sourcerss | ok | KrebsOnSecurity
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Jul 14, 2026, 7:22 PM UTC
Score inputsbase score 64, priority score -1, high severity, KrebsOnSecurity feed item, AI relevance match, Watchlist: Microsoft, Windows, artificial intelligence, Patch
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#Microsoft#Windows#artificial intelligence#KrebsOnSecurity
highVendor advisoryRansomware

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Security | Aug 10, 2026

Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to ...

Evidence and analyst toolsscore 62
Sourcerss | ok | Microsoft Security
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 10, 2026, 3:00 PM UTC
Score inputsbase score 62, priority score 35, high severity, Microsoft Security feed item, Watchlist: ransomware, Microsoft, Ransomware
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#ransomware#Microsoft#Microsoft Security
Sigma searchNuclei searchSentinel search
TrustSource health1 failed and 4 degraded sources in this run.

Source Health

69 sources
Coverage impact: failed: GDELT. degraded: NPR Politics, Defense.gov News, Federal Reserve Press, GovInfo Federal Register. Treat affected lanes as incomplete until refresh succeeds.

BleepingComputer

rss | 15 items

ok

The Hacker News

rss | 18 items

ok

SecurityWeek

rss | 10 items

ok

Dark Reading

rss | 18 items

ok

KrebsOnSecurity

rss | 10 items

ok

OpenAI News

rss | 8 items

ok

TechCrunch AI

rss | 10 items

ok

VentureBeat AI

rss | 7 items

ok

The Verge AI

rss | 8 items

ok

Google AI

rss | 10 items

ok

MIT News AI

rss | 8 items

ok

MIT Technology Review

rss | 6 items

ok

The Register AI/ML

rss | 8 items

ok

Google Project Zero

rss | 7 items

ok

CISA Advisories

rss | 18 items

ok

CISA ICS Advisories

rss | 8 items

ok

Microsoft Security

rss | 8 items

ok

Microsoft MSRC Updates

rss | 10 items

ok

Cisco Security Advisories

rss | 8 items

ok

Palo Alto Security Advisories

rss | 8 items

ok

FortiGuard Outbreak Alerts

rss | 8 items

ok

FortiGuard Threat Signal

rss | 8 items

ok

Chrome Releases

rss | 8 items

ok

Mozilla Security

rss | 8 items

ok

Unit 42

rss | 8 items

ok

Cisco Talos

rss | 8 items

ok

ESET WeLiveSecurity

rss | 8 items

ok

Malwarebytes Labs

rss | 8 items

ok

SentinelOne

rss | 6 items

ok

SANS Internet Storm Center

rss | 8 items

ok

CrowdStrike

rss | 7 items

ok

CyberScoop

rss | 8 items

ok

The Record

rss | 5 items

ok

DataBreaches.net

rss | 6 items

ok

BBC World

rss | 7 items

ok

BBC Business

rss | 6 items

ok

NPR World

rss | 3 items

ok

NPR Politics

rss | 0 items | Source responded but no relevant items matched.

degraded

Al Jazeera

rss | 8 items

ok

The Guardian World

rss | 6 items

ok

The Guardian US Politics

rss | 5 items

ok

The Guardian Business

rss | 6 items

ok

NYTimes World

rss | 6 items

ok

NYTimes Politics

rss | 3 items

ok

Defense.gov News

rss | 0 items | Source responded but no relevant items matched.

degraded

Federal Reserve Press

rss | 0 items | Source responded but no relevant items matched.

degraded

GovInfo Federal Register

rss | 0 items | Source responded but no relevant items matched.

degraded

GovInfo Congressional Bills

rss | 6 items

ok

NPR News

rss | 8 items

ok

NPR National

rss | 8 items

ok

NPR Politics

rss | 6 items

ok

NYTimes U.S.

rss | 6 items

ok

NYTimes Politics

rss | 6 items

ok

The Guardian U.S.

rss | 6 items

ok

BBC U.S. & Canada

rss | 6 items

ok

BBC World

rss | 8 items

ok

BBC Business

rss | 6 items

ok

NPR World

rss | 8 items

ok

Al Jazeera

rss | 8 items

ok

The Guardian World

rss | 6 items

ok

The Guardian Business

rss | 6 items

ok

NYTimes World

rss | 6 items

ok

NYTimes Business

rss | 6 items

ok

CISA KEV

structured | 22 items

ok

GitHub Advisories

api | 24 items

ok

NVD Recent CVEs

api | 18 items

ok

FIRST EPSS

api | 20 items

ok

Hacker News

api | 5 items

ok

GDELT

api | 0 items | fetch failed

failed

1 source currently timed out or rejected the request. Refresh reruns every source, including failed pulls.

ScopeWatchlist75 terms used to highlight recurring products, tactics, and security topics.

Watchlist

CISAKEVzero-dayransomwareregulationtarifftradeexport controlsupply chaininitial accessidentityphishingAI securityprompt injectionmodel poisoningagentic AIdeepfakeMicrosoftWindowsAzureEntraActive DirectoryOktaCiscoPalo AltoFortinetIvantiVMware