CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Microsoft Vibing - capturing screenshots and voice samples without governance

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 586

As cited

Copy frozen at (site build).

cloud saas

Microsoft Vibing - capturing screenshots and voice samples without governance

Microsoft Vibing is an executable distributed through the Microsoft Store that captures user screenshots, clipboard contents, microphone audio, and window metadata, then sends this data to a Microsoft Azure endpoint without explicit user consent or in-app disclosure. The application was developed by Microsoft Research Asia employees but misrepresented as a community or open-source project to bypass internal security and privacy governance reviews. The software auto-starts on Windows login, encodes captured data with machine GUIDs for tracking, and uses WebSocket connections that can evade some proxy configurations.

Why it matters: Windows users and IT teams managing endpoints need to audit whether Vibing is installed and remove it immediately, as it exfiltrates sensitive data including screenshots, audio, and system identifiers to Microsoft infrastructure without proper consent mechanisms or documented data handling policies.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

Microsoft Vibing - capturing screenshots and voice samples without governance

Microsoft Vibing is an executable distributed through the Microsoft Store that captures user screenshots, clipboard contents, microphone audio, and window metadata, then sends this data to a Microsoft Azure endpoint without explicit user consent or in-app disclosure. The application was developed by Microsoft Research Asia employees but misrepresented as a community or open-source project to bypass internal security and privacy governance reviews. The software auto-starts on Windows login, encodes captured data with machine GUIDs for tracking, and uses WebSocket connections that can evade some proxy configurations.

Why it matters: Windows users and IT teams managing endpoints need to audit whether Vibing is installed and remove it immediately, as it exfiltrates sensitive data including screenshots, audio, and system identifiers to Microsoft infrastructure without proper consent mechanisms or documented data handling policies.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

Microsoft Vibing - capturing screenshots and voice samples without governance

Microsoft Vibing is an executable distributed through the Microsoft Store that captures user screenshots, clipboard contents, microphone audio, and window metadata, then sends this data to a Microsoft Azure endpoint without explicit user consent or in-app disclosure. The application was developed by Microsoft Research Asia employees but misrepresented as a community or open-source project to bypass internal security and privacy governance reviews. The software auto-starts on Windows login, encodes captured data with machine GUIDs for tracking, and uses WebSocket connections that can evade some proxy configurations.

Why it matters: Windows users and IT teams managing endpoints need to audit whether Vibing is installed and remove it immediately, as it exfiltrates sensitive data including screenshots, audio, and system identifiers to Microsoft infrastructure without proper consent mechanisms or documented data handling policies.

VendorsMicrosoftGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary