Microsoft Azure AI Foundry CVSS 10.0 Authentication Bypass CVE-2026-85889 and Windows Zero-Day Exploitation
During Microsoft's September 2026 Patch Tuesday, a critical CVSS 10.0 authentication bypass (CVE-2026-85889) was disclosed in the Azure AI Foundry internal management API. This vulnerability allowed unauthenticated network attackers to invoke privileged functions, enabling immediate administrator role escalation. A subsequent chain of five vulnerabilities (CVE-2026-85890 through CVE-2026-85894) facilitated cross-tenant access, session hijacking, and arbitrary code execution within the Foundry sandbox. Concurrently, two Windows zero-day vulnerabilities in win32k.sys (CWE-416) and spoolsv.exe (CWE-120) were observed being actively exploited in the wild for approximately 72 hours before out-of-band patches were released. While the Azure vulnerability was mitigated server-side, immediate client-side patching is required for all Windows systems to prevent kernel-mode exploitation.
Warlock Ransomware Exploits Microsoft SharePoint Vulnerabilities
The Warlock ransomware group is conducting targeted campaigns against critical infrastructure sectors, including energy, water, and healthcare, by exploiting unpatched Microsoft SharePoint vulnerabilities. Attackers utilize CVE-2023-29357 for unauthenticated remote code execution (RCE) and CVE-2022-24521 for privilege escalation. Following initial access, the threat actor deploys webshells for persistence and utilizes living-off-the-land binaries like certutil and bitsadmin for lateral movement. The campaign employs AES-256 and RSA-4096 hybrid encryption coupled with double extortion via data exfiltration to leak sites. Immediate application of SharePoint Cumulative Updates is required to mitigate these high-impact exploitation vectors.
Storm-3168: Rapid Azure Resource Deletion Campaign Targeting Microsoft Azure Subscriptions
Threat actor JADEPUFFER (Storm-3168) conducted a highly automated, destructive campaign against Microsoft Azure tenants using compromised service principals. Initial access was achieved through service principal secrets exposed in public GitHub issue histories. Following a 15-hour reconnaissance phase involving ~300 read-only API calls, the actor executed a seven-minute burst of over 150 destructive operations. This included deleting >100 storage accounts, Azure Key Vaults, SQL databases, and removing Azure Site Recovery and backup protection locks. Post-destruction, the actor attempted credential harvesting via storageAccount/listKeys calls. The attack pattern—combining rapid resource destruction with recovery-impairment tactics—suggests an extortion-focused methodology designed to pressure victims through immediate operational paralysis.
Microsoft Patch Tuesday: Record-Breaking Vulnerability Volume and Active Exploitation
The September 2026 Microsoft Patch Tuesday release addresses a historic 974 CVEs, including over 100 critical vulnerabilities. Of significant concern are two actively exploited zero-day vulnerabilities: CVE-2026-81963 (improper link resolution in the Windows Update Stack) and CVE-2026-85880 (Windows ALPC heap-based buffer overflow), both enabling elevation of privilege and sandbox escapes. Additionally, a CVSS 9.8 RCE in the Windows DNS Server presents a high risk of wormable, infrastructure-wide compromise, reminiscent of the SigRed vulnerability. With 723 vulnerabilities affecting the Windows core and high-severity RCEs in Remote Desktop Services, immediate remediation is critical to prevent lateral movement and widespread perimeter breach.
Microsoft Disrupts EvilTokens AI-Powered Phishing-as-a-Service Campaign
Microsoft, in coordination with law enforcement and industry partners, has dismantled EvilTokens, a Phishing-as-a-Service (PaaS) platform that exploited the Microsoft OAuth 2.0 device-code authentication flow. The campaign compromised over 12,000 Microsoft 365 mailboxes across 10,000 organizations globally by intercepting valid session tokens rather than traditional passwords. The platform utilized an integrated AI chatbot to automate mailbox reconnaissance and Business Email Compromise (BEC) fraud generation. The disruption involved seizing 50 websites and over 150 domains, following the arrest of two UK-based operators. This incident highlights the critical risk of abusing legitimate authentication flows to bypass multi-factor authentication (MFA) and the increasing integration of generative AI into automated cybercrime ecosystems.
Microsoft Copilot Integration of OpenAI GPT-6 Astra
Microsoft is integrating OpenAI's GPT-6 Astra into Copilot Cowork and Copilot Studio, introducing "Work IQ" to enable autonomous high-level task delegation grounded in organizational data. This integration expands the enterprise attack surface by allowing the LLM to access cross-application data—including chats, meetings, and files—creating new vectors for prompt injection and unauthorized data exfiltration. The primary technical risk involves potential privilege escalation where the model's reasoning engine may bypass granular Microsoft 365 permission structures, leading to the exposure of sensitive business intelligence and the execution of unauthorized actions.
Critical Zero-Click RCE in Microsoft Windows TCP/IP CVE-2024-38063
CVE-2024-38063 is a critical remote code execution (RCE) vulnerability within the Microsoft Windows TCP/IP driver (tcpip.sys). The flaw is triggered by specially crafted IPv6 packets containing malformed Hop-by-Hop extension headers, leading to an integer/buffer overflow during packet processing. Because the vulnerability resides at the kernel level and requires no user interaction, it allows unauthenticated attackers to achieve SYSTEM-level code execution. This zero-click vector enables potential wormable exploitation across IPv6-enabled networks, posing a severe risk of full system compromise, lateral movement, and data exfiltration. Immediate application of Microsoft's August 2024 security updates is mandatory to remediate the driver flaw.