Latest Tech News

Stay updated with the latest in technology, AI, cybersecurity, and more

Filtered by: micro Clear Filter

Microsoft Put Older Versions of SharePoint on Life Support. Hackers Are Taking Advantage

Hundreds of organizations around the world suffered data breaches this week, as an array of hackers rushed to exploit a recently discovered vulnerability in older versions of the Microsoft file-sharing tool known as SharePoint. The string of breaches adds to an already urgent and complex dynamic: Institutions that are longtime SharePoint users can face increased risk by continuing to use the service, just as Microsoft is winding down support for a platform in favor of newer cloud offerings. Mic

What to know about ToolShell, the SharePoint threat under mass exploitation

Government agencies and private industry have been under siege over the past four days following the discovery that a critical vulnerability in SharePoint, the widely used document-sharing app made by Microsoft, is under mass exploitation. Since that revelation, the fallout and the ever-increasing scope of the attacks have been hard to keep track of. What follows are answers to some of the most common questions about the vulnerability and the ongoing exploitation of it, which collectively is be

Microsoft fixes three SharePoint zero-day exploits used in series of cyberattacks - how to patch them

Olemedia / Getty Images Microsoft has patched three critical zero-day SharePoint security flaws that have already been exploited by hackers to attack a larger number of vulnerable organizations. Responding to the exploits, the software giant initially issued fixes just for SharePoint Server Subscription Edition and SharePoint Server 2019 and then eventually rolled out a patch for SharePoint Server 2016 as well. Designated as CVE-2025-53771 and CVE-2025-53770, the two vulnerabilities apply only

US nuclear weapons agency hacked in Microsoft SharePoint attacks

Unknown threat actors have breached the National Nuclear Security Administration's network in attacks exploiting a recently patched Microsoft SharePoint zero-day vulnerability chain. NNSA is a semi-autonomous U.S. government agency part of the Energy Department that maintains the country's nuclear weapons stockpile and is also tasked with responding to nuclear and radiological emergencies within the United States and abroad. A Department of Energy spokesperson confirmed in a statement that hac

US nuclear weapons agency reportedly hacked in SharePoint attacks

Unknown threat actors have reportedly breached the National Nuclear Security Administration's network in attacks exploiting a recently patched Microsoft SharePoint zero-day vulnerability chain. NNSA is a semi-autonomous U.S. government agency part of the Energy Department that maintains the country's nuclear weapons stockpile and is also tasked with responding to nuclear and radiological emergencies within the United States and abroad. A Department of Energy spokesperson confirmed in a stateme

The Outer Worlds 2 will no longer be Microsoft’s first $80 Xbox game

is a senior editor and author of Notepad , who has been covering all things Microsoft, PC, and tech for over 20 years. Microsoft-owned developer Obsidian Entertainment is announcing a price drop for the The Outer Worlds 2 today. The game was originally supposed to debut at $79.99 in October, but it’s now going back to the regular $69.99 Xbox game price. Microsoft announced earlier this year that it would be raising the price of new Xbox first-party games from $69.99 to $79.99, alongside increa

Microsoft fixes two SharePoint zero-days under attack, but one is still unresolved - how to patch

Olemedia / Getty Images Microsoft has patched two critical zero-day SharePoint security flaws that have already been exploited by hackers to attack vulnerable organizations. Responding to the exploits, the software giant has issued fixes for SharePoint Server Subscription Edition and SharePoint Server 2019, but is still working on a patch for SharePoint Server 2016. Designated as CVE-2025-53771 and CVE-2025-53770, the two vulnerabilities apply only to on-premises versions of SharePoint, so org

Brave blocks Microsoft Recall by default

This is the 35th post in an ongoing series describing new privacy features in Brave. This post describes work done by Pavel Beloborodov (Senior Software Engineer) and Brian Johnson (Principal Engineer). It was written by Shivan Kaul Sahib (VP, Privacy and Security). Starting in version 1.81 for Windows users, Brave browser will block Microsoft Recall from automatically taking screenshots of your browsing activity. Why we’re doing this Microsoft first announced Recall in May 2024 and immediate

US nuclear weapons agency breached using Microsoft SharePoint hack

The US government agency in charge of designing and maintaining nuclear weapons was among those breached by a hack of Microsoft's SharePoint server software, Bloomberg reported. However, attackers weren't able to obtain any sensitive or classified information, according to an unnamed source with knowledge of the matter. The breach occurred at the National Nuclear Security Administration, an arm of the Energy Department responsible for producing and dismantling nuclear arms. "On Friday, July 18t

US agency responsible for nuclear weapons was breached in Sharepoint hack [U]

More than 10,000 organizations around the world are at risk from hackers after a serious security flaw was discovered in Microsoft’s popular Sharepoint platform, used to store and share confidential documents. The majority of companies at risk are said to be in the US. Update: Bloomberg reports that the National Nuclear Security Administration was among the organizations breached – see the end of the piece … Microsoft said that there were “active attacks targeting on-premises servers.” US fede

