Security


Closeup of futuristic fabric

Microsoft Dials Back Copilot, Pledges Windows 11 Quality Overhaul

Microsoft is hitting the brakes on its aggressive Copilot push in Windows 11, promising a sweeping quality overhaul that puts performance and reliability ahead of AI feature expansion .

Study: AI Adoption Forces Trade-Off Between Speed and Identity Security

AI adoption is forcing companies to trade security for speed -- and identity controls are the first casualty.

CISA, Microsoft Outline Intune Safeguards After Stryker Cyber Attack

The Cybersecurity and Infrastructure Security Agency is urging U.S. organizations to strengthen security around Microsoft Intune and other endpoint management platforms after a cyberattack on medical technology giant Stryker Corp. disrupted operations and contributed to surgery delays at hospitals nationwide.

Mossad/Not-Mossad: Preparing for Nation-State Cyber Threats

As geopolitical tensions escalate and nation-state cyberattacks increase, organizations must adopt an "assume breach" mindset and strengthen disaster recovery planning -- including preparing for physical threats to cloud infrastructure.

Color Wave

Microsoft Pushes Copilot Into Action Mode With Cowork, Adds AI Security and Model Catalog Upgrades

Microsoft rolled out a trio of AI updates this week, spanning Microsoft 365 Copilot, Security Copilot and Microsoft Foundry.

Hackers Don't Break in Anymore -- They Log In

Hackers are shifting their focus from "breaking in" to "logging in," according to the inaugural Cloudflare Threat Report, released in early March.

Microsoft March Patch Tuesday: 8 Critical Bulletins and 2 Zero-Days

Microsoft's March 2026 Patch Tuesday includes fixes for 83 vulnerabilities affecting Windows, Office, SQL Server, Azure and .NET.

GitHub Abuse Emerges in Twin Social Engineering Campaigns Spotted by Fortra, Trend Micro

Security researchers are tracking two separate GitHub-related threat campaigns that use the platform's infrastructure in different ways -- one to deliver vishing lures through legitimate GitHub notifications, and another to push Windows users toward malware-infected downloads hosted through deceptive GitHub Pages and repositories.

Signed Malware Impersonating Workplace Apps Used To Deploy RMM Backdoors

Microsoft's Defender Security Research Team has identified a series of phishing campaigns in which an unknown attacker used digitally signed malware masked as common workplace applications to deploy remote monitoring and management tools as persistent backdoors on targeted systems.

Microsoft Advances Windows 11 Beta Build, Expands Enterprise 5G Management with Ericsson Partnership

Microsoft this week moved forward on two parallel tracks of its Windows strategy, releasing a new Windows 11 Beta Channel preview while unveiling an enterprise-focused 5G laptop management partnership with Ericsson aimed at simplifying connectivity oversight for IT departments.

Microsoft Addresses 6 Actively Exploited Zero-Days in February's Patch Tuesday

Microsoft's February Patch Tuesday release addresses 58 vulnerabilities across Windows, Office and several other products, with six zero-day flaws highlighting the monthly release.

Microsoft Warns of Active SolarWinds Web Help Desk Exploitation

Microsoft's Defender Security Research Team has observed threat actors actively exploiting internet-exposed SolarWinds Web Help Desk instances in multi-stage intrusions that led to lateral movement toward high-value assets within targeted organizations.

Microsoft is Rolling Out New Security Messaging for Teams

Microsoft is adding security warning messages in Teams for organizations using default configurations, a move the company says is part of its Secure By Default initiative and aimed at increasing user awareness of potentially risky files and links without changing existing enforcement policies.

Gallot Returns to Microsoft to Lead Security as Bell Takes on Quality Initiative

Microsoft announced a leadership shake-up Wednesday that will see Hayete Gallot return to the company as executive vice president of security, replacing Charlie Bell, who is shifting into a new role focused on Microsoft’s Quality Excellence Initiative.

Russian Hackers Continue Exploiting Microsoft Office Zero-Day After Emergency Patch

Microsoft issued an out-of-band security update on Jan. 26 to address CVE-2026-21509, a Microsoft Office vulnerability the company said was being actively exploited at the time of disclosure.

Cloud Complexity Is Outstripping Security Defenses

The 2026 Cloud Security Report from Fortinet finds cloud security teams are less concerned about whether cloud platforms can be secured and more focused on whether their defenses can keep pace with the speed of change.

Office 365 Email Outage Highlights Limits of Cloud Resilience Planning

A recent Exchange Online disruption tied to Microsoft network changes underscores how deeply businesses still rely on email -- and how few practical options organizations have to protect critical workflows when cloud services fail.

Encryptionless Extortion Rises as Ransomware Groups Shift Tactics in 2025

Ransomware attacks continued to climb in 2025 as attackers increasingly timed operations around year-end staffing gaps and shifted away from traditional file encryption.

Microsoft Releases Emergency Fix for Azure Virtual Desktop, Windows 365 Authentication Failures

Microsoft released an out-of-band update Friday to resolve credential authentication failures affecting Azure Virtual Desktop and Windows 365 connections that emerged after the company's January 2026 security update.

Microsoft Rolls Out Security Baseline for Microsoft 365 Apps, Teams Admin Center Trust Features

Microsoft released a pair of security and compliance updates this week designed to help IT administrators strengthen protections across Microsoft 365 Apps for enterprise and simplify app governance in Teams.

Subscribe on YouTube