July 17, 2026

ACR Stealer: Two observed intrusion chains amid increased threat activity

In this article Campaign 1: WebDAV-based ClickFix with Python loaders and blockchain C2 Campaign 2: MSHTA-initiated PowerShell chain with steganographic payload delivery Mitigation and protection guidance […]
July 16, 2026

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

In this article Attack chain overview How the attack started: GitHub Actions pwn request Mitigation and protection guidance Learn more On July 14, 2026, Microsoft Threat […]
July 14, 2026

Defending SaaS-based applications against ShinyHunters OAuth abuse

In this article Attack chain overview Improving visibility into Salesforce OAuth abuse Mitigation and protection guidance Learn more In a series of campaigns observed between mid-2025 […]
July 10, 2026

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

In this article A wiper inside a backdoor Backdoor capabilities How GigaWiper was assembled Conclusion: Multiple destructive capabilities consolidated into a single implant Defending against destructive […]
July 7, 2026

5 insights from Frost & Sullivan’s 2025 Frost Radar™ for Cloud Security Posture Management

Cloud security posture management (CSPM) is being redefined as two forces collide: Cloud environments are becoming more interconnected—spanning workloads, identities, data, APIs, and development pipelines—while security […]
July 3, 2026

Improving security posture across the Microsoft partner ecosystem

The Deputy CISO blog series is where Microsoft  Deputy Chief Information Security Officers (CISOs) share their thoughts on what is most important in their respective domains. In this series, […]