Security


Cloud Complexity Is Outstripping Security Defenses

The 2026 Cloud Security Report from Fortinet finds cloud security teams are less concerned about whether cloud platforms can be secured and more focused on whether their defenses can keep pace with the speed of change.

Office 365 Email Outage Highlights Limits of Cloud Resilience Planning

A recent Exchange Online disruption tied to Microsoft network changes underscores how deeply businesses still rely on email -- and how few practical options organizations have to protect critical workflows when cloud services fail.

Encryptionless Extortion Rises as Ransomware Groups Shift Tactics in 2025

Ransomware attacks continued to climb in 2025 as attackers increasingly timed operations around year-end staffing gaps and shifted away from traditional file encryption.

Microsoft Releases Emergency Fix for Azure Virtual Desktop, Windows 365 Authentication Failures

Microsoft released an out-of-band update Friday to resolve credential authentication failures affecting Azure Virtual Desktop and Windows 365 connections that emerged after the company's January 2026 security update.

Microsoft Rolls Out Security Baseline for Microsoft 365 Apps, Teams Admin Center Trust Features

Microsoft released a pair of security and compliance updates this week designed to help IT administrators strengthen protections across Microsoft 365 Apps for enterprise and simplify app governance in Teams.

Microsoft Knocks Offline RedVDS Cybercrime Marketplace Linked to $40M in Fraud

Microsoft said it has disrupted RedVDS, a global cybercrime subscription service used by financially motivated attackers to carry out business email compromise, mass phishing and account takeover campaigns.

Zero-Day Attack Drives 113-Vulnerability Patch Tuesday Release to Start 2026

Microsoft rang in 2026 with its biggest January Patch Tuesday rollout in four years, shipping fixes for 113 vulnerabilities across Windows, Office and other products

New Microsoft Machine Learning Tools Target Alert Fatigue in Defender XDR Platform

Microsoft has begun out new AI-powered incident prioritization capabilities in Microsoft Defender alongside an expanded suite of proactive incident response services, giving security teams more tools to prevent, detect and recover from cybersecurity threats.

Microsoft Wraps 2025 Patch Tuesday With Fixes for 3 Zero-Day

Microsoft closed out 2025 with its final Patch Tuesday release. This month's update fixes 56 vulnerabilities across Windows, Office and several other products, and includes three zero-day flaw fixes.

Microsoft Expands Intune Suite Capabilities to M365 E3 and E5 Plans

Microsoft is bringing advanced endpoint management capabilities from its Intune Suite directly into Microsoft 365 E3 and E5 subscriptions.

Microsoft Locks Down Entra ID Authentication with Script Injection Blocking

Microsoft is tightening security around its Entra ID sign-in process by blocking external script injection, a move that could force some orgs to rethink their browser extension strategies.

Microsoft Expands Copilot's Role in Office, Outlook and Security at Ignite 2025

At Ignite 2025, Microsoft doubled down on its Copilot strategy, announcing new agents and capabilities that bring deeper intelligence and automation to everyday workflows in Microsoft 365.

Group Used Its AI in Global Cyber Espionage Campaign

In what may be the first publicly known case of a state-sponsored cyber-espionage campaign using a large language model, Anthropic reported that attackers linked to China leveraged its Claude Code AI to carry out intrusions against about 30 global organizations.

1 Zero-Day, 4 Critical Items Addressed in November Patch Tuesday

Microsoft's latest Patch Tuesday brings fixes for 63 security flaws spread across Windows, Office and several other Microsoft products, including one zero-day vulnerability.

Microsoft Warns of Escalating Attacks Targeting Azure Blob Storage

Microsoft is warning IT administrators about an increase in attacks aimed at Azure Blob Storage, saying threat actors are taking advantage of exposed credentials, weak access controls and misconfigurations to gain access to sensitive cloud data.

Exploring a Free Tool To Improve Windows Privacy

A lightweight free utility gives Windows users an easy way to review and control system-level privacy settings without digging into the registry.

How AI Is Transforming SOC Efficiency with Security Copilot

At Live! 360 Orlando, Microsoft MVP John O’Neill Sr. will explore how combining Security Copilot with Defender XDR is helping SOCs accelerate response times, improve accuracy and reduce analyst fatigue.

Preventing Microsoft 365 Phishing Attacks, Part 3: Damage Control

Microsoft 365 administrators can fine-tune Defender's anti-phishing policies to determine how detected spoofed or impersonated messages are handled, from quarantine and deletion to user safety tips that flag suspicious senders.

Blue Nebula Graphic

Microsoft Ends Local Account Workarounds in Latest Windows 11 Build

Microsoft's latest Insider Preview, Build 26220.6772, introduces a significant policy change: removal of known workarounds to skip Microsoft Account setup during Windows 11 installation (OOBE).

Preventing Microsoft 365 Phishing Attacks, Part 2: ID Check

Microsoft 365 administrators can use built-in Defender for Office 365 tools to enable impersonation and domain protection, reducing phishing risks by identifying spoofed senders and untrusted domains.

Subscribe on YouTube