US nuclear weapons agency reportedly breached in Microsoft SharePoint attacks

is a senior editor and author of Notepad , who has been covering all things Microsoft, PC, and tech for over 20 years. Hours after Microsoft revealed hacking groups affiliated with the Chinese government have been exploiting a flaw in its SharePoint software, Bloomberg News reports that the National Nuclear Security Administration has also been breached in the attacks. A single source tells Bloomberg that the department, which provides the Navy with nuclear reactors for submarines, was caught

Microsoft servers hacked by Chinese groups, says tech giant

Microsoft servers hacked by Chinese groups, says tech giant "Investigations into other actors also using these exploits are still ongoing," Microsoft said in a statement. The US tech giant has released security updates in response and has advised all on-premises SharePoint server customers to install them. China state-backed Linen Typhoon and Violet Typhoon as well as China-based Storm-2603 were said to have "exploited vulnerabilities" in on-premises SharePoint servers, the kind used by firms

Microsoft servers hacked by Chinese groups, firm says

Microsoft servers hacked by Chinese groups, firm says "Investigations into other actors also using these exploits are still ongoing," Microsoft said in a statement. The US tech giant has released security updates in response and has advised all on-premises SharePoint server customers to install them. China state-backed Linen Typhoon and Violet Typhoon as well as China-based Storm-2603 were said to have "exploited vulnerabilities" in on-premises SharePoint servers, the kind used by firms, but

Lumma infostealer malware returns after law enforcement disruption

The Lumma infostealer malware operation is gradually resuming activities following a massive law enforcement operation in May, which resulted in the seizure of 2,300 domains and parts of its infrastructure. Although the Lumma malware-as-a-service (MaaS) platform suffered significant disruption from the law enforcement action, as confirmed by early June reports on infostealer activity, it didn't shut down. The operators immediately acknowledged the situation on XSS forums, but claimed that thei

Microsoft links Sharepoint ToolShell attacks to Chinese hackers

Several hacking groups with ties to the Chinese government have been linked to a recent wave of widespread attacks targeting a Microsoft SharePoint zero-day vulnerability chain. They used this exploit chain (dubbed "ToolShell") to breach dozens of organizations worldwide after hacking into their on-premise SharePoint servers. "Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon exploiting these vulnerabilities targeting internet-facing SharePoint serv

Windows 11 KB5062660 update brings new 'Windows Resilience' features

​​Microsoft has released the KB5062660 preview cumulative update for Windows 11 24H2 with twenty-nine new features or changes, with many gradually rolling out, such as the new Black Screen of Death and Quick Machine Recovery tool. The KB5062660 update is part of the company's optional non-security preview updates schedule, which releases updates at the end of each month to test new fixes and features coming to next month's August Patch Tuesday. Unlike regular Patch Tuesday cumulative updates,

Windows 11’s new update will add a bunch of AI features

is a news writer who covers the streaming wars, consumer tech, crypto, social media, and much more. Previously, she was a writer and editor at MUO. Microsoft is releasing several new AI features for Windows 11, including its Copilot Vision tool that can scan everything on your screen. The features, which are gradually rolling out to everyone now, also include tools that are exclusive to Copilot Plus PCs. For starters, all Windows 11 users can now access Copilot Vision through the Copilot app,

Windows 11 gets new Black Screen of Death, auto recovery tool

Microsoft is rolling out significant changes to Windows 11 24H2 as part of the Windows Resilience Initiative, designed to reduce downtime and help devices recover from serious failures, as well as an overhaul of the all-too-familiar BSOD crash screens. Microsoft's Windows Resiliency Initiative is a new effort by Microsoft to make Windows more stable, self-healing, and faster to recover from critical failures. This initiative is in direct response to recent incidents that caused widespread disru

Microsoft Will Wipe Out Your Passwords on Aug. 1. What to Do Now

Microsoft is getting rid of passwords in less than two weeks. On Aug. 1, the Microsoft Authenticator app will no longer store or manage passwords, which could be a problem for a lot of users. Microsoft Authenticator has been one of the best password managers for years. You were able to save passwords, enable two-factor authentication and auto-fill. This change means that if you're using the Authenticator app as a password manager, you'll need to look for another option soon. At the same time,

OpenAI Seeks Additional Capital From Investors as Part of Its $40 Billion Round

OpenAI is seeking capital from new and existing investors, two people familiar with the company’s plans tell WIRED. The fundraising effort is part of a $40 billion round announced in March. The round will reopen on Monday, July 28, according to one of the sources, who has direct knowledge of the fundraising effort. The $40 billion round announced earlier this year brought OpenAI’s valuation up to $300 billion, making it one of the most highly valued private startups in history. The round was le

