Skip to the main content.

ABT Blog

Read about mortgage technology solutions topics

Critical Microsoft Entra ID token service spoofing vulnerability illustration showing the Microsoft Enterprise Security Token Service (ESTS) issuing authentication tokens for Microsoft 365 and Microsoft Azure resources, with the Microsoft 4-square logo prominently displayed and a CVSS 9.3 critical badge.

13 min read

CVE-2026-40379: Microsoft's Critical Entra ID Token Service Spoofing CVE: The FI Response

In This Article What CVE-2026-40379 Actually Is Why "Exclusively Hosted Service" Changes Your Job The Five-Step ESTS Token Flow The FI Posture Review What Examiners and Boards Want to See The Pattern of Cloud-Side Entra ID CVEs in 2026 M365 Guardian...

Read More
Microsoft-branded hero image for ABT blog article: Hybrid Cloud for Financial Institutions: How Banks, Credit Unions, and Mortgage Companies Get Microsoft Azure + On-Prem Right. Banks, credit unions, and mortgage companies.

12 min read

Hybrid Cloud for Financial Institutions: How Banks, Credit Unions, and Mortgage Companies Get Microsoft Azure + On-Prem Right

In This Article What Hybrid Cloud Means for Financial Institutions Five Operational Benefits for Banks, Credit Unions, and Mortgage Companies Where...

Read More
Microsoft-branded hero image for ABT blog article: Tech Due Diligence for Fintech Mortgage Startups: An MSP's Perspective. Banks, credit unions, and mortgage companies.

5 min read

Tech Due Diligence on Fintech Vendors: What Examiners Now Expect

The OCC, Federal Reserve, and FDIC unified third-party risk management under a single interagency standard on June 6, 2023. Three years later,...

Read More
Microsoft-branded hero image for ABT blog article: Is Your Interface CFPB-Proof? What Mortgage Teams Need to Know About HMDA Compliance. Banks, credit unions, and mortgage companies.

5 min read

CFPB-Proof Loan Application Interfaces: How Banks, Credit Unions, and Mortgage Companies Capture Fair Lending Data Examiners Trust in 2026

In This Article The CFPB Rollback Did Not Repeal Your Data Rules The 2026 State-Level Patchwork Banks, Credit Unions, and Mortgage Companies Now...

Read More
Credit union boardroom with NCUA examiner reviewing Microsoft 365 board IT report on screen

20 min read

Credit Union Board IT Reporting: What NCUA and FFIEC Examiners Expect

In This Article What NCUA Part 748 Appendix A Requires Your Board to Approve and Review NCUA Letter 24-CU-02: The Four Areas of Board Cybersecurity...

Read More
Microsoft-branded hero image for ABT blog article: Scaling Pains or Scaling Gains? IT Metrics That Predict Mortgage Growth Success. Banks, credit unions, and mortgage companies.

8 min read

Scaling Pains or Scaling Gains? IT Metrics That Predict Financial Institution Growth Success

In This Article What Scalable Mortgage Technology Actually Means Why Scaling Failures Cost More Than Downtime Five IT Metrics That Predict Growth...

Read More
Microsoft-branded hero image for ABT blog article: Storm-2949: Microsoft Just Disclosed a No-Malware Identity Attack on Cloud Tenants. Banks, credit unions, and mortgage companies.

14 min read

Storm-2949: Microsoft Just Disclosed a No-Malware Identity Attack on Cloud Tenants

In This Article What Microsoft Disclosed About Storm-2949 The SSPR Abuse Path: How One Phone Call Becomes a Cloud-Wide Breach Why This Lands So Hard...

Read More
Microsoft 365 SharePoint Online read-only banner overlay with Microsoft 4-square logo, Microsoft 365 wordmark, and late May 2026 license-aligned storage quota enforcement timeline for financial institutions

15 min read

SharePoint Storage Quota Enforcement May 2026: FI Verification Guide

In This Article What Changes Late May 2026 Why Financial Institutions Are Especially Exposed The Storage Formula: 1 TB Plus 10 GB Per Qualifying...

Read More
Section 1033 Is Paused. Your Open Banking API Exposure Isn't. Hero image with Microsoft 365 branding and 4-square logo for the ABT blog article on community bank API security.

15 min read

Open Banking APIs and Cybersecurity for Community Banks: Section 1033 Is Paused, Your API Exposure Isn't

In This Article Section 1033 Is Paused, Not Cancelled Where the API Traffic Is Coming From Today The Five Threats Hiding in Consumer-Permissioned...

Read More
Healthcare nonprofit cybersecurity 2026 with Microsoft 365 product names

12 min read

Healthcare Nonprofit Cybersecurity 2026: Microsoft's October Policy Change, the OCR Pattern, and How to Lock Pricing Before July 1

In This Article Why Healthcare Nonprofits Are on the Target List Right Now The October 2025 Microsoft Policy Change Most Healthcare Nonprofits Missed...

Read More