Microsoft

CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability

Microsoft Security Center Center News - Thu, 08/06/2026 - 14:00
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-56161 Azure Logic Apps Information Disclosure Vulnerability

Microsoft Security Center Center News - Thu, 08/06/2026 - 14:00
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
Categories: Microsoft

CVE-2026-62830 Azure SRE Agent Elevation of Privilege Vulnerability

Microsoft Security Center Center News - Thu, 08/06/2026 - 14:00
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-65667 Microsoft Teams Elevation of Privilege Vulnerability

Microsoft Security Center Center News - Thu, 08/06/2026 - 14:00
Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-56162 Azure SQL Database Elevation of Privilege Vulnerability

Microsoft Security Center Center News - Thu, 08/06/2026 - 14:00
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-50515 Azure Service Bus Remote Code Execution Vulnerability

Microsoft Security Center Center News - Thu, 08/06/2026 - 14:00
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-62869 Azure Entra ID Spoofing Vulnerability

Microsoft Security Center Center News - Thu, 08/06/2026 - 14:00
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
Categories: Microsoft

CVE-2026-63522 Azure SQL Database Elevation of Privilege Vulnerability

Microsoft Security Center Center News - Thu, 08/06/2026 - 14:00
Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.
Categories: Microsoft

CVE-2026-63508 Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability

Microsoft Security Center Center News - Thu, 08/06/2026 - 14:00
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-62873 Microsoft 365 Admin Center Elevation of Privilege Vulnerability

Microsoft Security Center Center News - Thu, 08/06/2026 - 14:00
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.
Categories: Microsoft

CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability

Microsoft Security Center Center News - Thu, 07/30/2026 - 14:00
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability

Microsoft Security Center Center News - Thu, 07/30/2026 - 14:00
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Categories: Microsoft

Chromium: CVE-2026-13037 Use after free in WebView

Microsoft Security Center Center News - Tue, 07/28/2026 - 22:03
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-13032 Use after free in WebGL

Microsoft Security Center Center News - Tue, 07/28/2026 - 22:03
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-13030 Uninitialized Use in GPU

Microsoft Security Center Center News - Tue, 07/28/2026 - 22:03
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Chromium: CVE-2026-13028 Use after free in WebGL

Microsoft Security Center Center News - Tue, 07/28/2026 - 22:03
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.
Categories: Microsoft

Looking back on Microsoft’s FY26: From AI experimentation to Frontier Transformation

Microsoft News - Tue, 07/28/2026 - 16:00

Throughout this past fiscal year, customers across every industry and segment moved from AI experimentation to deploying AI for real-world business outcomes. They unlocked innovation and created new opportunities for growth. We saw the emergence of Frontier Firms as they moved beyond efficiency gains to focus on human ambition and embed AI at the core of how they operate. Successful customers are building an intelligence platform so their unique IQ — their knowledge, data, workflows, applications and expertise — can continuously compound, ensuring the value of AI accrues to the customer, not the model. They have a trust platform that is pervasive, with the ability to manage, govern, secure and measure AI across every business process.

Everything we are doing at Microsoft is empowering Frontier Transformation: Copilot enables AI in the flow of human ambition, Microsoft IQ amplifies and protects an organization’s IQ and Agent 365 is the trust platform that enables observability at every layer of the stack.

Businesses are not static, and neither are the AI systems that support them. As organizations evolve, AI systems must continuously learn and improve. Agentic workflows need to be built, observed and tuned against the outcomes organizations seek and the ROI they demand. Microsoft’s open, model-diverse and heterogenous platform powers that improvement loop. We also recently announced Microsoft Frontier Company, bringing our AI engineering approach to customers around the world to help them build these AI systems to accelerate measurable business outcomes.

Throughout the past year, we saw customers put these capabilities to work in powerful ways — embedding AI into core business processes, building agentic systems, strengthening security, accelerating innovation and creating new sources of value. The stories below highlight organizations leading Frontier Transformation, demonstrating how intelligence, trust and human ambition come together across industries.

To advance its journey to become a global AI-powered company, Atos Group deployed Microsoft 365 Copilot to 56,000 employees across 54 countries — from consultants to engineers to frontline workers — and was one of the first organizations globally to adopt Microsoft 365 E7: The Frontier Suite. Using Microsoft Foundry, Microsoft Copilot Studio and Agent 365, Atos is building, operating and governing a growing ecosystem of 19,000 AI agents through a unified operating model that brings together productivity, security, compliance and agent governance. As Atos embeds secure agentic AI across its workforce, the company is creating a repeatable model to continuously improve thousands of agents at scale while applying the same playbook to help customers accelerate adoption across highly regulated industries.

