‘SIM Farms’ Are a Spam Plague. A Giant One in New York Threatened US Infrastructure, Feds Say

Credit to Author: Andy Greenberg, Lily Hay Newman, Matt Burgess| Date: Tue, 23 Sep 2025 18:09:18 +0000

The agency says it found a network of some 300 servers and 100,000 SIM cards—enough to knock out cell service in the NYC area. Experts say it mirrors facilities typically used for cybercrime.

Read more

Introducing Microsoft Marketplace — Thousands of solutions. Millions of customers. One Marketplace.

Credit to Author: Alyssa Taylor| Date: Thu, 25 Sep 2025 15:47:32 +0000

To empower customers in becoming Frontier, we’re excited to announce the launch of the reimagined Microsoft Marketplace, your trusted source for cloud solutions, AI apps and agents.

The post Introducing Microsoft Marketplace — Thousands of solutions. Millions of customers. One Marketplace. appeared first on Microsoft Security Blog.

Read more

XCSSET evolves again: Analyzing the latest updates to XCSSET’s inventory

Credit to Author: Microsoft Threat Intelligence| Date: Thu, 25 Sep 2025 15:00:00 +0000

Microsoft Threat Intelligence has uncovered a new variant of the XCSSET malware, which is designed to infect Xcode projects, typically used by software developers building Apple or macOS-related applications.

The post XCSSET evolves again: Analyzing the latest updates to XCSSET’s inventory appeared first on Microsoft Security Blog.

Read more

Retail at risk: How one alert uncovered a persistent cyberthreat​​

Credit to Author: Microsoft Incident Response| Date: Wed, 24 Sep 2025 17:00:00 +0000

In the latest edition of our Cyberattack Series, we dive into real-world cases targeting retail organizations. With 60% of retail companies reporting operational disruptions from cyberattacks and 43% experiencing breaches in the past year, the stakes have never been higher. This post unpacks where a single alert led to the discovery of a major persistent threat, how attackers exploited unpatched SharePoint vulnerabilities and compromised identities to infiltrate networks—and how the Microsoft Incident Response—the Detection and Response Team (DART) swiftly stepped in with forensic insights and actionable guidance. Download the full report to learn more about how one small signal exposed a much larger danger, and how you can strengthen your defenses against similar threats.

The post Retail at risk: How one alert uncovered a persistent cyberthreat​​ appeared first on Microsoft Security Blog.

Read more

AI vs. AI: Detecting an AI-obfuscated phishing campaign

Credit to Author: Microsoft Threat Intelligence| Date: Wed, 24 Sep 2025 12:00:00 +0000

Microsoft Threat Intelligence recently detected and blocked a credential phishing campaign that likely used AI-generated code to obfuscate its payload and evade traditional defenses, demonstrating a broader trend of attackers leveraging AI to increase the effectiveness of their operations and underscoring the need for defenders to understand and anticipate AI-driven threats.

The post AI vs. AI: Detecting an AI-obfuscated phishing campaign appeared first on Microsoft Security Blog.

Read more