Skip to the main content.

ABT Blog

Read about mortgage technology solutions topics

cybersecurity

Microsoft 365 adversary in the middle attack chain ending in a registered Microsoft Entra ID device and an enrolled Windows Hello for Business credential

11 min read

Knight Office AiTM Kit: Persistence Past Password Reset

In This Article What Huntress found How this differs from the August Windows Hello research The step that survives your incident response Whether...

Read More
Shadow IT discovery dashboard showing sanctioned and unsanctioned cloud apps for a financial institution, with Microsoft 365 branding

15 min read

Shadow IT in Financial Institutions: Find It, Govern It

Your staff already told you which tools they need. They just did not ask first. How to find unsanctioned apps in a Microsoft 365 tenant with Defender...

Read More
Cyber incident reporting deadlines for financial institutions, showing the 36 hour, 72 hour and 30 day regulatory clocks

12 min read

The 36-Hour, 72-Hour, and 30-Day Incident Reporting Clocks

Three federal rules, three deadlines, and three different definitions of the moment the clock starts. What triggers each one, and what Microsoft 365...

Read More
Microsoft Entra ID Conditional Access exclusion list review for financial institutions

12 min read

Conditional Access Exclusions: The List Nobody Reviews

Every institution grants Conditional Access exceptions. Microsoft documents how those lists grow, names access reviews as the compensating control,...

Read More
FTC Safeguards Rule shield covering a CPA firm, title agency, and auto dealer, with a Microsoft 365 security dashboard

9 min read

You Might Be Running a Financial Institution. The FTC Thinks So.

In This Article The Label You Did Not Choose Who Is Covered? The List Is Longer Than You Think What the Safeguards Rule Actually Requires What...

Read More
Windows Hello for Business key abuse and Microsoft Entra ID device registration

15 min read

Windows Hello for Business Key Abuse: What Financial Institutions Need to Verify

Malware already running in a signed-in Windows session can use that user's Windows Hello for Business key to authenticate to Microsoft Entra ID, with...

Read More
Dark editorial illustration of a hijacked Microsoft 365 session quietly reading payroll and finance mail while security alerts stay silent

13 min read

Payroll Pirates: The Microsoft 365 Attack Your Alerts Miss

A Microsoft 365 session-hijacking campaign is reading payroll and finance mail while deliberately avoiding the account-modification signals most...

Read More
Microsoft Entra ID legacy risk policies deactivated with an October 1 2026 deadline, replaced by Conditional Access protecting bank accounts

14 min read

Entra Risk Policies Retire Oct 1, 2026: What Banks Must Do

In This Article What actually changes on October 1 The self-service loop that goes away first The detections keep firing. No risk policy acts on...

Read More
Hotel conference room laptop showing a captive portal sign-in, with a stolen Microsoft 365 session token flowing to an attacker past Microsoft Entra ID controls

14 min read

Hotel Wi-Fi Is Stealing Microsoft 365 Sessions

In This Article What Microsoft Found on Hotel and Conference Wi-Fi Two Attack Paths, and Why the Difference Decides Your Controls The Part That...

Read More
Three-stage diagram showing a password-protected closing package that Microsoft Defender for Office 365 cannot scan, moving to a quarantine folder with an off-by-default admin toggle

15 min read

Defender's New Password-Protected Attachment Quarantine: What Lenders Should Decide

Microsoft is adding an opt-in Safe Attachments setting that quarantines password-protected attachments Defender cannot scan or detonate. It is off by...

Read More