Recent Advisories

Severity ID Title Vendor Product Date Type
NONE MSSECURE:C7FCC0...

Defense in depth for autonomous AI agents_MSSECURE:C7FCC0B6AA7826584F18F54114B7939D

**Designing Secure Autonomous AI Agents with Defense in Depth** AI agents are moving beyond assistance and into action. Instead of generating cont...

N/A N/A MSSECURE
NONE MSSECURE:3BA43D...

Accelerating detection engineering using AI-assisted synthetic attack logs generation_MSSECURE:3BA43DCBEDD84DB22B6C8EA566684C84

In this article 1. Core Idea: From TTPs to Logs 2. Approaches for Synthetic Attack Log Generation 3. Evaluation Datasets 4. References 5...

N/A N/A MSSECURE
CRITICAL 9.8 MSSECURE:D246AB...

Defense at AI speed: Microsoft’s new multi-model agentic security system finds 16 new vulnerabilities_MSSECURE:D246AB97878596EA9B4013EF42AA93C8

In this article 1. AI-powered vulnerability discovery at hyper-scale 2. Codename: MDASH—Microsoft Security’s new multi-model agentic scanning ...

N/A N/A MSSECURE
NONE MSSECURE:F4DE49...

Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise_MSSECURE:F4DE49F6FA4A319994197035610CE5CA

In this article 1. Abuse of trusted relationships as an attack delivery mechanism 2. Methods, tools, and access strategies 3. Campaign concl...

N/A N/A MSSECURE
NONE MSSECURE:1E1F0D...

Defending consumer web properties against modern DDoS attacks_MSSECURE:1E1F0DDA3E9764C59FE3499A57784F0A

If you own, create, or maintain online services and web portals, you’re probably aware of the dramatic upswing in DDoS attacks on your domains. AI ...

N/A N/A MSSECURE
HIGH 7.8 MSSECURE:8C2178...

Active attack: Dirty Frag Linux vulnerability expands post-compromise risk_MSSECURE:8C217884A3B1C6B484BE2751D3AA5309

In this article 1. Why Dirty Frag matters 2. Technical overview 3. Exploitation scenarios 4. Mitigation guidance 5. Post-mitigation inte...

N/A N/A MSSECURE
CRITICAL 9.9 MSSECURE:4E20DB...

When prompts become shells: RCE vulnerabilities in AI agent frameworks_MSSECURE:4E20DBAC465767E4D354336F2963D674

In this article 1. A representative case study: Semantic Kernel 2. CVE-2026-26030: In-Memory Vector Store 3. CVE-2026-25592: Arbitrary file ...

N/A N/A MSSECURE
NONE MSSECURE:C568AE...

World Passkey Day: Advancing passwordless authentication_MSSECURE:C568AED983EC256C681DD39A01B139D5

World Passkey Day is a chance to reflect on progress toward a shared goal: reducing our reliance on passwords and other phishable authentication me...

N/A N/A MSSECURE
NONE MSSECURE:3E3C74...

​​Microsoft named an overall leader in KuppingerCole Analyst’s 2026 Emerging AI Security Operations Center (SOC) report ​​_MSSECURE:3E3C749A29842233B6F93E6E21E693D8

Security operations are entering a new phase. As attack techniques grow faster and more complex, the effectiveness of a SOC depends less on collect...

N/A N/A MSSECURE
NONE MSSECURE:B9774A...

ClickFix campaign uses fake macOS utilities lures to deliver infostealers_MSSECURE:B9774A5238ABF9F8F6DE190012C0F965

Microsoft researchers continue to observe the evolution of an infostealer campaign distributing ClickFix‑style instructions and targeting macOS use...

N/A N/A MSSECURE