Microsoft Defender Security Research Team

Threat Intel
HIGHPHP Webshells - Cookie-Controlled Tactics in Linux Hosting
Hackers are using HTTP cookies to control PHP webshells in Linux hosting environments. This stealthy tactic reduces detection risks, posing significant threats to users. Enhanced security measures are crucial to combat this evolving threat.
Fraud
HIGHOAuth Redirection Exploited for Phishing Attacks
OAuth redirection abuse is being used to deliver phishing attacks. This affects anyone using online services, putting your personal data at risk. Stay safe by checking URLs and enabling two-factor authentication.
Malware & Ransomware
HIGHMalware Uses Stolen Certificate to Bypass Security
A new signed malware is impersonating workplace apps to gain unauthorized access to company networks. This poses serious risks to sensitive data and operations. Organizations must enhance their certificate controls and monitor RMM activities to protect against these threats.