Skip to the main content.

ABT Blog

Read about mortgage technology solutions topics

cybersecurity

Hotel conference room laptop showing a captive portal sign-in, with a stolen Microsoft 365 session token flowing to an attacker past Microsoft Entra ID controls

14 min read

Hotel Wi-Fi Is Stealing Microsoft 365 Sessions

In This Article What Microsoft Found on Hotel and Conference Wi-Fi Two Attack Paths, and Why the Difference Decides Your Controls The Part That...

Read More
Three-stage diagram showing a password-protected closing package that Microsoft Defender for Office 365 cannot scan, moving to a quarantine folder with an off-by-default admin toggle

15 min read

Defender's New Password-Protected Attachment Quarantine: What Lenders Should Decide

Microsoft is adding an opt-in Safe Attachments setting that quarantines password-protected attachments Defender cannot scan or detonate. It is off by...

Read More
Microsoft 365 identity security concept illustrating AD FS federation token signing key protection for financial institutions

13 min read

AD FS Key Container Hardening: What Changes for Financial Institutions on October 13

The October 2026 Windows security update changes permissions on the AD FS Distributed Key Manager container by default. Here is what it removes,...

Read More
Microsoft 365 profile card with lower directory fields glowing orange, beside the headline The staff directory fills in, sign-in names included, late August

13 min read

Microsoft 365 Profile Cards: 11 Properties Go Visible

Microsoft is flipping eleven Microsoft 365 profile card properties from hidden to visible by default in late August 2026, including user principal...

Read More
Split scene showing a dimmed email inbox on the left and a bright Microsoft Teams incoming call notification on the right, with Microsoft 365 branding

10 min read

Microsoft Q2 2026 Threat Data: Teams Vishing Hit 10x While One Phishing Platform Collapsed

Microsoft's Q2 2026 email threat report shows Tycoon2FA phishing down 92% and invoice-themed BEC collapsing, while Teams vishing climbed to roughly...

Read More
Cyber insurance renewal checklist mapped to a Microsoft 365 security panel showing Microsoft Entra, Microsoft Defender, and Microsoft Purview.

12 min read

Cyber Insurance Requirements Mapped to Microsoft 365 for Financial Institutions

In This Article Cyber Coverage Became a Controls Exam What Carriers Actually Require Now The Control to Microsoft 365 Map Where Microsoft 365 Falls...

Read More
Microsoft-branded hero for the Microsoft Entra provisioning flaw CVE-2026-57100, identity control plane security for banks, credit unions, and mortgage companies

13 min read

Microsoft Entra Provisioning Flaw (CVE-2026-57100): What Financial Institutions Must Verify

Microsoft fixed a 9.9 elevation-of-privilege flaw (CVE-2026-57100) in the Microsoft Entra provisioning service server-side, with no customer patch....

Read More
Microsoft 365 incident response for financial institutions: alerts from endpoints, email, and identity correlate in Microsoft Defender XDR into a unified incident, with Microsoft Sentinel and Microsoft Purview carrying the response.

12 min read

Microsoft 365 Incident Response Plan for Financial Institutions: The Examiner-Ready Playbook

A written incident response plan is examiner-mandated for banks, credit unions, and mortgage companies. Here are the seven elements it must cover and...

Read More
ClickFix infostealer stealing a Microsoft 365 login session token from a browser, shown with Microsoft 365 branding, for banks, credit unions, and mortgage companies

13 min read

ClickFix Infostealers Are Draining Microsoft 365 Logins: What Financial Institutions Do Now

In This Article A Stolen Login Is a Working Login ClickFix: An Attack With No Vulnerability to Patch Why Sign-In MFA and Signature Antivirus Both...

Read More
July 2026 Microsoft Patch Tuesday triage for financial institutions: three exploited CVEs and the SharePoint Server flaw with a Sunday federal deadline

17 min read

July 2026 Patch Tuesday: Three Exploited Flaws and What Financial Institutions Patch First

In This Article Three Flaws Are Being Exploited Right Now CVE-2026-58644: The One With a Sunday Deadline The Two That Do Not Look Like Emergencies...

Read More