News & Insights on Microsoft Technologies

For people interested in Microsoft technologies

AllMicrosoft 365IntunePower PlatformEntra IDSecurityAzureSharePoint
Security

npm Dependency Confusion Attack Targets Developer Environments

Microsoft Threat Intelligence uncovered 33 malicious npm packages that abused dependency confusion to impersonate internal corporate packages and silently profile developer systems during installation. The campaign matters because it targets developer workstations and CI/CD environments, creating a foothold for potential follow-on supply chain attacks.

3 min read · May 30, 2026
Security

Typosquatted npm Packages Steal Cloud and CI/CD Secrets

Microsoft has uncovered an active npm supply chain attack in which 14 typosquatted packages stole AWS credentials, HashiCorp Vault tokens, GitHub Actions data, and npm publish tokens during installation. The campaign matters because it targets developer and build environments, creating risk of cloud lateral movement, CI/CD compromise, and downstream software supply chain attacks.

3 min read · May 29, 2026
Microsoft 365

Copilot Studio May 2026: Agents, Workflows, Voice

Microsoft has announced several Copilot Studio updates for May 2026, including general availability of computer-using agents, a redesigned workflows experience, and Work IQ extensibility. These changes matter because they expand automation options, simplify building orchestrated business processes, and support more natural real-time voice interactions.

2 min read · May 29, 2026
Security

The Gentlemen Ransomware: Self-Propagating Go Threat

Microsoft Threat Intelligence has published a deep technical analysis of The Gentlemen ransomware, a Go-based ransomware-as-a-service threat that combines strong file encryption with aggressive self-propagation. The research matters for defenders because the malware can rapidly spread across local systems and network shares, increasing the blast radius of a single compromise.

3 min read · May 29, 2026
SharePoint

SharePoint Admin Agent Boosts AI Governance Readiness

Microsoft has introduced the SharePoint Admin Agent, a first-party AI assistant designed to help admins manage content governance across SharePoint, OneDrive, Teams, and Microsoft 365. Built on SharePoint Advanced Management, it supports a six-step governance journey to improve readiness for Copilot and other AI experiences while giving admins conversational insights and guided actions.

3 min read · May 29, 2026
Security

Cryptojacking Campaign Abuses ScreenConnect and .NET

Microsoft has detailed an active cryptojacking campaign that uses poisoned search results and AI chatbot recommendations to lure users to fake software download sites. The attack abuses DLL sideloading, ScreenConnect, and Microsoft .NET utilities to gain persistent access and mine cryptocurrency on high-GPU systems, raising the risk of follow-on activity such as data theft or ransomware.

3 min read · May 29, 2026
Entra ID

Microsoft Entra Tenant Governance Finds Shadow Tenants

Microsoft Entra Tenant Governance now helps organizations discover shadow tenants connected through B2B collaboration, multitenant apps, and shared billing signals. The new related tenants capability gives IT teams continuous visibility into hidden tenant sprawl so they can assess risk, quarantine unsanctioned tenants, and tighten identity governance.

3 min read · May 29, 2026
Azure

Azure IaaS Performance: System-Level Workload Guide

Microsoft is highlighting a system-level approach to Azure IaaS performance, emphasizing that compute, storage, and networking must be optimized together for AI, Kubernetes, and business-critical workloads. For IT teams, the guidance matters because it shifts performance planning away from simply sizing up resources and toward designing for consistent latency, throughput, scalability, and resilience.

3 min read · May 29, 2026