LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
security

Microsoft extends the Outlook naughty step with two more file types

Microsoft is implementing new security measures for Outlook, adding two file types, .msix and .msixbundle, to its default block list for attachments. These file types are associated with Windows application packages and bundles. The change is set to affect users of the New Outlook for Windows client and Outlook on the Web within Exchange Online.

ZeroDay News ·

Source: The Register — Security

Microsoft is implementing new security measures for Outlook, adding two file types, .msix and .msixbundle, to its default block list for attachments. These file types are associated with Windows application packages and bundles. The change is set to affect users of the New Outlook for Windows client and Outlook on the Web within Exchange Online.

The update, which Microsoft states is part of its ongoing efforts to enhance security, aims to protect organizations from potentially unsafe file attachments. Starting in early to mid-November 2026, users of the affected clients will be prevented from downloading or opening attachments with these extensions by default.

While Microsoft noted that these file types are "infrequently used," legitimate scenarios exist for their transmission via email. Administrators who require the ability to send or receive these attachments can preemptively configure their systems by adding the .msix and .msixbundle extensions to the `AllowedFileTypes` property within the relevant `OwaMailboxPolicy` before the rollout takes effect.

The decision to block these file types follows previous security concerns related to Microsoft's application packaging system. In December 2023, Microsoft disabled the `ms-appinstaller` protocol handler by default after it was exploited by attackers to distribute malware. The current attachment block serves as an additional layer of protection against similar threats.

Other file types already blocked by Outlook on the Web include .py for Python scripts, .ps1 for PowerShell scripts, and .cab files. While the new block enhances security, it is acknowledged that threat actors might attempt to circumvent the restriction by renaming file extensions or providing download links, though such methods do not mitigate the inherent risks of malicious packages. Persuading users to download and install such packages remains a potential vector for compromise, even with existing Windows security features.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Mitigate Risks of AI-Generated Apps by Citizen Coders

The increasing use of AI tools by non-technical employees, often referred to as "citizen coders," to develop workplace applications presents significant security and data risks for organizations. While these AI-generated applications can boost productivity and streamline workflows, their rapid creation without proper oversight can lead to "shadow AI" assets with critical vulnerabilities,…

patch

ClickFix Attack Hides VBScript Payload in Browser Cache

A new "ClickFix" social engineering campaign has been identified that leverages browser caches to conceal malicious VBScript payloads. The technique, detailed by Microsoft Threat Intelligence on October 3, involves compromised websites pre-fetching a script disguised as an image into a visitor's browser cache. This allows the payload to be present on the victim's device before they are tricked…

CVE-2026-86360critical

Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access

Dell has issued an urgent advisory to customers, recommending they patch a critical vulnerability in its System Update (DSU) tool that could allow attackers to gain root access on affected PowerEdge servers. The flaw, identified as CVE-2026-86360, carries a CVSS score of 9.6, indicating its severe potential impact.

CVE-2026-21589critical

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical vulnerability has been reported in eight Atlassian Data Center products, enabling unauthenticated attackers to read known files within the web application root directory. The flaw, identified as CVE-2026-21589, was disclosed by Atlassian on October 5th and carries a CVSS rating of 9.3 out of 10, indicating its severe impact and ease of exploitation.

breach

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The U.S. Federal Bureau of Investigation (FBI) has reportedly removed an Accenture contractor following an alleged security failure that contributed to a data breach attributed to the ShinyHunters threat group. This incident is said to have resulted in the theft of personal details belonging to thousands of FBI employees. The reported cause of the breach was a patch failure.

malware

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

Fortinet's FortiGuard Labs has detailed a new Linux backdoor, dubbed ClingSTUN, which leverages legitimate public Session Traversal Utilities for NAT (STUN) infrastructure to mask its command and control (C2) communications. The malware primarily targets unpatched Internet of Things (IoT) devices, functioning as a back-connect proxy that turns compromised systems into remotely controlled nodes.