In this article Weston on the future of defense Our latest intelligence (and response) on npm supply chain attacks Follow the research in the Black Hat […]
In this article Campaign 1: WebDAV-based ClickFix with Python loaders and blockchain C2 Campaign 2: MSHTA-initiated PowerShell chain with steganographic payload delivery Mitigation and protection guidance […]
In this article Real-world scenarios Best Practices: Identity + RBAC + Scope + Safe Tool Binding Looking Ahead AI agents aren’t only smarter API callers. They […]
In this article Attack chain overview How the attack started: GitHub Actions pwn request Mitigation and protection guidance Learn more On July 14, 2026, Microsoft Threat […]
In this article Upstream: See the campaign before it reaches you Microsoft Defender Threat Intelligence Now Integrated into Defender In your environment: Follow the threat everywhere […]
In this article Attack chain overview Improving visibility into Salesforce OAuth abuse Mitigation and protection guidance Learn more In a series of campaigns observed between mid-2025 […]
As identity attacks grow more sophisticated in the AI era, organizations need stronger authentication methods that protect users from phishing, credential theft, and social engineering. To […]
Security is never finished. That conviction is where the Secure Future Initiative (SFI) started two years ago and continues to guide us today. AI is reshaping […]
In this article A wiper inside a backdoor Backdoor capabilities How GigaWiper was assembled Conclusion: Multiple destructive capabilities consolidated into a single implant Defending against destructive […]
AI models have reached a threshold where they exhibit expert-level capabilities in vulnerability discovery, exploit chaining, and proof-of-concept generation. As AI-powered vulnerability discovery matures, every organization […]
Cloud security posture management (CSPM) is being redefined as two forces collide: Cloud environments are becoming more interconnected—spanning workloads, identities, data, APIs, and development pipelines—while security […]
The Deputy CISO blog series is where Microsoft Deputy Chief Information Security Officers (CISOs) share their thoughts on what is most important in their respective domains. In this series, […]