15 min read
Windows Hello for Business Key Abuse: What Financial Institutions Need to Verify
Malware already running in a signed-in Windows session can use that user's Windows Hello for Business key to authenticate to Microsoft Entra ID, with...
15 min read
Malware already running in a signed-in Windows session can use that user's Windows Hello for Business key to authenticate to Microsoft Entra ID, with...
13 min read
A Microsoft 365 session-hijacking campaign is reading payroll and finance mail while deliberately avoiding the account-modification signals most...
14 min read
In This Article What actually changes on October 1 The self-service loop that goes away first The detections keep firing. No risk policy acts on...
14 min read
In This Article What Microsoft Found on Hotel and Conference Wi-Fi Two Attack Paths, and Why the Difference Decides Your Controls The Part That...
15 min read
Microsoft is adding an opt-in Safe Attachments setting that quarantines password-protected attachments Defender cannot scan or detonate. It is off by...
13 min read
The October 2026 Windows security update changes permissions on the AD FS Distributed Key Manager container by default. Here is what it removes,...
13 min read
Microsoft is flipping eleven Microsoft 365 profile card properties from hidden to visible by default in late August 2026, including user principal...
10 min read
Microsoft's Q2 2026 email threat report shows Tycoon2FA phishing down 92% and invoice-themed BEC collapsing, while Teams vishing climbed to roughly...
12 min read
In This Article Cyber Coverage Became a Controls Exam What Carriers Actually Require Now The Control to Microsoft 365 Map Where Microsoft 365 Falls...
13 min read
Microsoft fixed a 9.9 elevation-of-privilege flaw (CVE-2026-57100) in the Microsoft Entra provisioning service server-side, with no customer patch....