Kategorie
GhostLock Exposes an Uncomfortable Truth About Open Source Security
You Don't Have to Run an Exploit to Know If You're Vulnerable
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
How Linux Security Teams Spot Vulnerabilities Before CVEs Are Published
Microsoft Entra ID gets passkeys default authentication starting September
New phishing kits target Microsoft 365 accounts, evade MFA
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
Study of 85 Crypto Wallet Extensions Finds Address Leaks and Cross-Site Tracking Risks
SAP warns of critical flaws in NetWeaver and Commerce Cloud
How Pentera Turns AI Security Workflows into Validation Engines
How Pentera Turns AI Security Workflows into Validation Engines
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
With its latest layoffs, Microsoft goes all in on AI
Microsoft’s big lead over AI competitors like Google and others has vanished, and the company is now playing catch-up. As a result, Microsoft’s stock has tanked in the last year — down roughly 23% compared to a year ago, due mainly to its massive AI spending and an inability to monetize Copilot.
The company clearly needs to do something. And last week it did, though not what you might expect. It laid off 4,800 people, a little more than 2% of its worldwide workforce, with its Xbox division hit hardest. And it’s not reducing its massive spending on AI data centers or other AI-related costs.
The New York Times explained the cuts this way: “It is Microsoft’s latest employee culling as it plows tens of billions of dollars into the infrastructure for building artificial intelligence.”
Was cutting back on gaming (while still going all-in on AI) the right move for Microsoft? To answer that, let’s take a look at the details of the company’s July layoffs.
A year of layoffsThe recent cuts come in the wake of larger Microsoft workforce reductions over the last year or so. In May 2025, the company laid off 6,000 employees, about 3% of its workforce. Then a few months later, it laid off 9,000 more, about 4% of its workers. In both rounds of cuts, the company’s gaming division was hit — though it wasn’t the primary target.
This year, in April and May, the company rolled out its first voluntary retirement program for US employees. Approximately 3,000 people took the money and ran.
Then came last week, when Microsoft primarily targeted gaming. When the cuts take full effect over the next year, 2,850 gaming employees will be let go. In addition, Microsoft is cutting loose several of its gaming studio brands, which will become independent companies or be sold to buyers.
The layoffs hit the two remaining gaming studios, Activision Blizzard, which makes the big-selling games Call of Duty and Candy Crush, and ZeniMax Media, which publishes series including Fallout and The Elder Scrolls. Three years ago, in 2023, Microsoft bought Activision Blizzard for $69 billion. That followed its purchase of ZeniMax Media in 2020 for $7.5 billion. Both seemed like sizable acquisitions at the time.
Compared to Microsoft’s AI spending now, they’re chump change.
Follow the moneyA memo sent to employees about the July layoffs by Amy Coleman, Microsoft executive vice president and chief people officer, made clear the layoffs were more about AI than they were about gaming.
Of the cuts, she wrote: “The “why” is this: our business is changing because the world around it is changing. The way technology is built, deployed, and used is transforming faster than at any point in my time here. Our customers’ needs are shifting, the business models that serve them are shifting, and that means the work itself — what we do, where we focus, and how we’re organized — has to transform, too.
“Our customers are navigating this same shift, and they’re counting on us to help them through it.”
That last sentence is an oblique reference to the early July launch of the Microsoft Frontier Company, which will embed 6,000 engineers inside customers’ businesses to help them more effectively deploy AI. The cost: $2.5 billion.
That sounds like a substantial amount of money. But it’s only a drop in the bucket of how much money the company plans to spend on AI. In April, Microsoft told investors it would spend $190 billion on data centers and other AI infrastructure this year, a 60% increase over what it spent last year. At the same time, Microsoft said it would shrink its workforce.
Its latest layoffs are clear-cut evidence of that. It’s also evidence that the company recognizes how badly Xbox has performed, and that it needed to do something about it.
In early June, Microsoft sent a memo to everyone in its Xbox division entitled “Next 100 Days: XBOX Reset.” The memo laid out the problems with its ailing game business and pulled no punches. It noted that beyond the $69 billion the company spent three years ago to buy Activision, “Over the past five years, we have spent over $20 billion on ongoing investments in our content, platform, and hardware subsidy, but our annual revenue has declined nearly half a billion during that time. Going forward, this cannot continue.”
The layoffs and spinoffs were the first steps. They won’t be the last.
There’s no doubt this is just the beginning of Microsoft’s disinvestment in gaming. The issue isn’t just that the company’s investments haven’t paid off. It’s that Microsoft’s AI ambitions are so large and expensive that it can no longer afford to seriously fund gaming.