Facing state-sponsored threats and complex global operations, ASM is strengthening cyber resilience with Microsoft Security Copilot, helping protect the intellectual property behind advanced semiconductor manufacturing. By bringing threat investigations into a unified AI-powered experience, ASM enables analysts to investigate incidents faster, apply consistent decision-making across global operations and accelerate the development of cybersecurity talent. The company reduced incident triage time by 68%, cut laptop compromise investigations from 25 minutes to eight and now saves 337 hours each week on investigations while redeploying 20% of its security operations staff to governance, risk and compliance initiatives.

Banco Popular Dominicano, the largest private-sector bank in the Dominican Republic, transformed operational risk management from periodic, sample-based reviews into continuous, AI-powered supervision. Using AURA — an ecosystem of specialized agents built on Microsoft Copilot Studio and Microsoft Power Platform — the bank monitors 100% of its operational risk universe in real time, up from roughly 40% coverage, and can automatically analyze changes, validate controls and surface issues as they occur. The shift has delivered seven times greater analytical capacity, reduced manual operating effort by 70%, achieved 98% methodological accuracy and enabled continuous processing of approximately 80,000 documents per week and more than 300 cases per day. Just as importantly, risk teams have moved from reacting to problems after the fact to anticipating and preventing deviations before they occur. These results demonstrate the power of AI democratization. By enabling business teams to build intelligent solutions themselves through low-code tools, Banco Popular transformed operational risk management while fostering a culture of innovation led by domain experts.

To help reduce the manual burden for employees while meeting the pharmaceutical industry’s strict data security requirements, Cactus Life Sciences modernized scientific workflows with Microsoft 365 Copilot and agents. The company has deployed more than 30 custom automation agents to streamline document review and structure data extraction and information retrieval across scientific writing and project management teams. Supported by a centralized knowledge repository and the Copilot Champions community, the company reports efficiency improvements of approximately 35% to 50% in structured data extraction. By automating labor-intensive tasks and maintaining human review and quality controls, the company is enabling scientific writers to focus on deeper analysis, synthesis and delivering exceptional science to clients.

Chow Tai Fook is redefining luxury retail with Microsoft 365 E5, Microsoft Purview, Microsoft Azure OpenAI Service, Microsoft Fabric and Microsoft Foundry. The company has deployed over 400 customized AI agents supporting more than 24,000 employees, with millions of AI interactions each month and core business-process efficiency gains exceeding 70%. Through its AI Fook super-agent ecosystem, frontline associates can instantly access product expertise, inventory insights and personalized recommendations, helping drive sales conversion improvements of up to 57% while delivering hyper-personalized omnichannel experiences at scale. With hundreds of AI agents operating across the business, Chow Tai Fook is creating a foundation where customer, product and operational intelligence can be applied across every interaction, helping personalize experiences and improve decision-making across its global retail network.

To accelerate AI adoption, EY moved AI from experimentation into enterprise-wide transformation. After deploying Microsoft 365 Copilot to 150,000 employees and realizing a 15% productivity gain, the firm is expanding the Microsoft 365 Frontier Suite across its global workforce of more than 400,000 people, embedding agentic AI capabilities across the enterprise. As Client Zero, EY is applying Microsoft technologies across its own operations, including Microsoft Power Platform, Microsoft Copilot Studio, Microsoft Azure, Microsoft Foundry and Microsoft Fabric. The results include 95% faster lead times, a more than 37% reduction in finance operating costs and up to a 90% reduction in manual workloads across key business processes.

To reimagine the grocery shopping experience, Grandiose Supermarkets created an AI-powered shopping companion — GrandChef — built on Microsoft Foundry and Azure OpenAI Service. By connecting meal inspiration, recipe discovery and product purchasing into a single experience grounded in live product and inventory data, GrandChef helps shoppers move from intent to purchase faster and with greater confidence. This has led to a 31% increase in conversion, a 20% lift in average basket value and shopping journeys that are 40% faster. Together, these gains are helping Grandiose Supermarkets create more personalized customer experiences while driving measurable business growth. By connecting customer intent, product data and purchasing decisions in a single experience, Grandiose is creating a feedback loop that helps continuously improve recommendations and shopping experiences.

