Skip to content
Threat Feed

CPE

Cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*

5 briefs RSS
high advisory

Multiple Privilege Escalation Vulnerabilities in Microsoft Authenticator and Xbox Gaming Services

Local attackers can exploit multiple vulnerabilities in Microsoft Authenticator and Xbox Gaming Services to achieve elevated privileges on Windows systems.

Microsoft Authenticator +1 privilege-escalation windows vulnerability
1t 2c
low advisory

Information Disclosure Vulnerability in Microsoft 365 Copilot

A vulnerability identified as CVE-2024-38148 in Microsoft 365 Copilot allows remote, unauthenticated attackers to potentially access unauthorized sensitive information within the service environment.

365 Copilot information-disclosure cloud-security saas
1t 1c
critical threat

August 2026 Microsoft Security Update Analysis

Microsoft's August 2026 security release addresses 415 vulnerabilities, including a zero-day (CVE-2026-68820) exploited in the wild that enables local privilege escalation in the Windows Ancillary Function Driver for WinSock.

exploited Windows +7 vulnerability-management patch-tuesday privilege-escalation
1t 5c updated
high threat

Microsoft Security Updates — August 2026

Roundup of Microsoft security advisories published in August 2026.

roundup
29c updated
high advisory

DNS Kerberos Coercion Attempt Detection

This brief details the detection of DNS-based Kerberos coercion attacks, where adversaries inject marshaled credential structures into DNS records to spoof SPNs and redirect authentication, as seen in CVE-2025-33073, using Suricata and Sysmon event ID 22.

PoC Fortinet edge appliances +38 kerberos coercion dns cve-2025-33073
3r 3t 4c 4i updated