A crafted SVG submitted to Bing image search can execute commands as NT AUTHORITY\SYSTEM on Microsoft’s production servers, impacting multiple hosts with critical security implications.
Microsoft patched a critical SharePoint Server vulnerability, CVE-2026-50522, now actively exploited after a public proof-of-concept was released, enabling remote code execution via deserialization of untrusted data.
Microsoft Threat Intelligence uncovered ShinyHunters abusing OAuth in SaaS applications through vishing, supply chain attacks, and guest access misconfigurations, exposing new SaaS security risks.