To support audits across its global organization, Grupo Bimbo built two agents with Microsoft Copilot Studio and deployed them through Microsoft 365 Copilot and Microsoft Teams: the result was Audit Assist, an idea generated from a Microsoft-supported internal hackathon and Comatrix. By connecting auditors directly to approved guidance, procedures and templates in SharePoint, the company is helping teams work more efficiently across 39 countries while improving consistency and audit quality. The solution/AI agents reduced planning-phase audit time by 20% and accelerated risk and control matrix creation from days to seconds, enabling auditors to spend less time searching for information and more time on analysis and decision-making. By making approved audit knowledge instantly accessible across its global audit organization, Grupo Bimbo is creating a foundation where expertise can scale with the business — improving consistency, reducing rework and enabling auditors to focus on higher-value analysis and decision-making.

To create a unified foundation for data, automation and AI across its operations in 47 countries, Navien built a connected, intelligent operating model with Microsoft Fabric, Microsoft 365 Copilot, Microsoft Foundry and Microsoft Copilot Studio. By connecting fragmented data and processes across procurement, manufacturing, quality and customer service, the company is enabling more consistent, data-driven decision-making across its operations. Navien saved 28,000 hours annually through AI agents and automation, with 32% of employees using self-service analytics to make decisions without IT support. Through its migration to Azure, it also expects more than 1.4 million in total cost-of-ownership savings over five years. By connecting data, insights and workflows across the business, Navien is enabling faster, more consistent decision-making at scale across its global operations.

NHS England is accelerating AI adoption across the healthcare system with the largest implementation of its kind in the healthcare sector. Following a trial involving 30,000 workers across 90 NHS organizations — where users saved an average of 43 minutes of administrative time per day — NHS England is rolling out Microsoft 365 Copilot to over 500,000 clinicians and support staff. Organizations can use Microsoft Copilot Studio to build and deploy AI agents that streamline clinical, operational and administrative workflows. Through Agent 365, NHS England can govern and scale those agents across the healthcare system while enabling individual trusts to build solutions for local needs — creating a secure framework where agentic workflows can be deployed, managed and expanded consistently to improve service delivery, reduce costs and create more time for patient care.

Novo Nordisk is using AI to help researchers make faster, more quantitative decisions in pharmaceutical R&D. Working with Microsoft’s AI Acceleration Studio within the Forward Deployed Engineering team, the company built a governed reasoning agent on Microsoft Azure with its proprietary dataset, including more than 200,000 patient-years of harmonized clinical trial data, while maintaining rigor, oversight and compliance. The system has expanded the team’s capacity to evaluate potential opportunities from 5 to 10 strong ideas per quarter to more than 50, and the company expects it to reduce time to insight for exploratory analyses from weeks to minutes. By grounding AI in its datasets and governed workflows, Novo Nordisk is helping scientists turn decades of institutional expertise into a reusable intelligence layer that can help accelerate discovery across the organization.

As AI becomes part of investment decision-making, SimCorp is helping financial institutions bring AI into investment workflows without compromising governance, auditability or control. By unifying SimCorp One on Microsoft Azure and leveraging Microsoft Foundry, the company is helping portfolio managers, risk analysts and operations teams access insights faster, automate manual processes and spend more time on higher-value decisions. By standardizing how AI is deployed and governed across global investment operations, SimCorp is creating a foundation for trusted AI at scale, helping organizations embed AI into investment workflows while maintaining the controls required in highly regulated markets. One study found SimCorp One customers realized 134% ROI over three years, improved operational efficiency by 45 percent, saved 10 hours per person per week and accelerated time to market by 50 to 60 days.

Stellantis is accelerating AI-led strategy and digital transformation across its global business, co-developing more than 100 AI initiatives across sales, customer care, product development and operations. By applying AI-powered insights across the business, the automaker is streamlining product development and validation, advancing predictive maintenance and bringing new digital features and services to market faster for customers. Stellantis is also deploying an AI-driven global cyberdefense center to help protect vehicles, customers and operations worldwide while modernizing its infrastructure on Microsoft Azure with a targeted 60% reduction in its datacenter footprint by 2029, powering a more scalable and interconnected digital ecosystem for future digital and connected services and resilient operations.

