Security


Microsoft Issues Second Biggest Patch Tuesday Ever in April

Microsoft this week released one of the largest Patch Tuesday bundles in its history, delivering fixes for 163 new Microsoft CVEs in a month that includes three zero-days and eight Critical-rated vulnerabilities.

Microsoft Flags Fast-Moving Ransomware, Router-Based Espionage Threats

Microsoft is warning organizations about two active cybersecurity threats: a fast-moving ransomware campaign and a Russian espionage operation that abuses small office and home office routers to monitor victims' network traffic.

Red Petal Closeup Graphic

Hackers Use AI to Bypass Passwords in Large Scale Phishing Attack

Microsoft this week says it has uncovered a large-scale, sophisticated AI-driven phishing campaign that uses automation and legitimate authentication processes to compromise accounts more effectively than traditional phishing attacks.

Microsoft, RSA Make Dual Authentication Moves at RSAC 2026

Two of the bigger authentication announcements to come out of the RSA Conference this week both point in the same direction: organizations need a more flexible, unified approach to identity security, especially as AI agents start acting alongside human workers.

Rubrik Ties Microsoft Defender to Identity Recovery to Cut Response Times to Hours

Rubrik unveiled a new integration with Microsoft Defender at RSAC 2026, linking real-time identity threat detection with automated rollback and recovery capabilities.

Closeup of futuristic fabric

Microsoft Dials Back Copilot, Pledges Windows 11 Quality Overhaul

Microsoft is hitting the brakes on its aggressive Copilot push in Windows 11, promising a sweeping quality overhaul that puts performance and reliability ahead of AI feature expansion .

Study: AI Adoption Forces Trade-Off Between Speed and Identity Security

AI adoption is forcing companies to trade security for speed -- and identity controls are the first casualty.

CISA, Microsoft Outline Intune Safeguards After Stryker Cyber Attack

The Cybersecurity and Infrastructure Security Agency is urging U.S. organizations to strengthen security around Microsoft Intune and other endpoint management platforms after a cyberattack on medical technology giant Stryker Corp. disrupted operations and contributed to surgery delays at hospitals nationwide.

Mossad/Not-Mossad: Preparing for Nation-State Cyber Threats

As geopolitical tensions escalate and nation-state cyberattacks increase, organizations must adopt an "assume breach" mindset and strengthen disaster recovery planning -- including preparing for physical threats to cloud infrastructure.

Color Wave

Microsoft Pushes Copilot Into Action Mode With Cowork, Adds AI Security and Model Catalog Upgrades

Microsoft rolled out a trio of AI updates this week, spanning Microsoft 365 Copilot, Security Copilot and Microsoft Foundry.

Hackers Don't Break in Anymore -- They Log In

Hackers are shifting their focus from "breaking in" to "logging in," according to the inaugural Cloudflare Threat Report, released in early March.

Microsoft March Patch Tuesday: 8 Critical Bulletins and 2 Zero-Days

Microsoft's March 2026 Patch Tuesday includes fixes for 83 vulnerabilities affecting Windows, Office, SQL Server, Azure and .NET.

GitHub Abuse Emerges in Twin Social Engineering Campaigns Spotted by Fortra, Trend Micro

Security researchers are tracking two separate GitHub-related threat campaigns that use the platform's infrastructure in different ways -- one to deliver vishing lures through legitimate GitHub notifications, and another to push Windows users toward malware-infected downloads hosted through deceptive GitHub Pages and repositories.

Signed Malware Impersonating Workplace Apps Used To Deploy RMM Backdoors

Microsoft's Defender Security Research Team has identified a series of phishing campaigns in which an unknown attacker used digitally signed malware masked as common workplace applications to deploy remote monitoring and management tools as persistent backdoors on targeted systems.

Microsoft Advances Windows 11 Beta Build, Expands Enterprise 5G Management with Ericsson Partnership

Microsoft this week moved forward on two parallel tracks of its Windows strategy, releasing a new Windows 11 Beta Channel preview while unveiling an enterprise-focused 5G laptop management partnership with Ericsson aimed at simplifying connectivity oversight for IT departments.

Microsoft Addresses 6 Actively Exploited Zero-Days in February's Patch Tuesday

Microsoft's February Patch Tuesday release addresses 58 vulnerabilities across Windows, Office and several other products, with six zero-day flaws highlighting the monthly release.

Microsoft Warns of Active SolarWinds Web Help Desk Exploitation

Microsoft's Defender Security Research Team has observed threat actors actively exploiting internet-exposed SolarWinds Web Help Desk instances in multi-stage intrusions that led to lateral movement toward high-value assets within targeted organizations.

Microsoft is Rolling Out New Security Messaging for Teams

Microsoft is adding security warning messages in Teams for organizations using default configurations, a move the company says is part of its Secure By Default initiative and aimed at increasing user awareness of potentially risky files and links without changing existing enforcement policies.

Gallot Returns to Microsoft to Lead Security as Bell Takes on Quality Initiative

Microsoft announced a leadership shake-up Wednesday that will see Hayete Gallot return to the company as executive vice president of security, replacing Charlie Bell, who is shifting into a new role focused on Microsoft’s Quality Excellence Initiative.

Russian Hackers Continue Exploiting Microsoft Office Zero-Day After Emergency Patch

Microsoft issued an out-of-band security update on Jan. 26 to address CVE-2026-21509, a Microsoft Office vulnerability the company said was being actively exploited at the time of disclosure.

Subscribe on YouTube