Microsoft announces Surface Laptop 5G for Business

Microsoft has unveiled a new Surface Laptop 5G as part of its computing collection for business customers. The company said that a 5G option was in the works for its business line back in January when it unveiled other updates to the Surface Pro and Surface Laptop for Business, and this requested feature is intended to make the laptop an option that's both portable and connected. With a system of six internal antennas, the Surface 5G should be able to transition smoothly between WiFi and cellula

Coyote malware abuses Windows accessibility framework for data theft

A new variant of the banking trojan 'Coyote' has begun abusing a Windows accessibility feature, Microsoft's UI Automation framework, to identify which banking and cryptocurrency exchange sites are accessed on the device for potential credential theft. Microsoft UIA is a Windows accessibility framework designed to allow assistive technologies to interact with, inspect, and control user interface (UI) elements in applications. Windows apps expose their UI elements through a UI Automation tree, a

Microsoft's new Surface Laptop 5G can be your new hotspot with six antennas

Kyle Kucharski/ZDNET Microsoft just announced another version of its Surface Laptop: this time, with 5G connectivity. The Surface Laptop 5G is a 13.8-inch laptop powered by Intel Core Ultra (Series 2) chips and an integrated 5G modem designed for business users to stay permanently connected. It comes with both NanoSIM and eSIM options, and Microsoft says it's compatible with over 100 mobile operators worldwide. Also: This split keyboard offers deep customization - if you're willing to go all

Microsoft’s new Intel-powered Surface Laptop 5G arrives in August

is a senior editor and author of Notepad , who has been covering all things Microsoft, PC, and tech for over 20 years. Microsoft announced a new 5G version of its Surface Laptop today, which will start shipping on August 26th starting at $1,799.99. The Surface Laptop 5G is powered by Intel’s Core Ultra Series 2 processors, complete with an NPU capable of providing access to Microsoft’s latest Copilot Plus AI features. The Surface Laptop 5G is very similar to the existing 13.8-inch Surface Lapt

Microsoft says Chinese hacking groups are behind SharePoint attacks

Some of the attacks that targeted organizations using an exploit in Microsoft’s SharePoint server platform over the last few days have been linked to hacking groups affiliated with the Chinese government, according to a new Microsoft security blog. “As of this writing, Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon, exploiting these vulnerabilities targeting internet-facing SharePoint servers,” Microsoft said on Tuesday. “In addition, we have obse

Microsoft says Chinese hacking groups exploited SharePoint vulnerability in attacks

Microsoft CEO Satya Nadella speaks during an event commemorating the 50th anniversary of the company at Microsoft headquarters in Redmond, Washington, on April 4, 2025. Microsoft Corp., determined to hold its ground in artificial intelligence, will soon let consumers tailor the Copilot digital assistant to their own needs. Microsoft on Tuesday said Chinese hacking groups were part of the recent attacks on its SharePoint collaboration software. As early as July 7, the Chinese nation-state actor

Google, Microsoft say Chinese hackers are exploiting SharePoint zero-day

Security researchers at Google and Microsoft say they have evidence that hackers backed by China are exploiting a zero-day bug in Microsoft SharePoint, as companies around the world scramble to patch the flaw. The bug, known officially as CVE-2025-53770 and discovered last weekend, allows hackers to steal sensitive private keys from self-hosted versions of SharePoint, a software server widely used by companies and organizations to store and share internal documents. Once exploited, an attacker

Microsoft links Sharepoint attacks to Chinese hacking groups

Several hacking groups with ties to the Chinese government have been linked to a recent wave of widespread attacks targeting a Microsoft SharePoint zero-day vulnerability chain. They used this exploit chain (dubbed "ToolShell") to breach dozens of organizations worldwide after hacking into their on-premise SharePoint servers. "Microsoft has observed two named Chinese nation-state actors, Linen Typhoon and Violet Typhoon exploiting these vulnerabilities targeting internet-facing SharePoint serv

Microsoft just upgraded Sentinel with an AI-powered data lake - here's how it works

NurPhoto/Contributor/Getty Microsoft is launching a new agentic AI system to help cybersecurity professionals manage and protect their organizations' data, the company said Tuesday. Microsoft Sentinel, a proprietary Security Incidents and Event Management (SEIM) platform, which debuted in 2019, now comes with a data lake -- that is, a centralized repository that can store structured and unstructured data without any kind of reformatting. Also: Microsoft fixes two SharePoint zero-days under at

Microsoft: Windows Server KB5062557 causes cluster, VM issues

Microsoft is asking businesses to reach out for support to mitigate a known issue causing Cluster service and VM restart issues after installing this month's Windows Server 2019 security updates. As the company explains in a private advisory seen by BleepingComputer, the Cluster service (a system component essential to cluster operation) might fail to function correctly after installing the KB5062557 update released on July 8th. The same bug is also causing some nodes to fail when attempting t