Facing a growing volume of cyberthreats across a complex healthcare environment, St. Luke’s University Health Network is using Microsoft Security Copilot to help protect the systems clinicians and patients depend on every day. Across 15 campuses, 300 outpatient sites and more than 2.5 petabytes of data and patient records, the organization needed a unified view of threats across a complex environment. Security Copilot connects Microsoft Defender, Microsoft Sentinel, Microsoft Entra, Microsoft Purview and other security tools, helping analysts correlate threats faster, eliminate silos and respond with greater precision. St. Luke’s is saving nearly 200 hours each month in phishing alert triage and creating incident reports in minutes instead of hours, helping security teams focus more time on protecting patient care.

University of Kentucky unified more than 150 AI initiatives across classrooms, research labs, healthcare settings and administrative offices through its CATS AI governance framework. Standardizing on Microsoft’s AI portfolio — including Microsoft 365 Copilot, Microsoft Dragon Copilot, GitHub Copilot and Microsoft Azure — the university achieved campus-wide deployment, providing more than 70,000 students and employees with access to AI capabilities. Clinicians are using Dragon Copilot to reduce documentation burdens and spend more time with patients, and students are using GitHub Copilot to become active builders of digital solutions, such as the Socratic Tutor: an AI-powered learning platform aimed at helping medical students master complex curriculum.

Looking back on FY26, I am inspired not only by the continued pace of AI innovation, but by what our customers are achieving. Across every industry and segment, organizations are turning their unique IQ into strategic advantage with continuously improving agentic workflows. The companies leading this next phase are building, observing and tuning agentic workflows against business outcomes. Intelligence compounds, trust scales and AI can work in the flow of human ambition. As Frontier Firms redefine what is possible with AI, we remain focused on helping our customers amplify and protect their intelligence so they can transform how they operate, compete and grow.

Judson Althoff is the chief executive officer of the commercial business at Microsoft. He is responsible for the product strategy, sales, services, support, marketing, operations and revenue growth of the company’s commercial business, which operates in more than 120 regional and national subsidiaries globally.

The post Looking back on Microsoft’s FY26: From AI experimentation to Frontier Transformation appeared first on The Official Microsoft Blog.

Categories: Microsoft

Rethinking security for the age of AI

Microsoft News - Mon, 07/27/2026 - 16:30

Editor’s note: Updates with additional details on the model’s crash score.

Why security needs a new cyber stack Introducing Project Perception

The physics of cybersecurity are changing. Autonomous systems can now reason, adapt and operate continuously. At the same time, the cost of offense is falling, while the volume, velocity and complexity of what must be secured continues to grow. Attackers can generate exploits faster, scale campaigns further and operate with unprecedented efficiency. The approaches built for a world of human actors cannot keep pace with a world of AI, agents and machine-speed attacks.

Security needs a new cyber stack. A new cyber stack must continuously perceive risk across the entire digital estate, reason across vast amounts of context and take action at machine speed. It must learn and adapt as environments evolve, helping organizations stay ahead of threats. And because security is ultimately a human mission, it must amplify defenders with better insights and more powerful ways to act. The defining characteristic of the next generation of security systems will not be their ability to generate more alerts. It will be their ability to continuously perceive, reason and act.

That vision led us to build Project Perception. A new agentic security system designed for the realities of AI. It turns signals into real-time protections using AI to defend against AI.

Project Perception brings together signals, context, models and specialized agents into a continuously learning system of defense. It can reason, prioritize and act at machine speed while keeping humans firmly in control and empowering them with powerful new workflows.

Project Perception is based on a simple idea: effective defense requires continuous understanding of how an attacker sees the world, how a defender evaluates risk and how protections are improved over time. To accomplish this, Perception coordinates three classes of specialized agents. Red team agents identify potential paths to compromise before an attacker can exploit them. Blue team agents investigate, reason over context and determine what represents meaningful risk. Green team agents take corrective actions and strengthen defenses across the environment. Working together, these agents form a closed-loop system that continuously discovers, evaluates and improves an organization’s security posture.

A system like Project Perception is only as effective as the visibility it has, the actions it can take, the experience of the teams building it and the models it can use. Microsoft brings together all four.

We see across identities, endpoints, applications, data, clouds and AI systems, providing broad visibility across the digital estate. Equally important, we can help customers take action across those environments. Combined with decades of security research, threat intelligence and real-world operational experience defending organizations, these capabilities shape how Project Perception reasons, prioritizes and responds.