Ultimately, it was the right thing to do, at least from a business perspective. The future is AI. It’s not in gaming.
So, for the foreseeable future at Microsoft, when it comes to AI — the sky’s the limit. But when it comes to gaming, things look much less rosy.
Microsoft starts testing cleaner Windows Search without ads
Forg365 industrializes Microsoft 365 phishing with AI-generated lures
A newly documented phishing-as-a-service platform distributed through Telegram is lowering the technical barrier to Microsoft 365 account takeovers by giving less-skilled attackers automated tools to evade some authentication controls and retain access after compromise.
The platform, called Forg365, uses AI-assisted lure creation alongside device-code abuse and adversary-in-the-middle techniques, according to research published by security company ZeroBEC.
Forg365 was offered with a five-day free trial, followed by subscriptions priced at $400 per month or $3,800 per year, the researchers said.
Customers can build phishing lures and control email delivery through a single operator panel. They can also manage captured account data and monitor compromised Microsoft 365 mailboxes. The service includes templates that impersonate widely used business platforms such as DocuSign, Adobe Acrobat Sign, SharePoint, and OneDrive.
“Phishing-as-a-service has been around for quite a few years,” said Jonathan Ong, senior analyst for managed security services at Omdia. “But the degree to which AI is integrated into Forg365 and enables users is what makes it concerning.”
Forg365’s significance lies in the industrialization and productization of the operator workflow, according to Devashri Datta, a cybersecurity researcher. “It integrates AI-assisted lure creation, evasion, and post-compromise mailbox operations into a subscription service distributed through Telegram,” Datta said.
How Forg365 worksZeroBEC said the campaign it investigated began with an email built around a business-document and remittance-approval pretext. The message relied on legitimate cloud and email services before sending the recipient through several redirects.
Forg365 classified visitors before deciding whether to display a device-code phishing page, an adversary-in-the-middle flow, or a harmless decoy.
In the device-code attack, the victim is directed to a legitimate Microsoft authentication process and persuaded to enter a code that authorizes a session controlled by the attacker. The involvement of genuine Microsoft infrastructure can make the request appear credible.
The platform can also relay authentication through an adversary-in-the-middle attack and capture session information. ZeroBEC said suspicious visitors were diverted to a benign page, helping the operators conceal the phishing flow from researchers and automated security tools.
Complicating incident responseA browser extension called ForgCookie allows attackers to generate and refresh Microsoft single sign-on cookies from their own browsers, ZeroBEC said.
Forg365 also advertises tools for keeping sessions active and monitoring a compromised inbox. Read-only access to the mailbox can then be shared through a password-protected link.
As a result, resetting a password may not remove the attacker. Stolen refresh-token material or an attacker-controlled session could remain usable after the password is changed. Any devices registered during the compromise must also be investigated.
“CISOs should treat two controls as co-equal priorities rather than sequential ones,” Datta said, referring to tightly restricting device-code authentication and deploying phishing-resistant MFA such as FIDO2 or WebAuthn passkeys.
Organizations that do not require device-code authentication should consider blocking it in Microsoft Entra ID, said Keith Prabhu, founder and CEO of Confidis. This can disrupt the device-code component of a Forg365 campaign, although it would not stop attacks that rely on adversary-in-the-middle techniques or stolen session cookies.
Companies that still depend on device-code authentication should identify legitimate uses before imposing a broader restriction. Exceptions may be needed for some command-line tools, conference-room systems or other devices with limited input capabilities.
Deploying phishing-resistant authentication may also require hardware security keys or managed smartphones and could increase support requests during the transition, Datta said.
After detecting a compromise, response teams should revoke active refresh tokens and terminate existing sessions. Prabhu also recommended reviewing and revoking unauthorized OAuth permissions. Because ForgCookie runs in the attacker’s browser, defenders should look for repeated silent sign-ins and non-interactive Microsoft Graph activity from unfamiliar addresses, according to ZeroBEC.
Mailbox forwarding rules and delegated access should be reviewed for unauthorized changes, Prabhu said. Such changes could allow attackers to monitor communications or retain access after a password reset.
“IR teams should audit newly registered devices and remove any that cannot be attributed to the user,” Datta said. Teams should also check whether an attacker enrolled an unauthorized authenticator application or passkey during the compromise, she added.
ZeroBEC found that some devices registered during its investigation had names beginning with “Forg365,” giving defenders a possible indicator of compromise.
The article originally appeared on CSO.
US sanctions VPN, malware providers for enabling ransomware attacks
- « první
- ‹ předchozí
- …
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- …
- následující ›
- poslední »



