11 min read
Power Pages Misconfiguration: No CVE, No Patch
Two financial regulators flagged a Microsoft Power Pages setting that exposes Dataverse records. No CVE, no patch, and your scanner will not see it.
11 min read
Two financial regulators flagged a Microsoft Power Pages setting that exposes Dataverse records. No CVE, no patch, and your scanner will not see it.
13 min read
In This Article What actually changes at the end of December 2026 What in your institution still sends mail this way How to find every dependency...
11 min read
In This Article What Huntress found How this differs from the August Windows Hello research The step that survives your incident response Whether...
15 min read
Your staff already told you which tools they need. They just did not ask first. How to find unsanctioned apps in a Microsoft 365 tenant with Defender...
12 min read
Three federal rules, three deadlines, and three different definitions of the moment the clock starts. What triggers each one, and what Microsoft 365...
12 min read
Every institution grants Conditional Access exceptions. Microsoft documents how those lists grow, names access reviews as the compensating control,...
9 min read
In This Article The Label You Did Not Choose Who Is Covered? The List Is Longer Than You Think What the Safeguards Rule Actually Requires What...
15 min read
Malware already running in a signed-in Windows session can use that user's Windows Hello for Business key to authenticate to Microsoft Entra ID, with...
13 min read
A Microsoft 365 session-hijacking campaign is reading payroll and finance mail while deliberately avoiding the account-modification signals most...
14 min read
In This Article What actually changes on October 1 The self-service loop that goes away first The detections keep firing. No risk policy acts on...