Security is a 24/7 mission. Organizations need protection that is highly effective, continuously available and affordable at scale. That requires more than access to the most capable model. It requires applying the right model to the right task. Project Perception adopts a multi-model architecture that combines frontier and specialized cyber models, optimizing for both quality and cost.

As part of this multi-model strategy, we are committed to bringing customers the best models for each security task, including innovating with our own specialized models. The first scenario is software vulnerability management, bringing MAI-Cyber-1-Flash inside MDASH, our software vulnerability multi-model team of agents. MDASH with MAI-Cyber-1-Flashdelivers 96% (any-crash score*) on CyberGym, an industry benchmark. It also outperforms competitors like Mythos on the CyberGym leaderboard. And this same configuration delivers almost 50% of cost savings vs. the current MDASH configuration in market today. That’s the power of a well-tuned, multi-model system with access to uniquely rich historical training data. Next, Project Perception will take advantage of MAI-Cyber-1-Flash for many more security workflows, beyond the software vulnerability scenario.

We are bringing this vision to customers around the world through Project Perception, which enters public preview on August 3.

YouTube Video

Click here to load media A cyber stack built for agentic security

Delivering agentic security requires more than adding agents to existing workflows. It requires a new cyber stack, designed from the ground up.

The stack begins with signals and sensors that provide awareness across the digital estate. Security context transforms those signals into token-efficient understanding that agents can use. Models provide intelligence and reasoning. A harness coordinates models and agents across security workflows. Agents apply that intelligence across security workflows and actuators translate decisions into protection. Together, these layers create a continuous learning system that can understand risk, adapt to changing conditions and improve security outcomes over time.

 

While each layer provides important capabilities, the power of Project Perception comes from how they work together.

Security context built for AI

Effective reasoning requires more than raw signals. Agents need context.

Microsoft transforms its breadth of visibility, threat intelligence and security expertise into a security context that connects security data, knowledge and semantics across the digital estate. The result is a continuously updated representation of an organization’s assets, identities, relationships, risks and activities that gives agents a shared, near real-time, understanding of the environment they are helping to defend.

 

This shared understanding is foundational to how Project Perception operates. Rather than forcing agents to continuously gather, correlate and reconstruct context from raw signals, it provides them with immediate and token-efficient access to the information they need to reason over risk, prioritize actions and make decisions. By grounding every interaction in this rich security context, Project Perception improves the accuracy and consistency of reasoning while reducing the time, compute and cost required to operate at scale.

A multi-model architecture built for security

No single model will be optimal for every security task. Effective cyber defense requires applying the right model to the right problem at the right time.

For Project Perception, the right model is determined by the combination of quality, reliability, latency and cost. Rather than relying on a single model, Project Perception adopts a multi-model architecture that continuously selects the capabilities best suited to the task, optimizing for both effectiveness and economics. Because security is an always-on mission, sustainable economics are essential to operating protection at scale.

This approach is shaped by ongoing research, benchmarking and evaluation across frontier and specialized models. Our security researchers continuously assess models against real-world security workflows, enabling us to match each task with the model that delivers the best outcome. This allows customers to benefit from advances in AI without being tied to any single model.

Actuators — insights to actions

Security teams do not need more information. They need better outcomes.

That is why actuators are a critical part of the cyber stack. Project Perception is deeply integrated across Microsoft Security products, enabling agents to connect insights to actions. Organizations can continuously reduce risk rather than simply identify it, helping defenders strengthen security while remaining in control.

Built with safety first

Underpinning every layer of the cyber stack is a foundation of trust. Project Perception is built in alignment with Microsoft’s Responsible AI principles and inherits the security, compliance, governance and operational controls our customers already rely on. This ensures these capabilities are delivered with the same rigor, accountability and enterprise readiness that customers expect.

The future of security

Security has always been a race between attackers and defenders. AI changes the speed, scale and economics of that race. Defenders need systems that can continuously perceive, reason and act alongside them.

 Project Perception is how we begin to build that future.

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

Other resources:

Hayete Gallot leads Microsoft’s work to help organizations operate securely in an AI-driven world. Her scope includes identity, threat protection, compliance and data security at global scale.

Note: *Any-crash measures the ability of the agent to identify vulnerabilities that can crash the code under evaluation with an input that triggers any existing or 0-day vulnerability. Our 96% score is an any-crash score.

The post Rethinking security for the age of AI appeared first on The Official Microsoft Blog.

Categories: Microsoft

Pages

Subscribe to Geeksultant aggregator - Microsoft