This month’s updates help you discover and control local AI agents, extend Zero Trust to agent traffic, and strengthen SOC foundations.
Category: Microsoft Security Blog
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis,…
Reimagining the SOC for the agentic era in Microsoft Defender
We are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for SIEM and threat protection…
Unmasking EvilTokens: Getting to the root of device code phishing
EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure,…
From guidance to action: Security fundamentals that materially reduce risk
AI has made fundamental changes to the operating environment for cybersecurity. Explore exposure management guidance on recommended controls and take…
Improving email security outcomes with real-world Microsoft Defender insights
The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where…
Threat matrix: Mapping threats across cloud web applications
Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate…
Passkey-themed social engineering leads to identity and cloud compromise
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA…
Protecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH…
Detect and disrupt AI-themed attacks with Microsoft Defender
See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain.
Threat matrix: Mapping threats across cloud web applications
Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate…
Passkey-themed social engineering leads to identity and cloud compromise
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA…
How to secure edge AI in customer-owned environments
As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing…
ASCII smuggling crosses over from AI prompt injection to phishing evasion
Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them.
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support,…
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives.…
Cybersecurity IR Workshop: The workshop you shouldn’t miss
Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response.
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with…
What’s new in Microsoft Security: August 2026
This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported…
When AI infrastructure becomes the target: Securing gateways and control points
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and…
