Skip to the main content.

ABT Blog

Read about mortgage technology solutions topics

cybersecurity (2)

Credit union boardroom with NCUA examiner reviewing Microsoft 365 board IT report on screen

20 min read

Credit Union Board IT Reporting: What NCUA and FFIEC Examiners Expect

In This Article What NCUA Part 748 Appendix A Requires Your Board to Approve and Review NCUA Letter 24-CU-02: The Four Areas of Board Cybersecurity...

Read More
Section 1033 Is Paused. Your Open Banking API Exposure Isn't. Hero image with Microsoft 365 branding and 4-square logo for the ABT blog article on community bank API security.

15 min read

Open Banking APIs and Cybersecurity for Community Banks: Section 1033 Is Paused, Your API Exposure Isn't

In This Article Section 1033 Is Paused, Not Cancelled Where the API Traffic Is Coming From Today The Five Threats Hiding in Consumer-Permissioned...

Read More
Five Microsoft 365 controls examiners check before Microsoft 365 Copilot Business deployment: Conditional Access via Microsoft Entra ID, Purview Audit, Purview DLP, Defender for Cloud Apps, and Intune, with shield-checkmark icons and the offer ending June 30.

33 min read

Five Microsoft 365 Controls Examiners Will Ask About Before You Roll Out Copilot

In This Article The Cost of NOT Shipping Copilot Five Microsoft 365 Controls That Turn Shadow AI Into Governed AI What FFIEC, OCC, NCUA, and FDIC...

Read More
The Exploit Part 3 - The Clone Trap. Anatomy of vendor supply chain breaches affecting credit unions, banks, and mortgage companies, with Microsoft 365 management as the supply chain reduction strategy.

12 min read

The Exploit: Anatomy of a Modern Cyber Heist Part 3 - The Clone Trap

In This Article SitusAMC: When JPMorgan's Mortgage Data Sat on Someone Else's Server Marquis Software: One Unpatched Firewall, 74 Financial...

Read More
Microsoft-branded hero image for ABT blog article: May 2026 Patch Tuesday: Netlogon + DNS RCEs Banks Must Patch Now. Banks, credit unions, and mortgage companies.

16 min read

May 2026 Patch Tuesday: Netlogon + DNS RCEs Banks Must Patch Now

In This Article What Microsoft Shipped on May 13, 2026 The Netlogon RCE That Earned a ZeroLogon Comparison The DNS Client RCE That Reaches Every...

Read More
Cyber kill chain attack on financial institutions: Mr. Cooper, Wells Fargo, Marquis Software breaches showing how stolen credentials and reconnaissance fuel modern cyber heists

11 min read

The Exploit: Anatomy of a Modern Cyber Heist Part 1 - The Leak in the Shadows

In This Article The Mr. Cooper Breach: 14.7 Million Records Stolen How Stolen Credentials Fuel the Dark Web Pipeline The Reconnaissance Playbook:...

Read More
Phishing-resistant MFA for financial institutions: hardware-backed FIDO2 security keys, passkeys, and Microsoft Entra ID Conditional Access protecting against AiTM, credential theft, and phishing attacks

16 min read

Phishing-Resistant MFA for Financial Institutions: Why FFIEC, NCUA, and OCC Examiners Now Expect FIDO2, Passkeys, and Hardware Keys

In This Article What "Phishing-Resistant" Authentication Actually Means Why SMS, Push, and One-Time Codes No Longer Pass the Bar What FFIEC Examiners...

Read More
Calyx PointCentral Hosting buyer guide for financial institutions: dedicated server, Tier 1 Microsoft CSP, FFIEC NCUA OCC NIST CSF 2.0 alignment, Azure usage pricing built for banks, credit unions, and mortgage companies in 2026

19 min read

Calyx PointCentral Hosting Buyer Guide for Financial Institutions (2026)

Prefer to watch? Why a dedicated tenant keeps borrower data out of the breach spillover. A 25-second look at why shared vendor infrastructure is...

Read More
Microsoft-branded hero image for ABT blog article: Microsoft Entra ID Entitlement Management SSRF (CVSS 10.0). Banks, credit unions, and mortgage companies.

12 min read

Microsoft Entra ID Entitlement Management SSRF (CVSS 10.0)

In This Article Why a 10.0 CVSS in identity governance is different What CVE-2026-35431 actually is Who's affected: licensing matters more than you...

Read More
SPF DKIM DMARC email authentication visual showing complete protection versus exposure for financial institutions

19 min read

Email Authentication for Financial Institutions: SPF, DKIM, and DMARC Enforcement Done Right

In This Article The Email Authentication Trap Most FIs Don't Know They're In SPF, DKIM, and DMARC: The Three-Protocol Stack Why Microsoft's Default...

Read More