A critical SSRF vulnerability in Microsoft Power Platform’s SharePoint connector allowed attackers to harvest user credentials and impersonate victims, risking severe security breaches across services like Power Apps and Automate. Microsoft patched the flaw (CVE-2024-49070) in December 2024, emphasizing the need for organizations to implement updates, limit user permissions, and monitor suspicious activity.

1 Million Devices Infected by Malwares Hosted on GitHub, Microsoft Warns
In December 2024, Microsoft Threat Intelligence identified a large-scale malvertising campaign (Storm-0408) that infected nearly one million devices globally, targeting both consumer and enterprise sectors