SecurityMicrosoft is outlining an "agentic SOC" model that combines autonomous threat disruption with AI agents to accelerate investigations and reduce alert fatigue. The approach aims to shift security operations from reactive incident response to faster, more adaptive defense, giving SOC teams more time for strategic risk reduction and governance.
3 min read · Apr 9, 2026
Entra IDMicrosoft highlights new research showing that AI adoption is rapidly expanding identity and network access risk, with AI agents, GenAI use, and fragmented tools increasing incidents across enterprises. The report argues that organizations need a more unified access strategy, or "access fabric," to improve visibility, enforce policy faster, and reduce risk as AI scales.
3 min read · Apr 9, 2026
SecurityMicrosoft has detailed a financially motivated Storm-2755 campaign targeting Canadian employees with payroll diversion attacks. The threat actor used SEO poisoning, malvertising, and adversary-in-the-middle techniques to steal sessions, bypass legacy MFA, and alter direct deposit details, making phishing-resistant MFA and session monitoring critical defenses.
3 min read · Apr 9, 2026
SecurityMicrosoft disclosed a severe intent redirection flaw in the third-party EngageSDK for Android, putting millions of crypto wallet users at potential risk of data exposure and privilege escalation. The issue was fixed in EngageSDK version 5.2.1, and the case highlights the growing security risk of opaque mobile app supply-chain dependencies.
3 min read · Apr 9, 2026
SecurityMicrosoft Threat Intelligence says Forest Blizzard has been compromising vulnerable home and small-office routers to hijack DNS traffic and, in some cases, enable adversary-in-the-middle attacks against targeted connections. The campaign matters to IT teams because unmanaged SOHO devices used by remote and hybrid workers can expose cloud access and sensitive data even when corporate environments remain secure.
3 min read · Apr 8, 2026
IntuneMicrosoft Intune now supports Android Enterprise management for Android XR devices, including the Samsung Galaxy XR headset. IT admins can use existing enrollment, policy, and app management workflows to test and deploy XR devices, while planning around current gaps such as kiosk mode, OEMConfig, and Remote Help.
3 min read · Apr 8, 2026
SecurityMicrosoft Threat Intelligence warns that Storm-1175 is rapidly exploiting vulnerable internet-facing systems to deploy Medusa ransomware, sometimes within 24 hours of initial access. The group’s focus on newly disclosed flaws, web shells, RMM tools, and fast lateral movement makes patch speed, exposure management, and post-compromise detection critical for defenders.
3 min read · Apr 6, 2026
SecurityMicrosoft Defender Security Research detailed a large-scale phishing campaign that abuses the OAuth device code flow using AI-generated lures, dynamic code generation, and automated backend infrastructure. The campaign raises the risk for organizations because it improves attacker success rates, bypasses traditional detection patterns, and enables token theft, inbox rule persistence, and Microsoft Graph reconnaissance.
3 min read · Apr 6, 2026
Microsoft 365Microsoft has announced that multi-agent systems in Copilot Studio are now generally available, alongside updates to connected experiences, the Prompt Editor, and governance controls. These changes help organizations build more capable copilots faster while improving oversight, iteration speed, and enterprise readiness.
2 min read · Apr 5, 2026
Power PlatformMicrosoft has launched a public preview that brings Power Apps model-driven apps directly into Microsoft 365 Copilot. Makers can expose app data and actions through an app MCP server, letting users view grids, open forms, and update records inside Copilot across Word, Excel, PowerPoint, and more.
3 min read · Apr 5, 2026
Power PlatformMicrosoft has outlined a practical adaptive governance framework for AI agents in Power Platform, focused on risk-based controls instead of blanket restrictions. The guidance emphasizes managed environments, sharing controls, identity discipline, and platform-enforced oversight so organizations can scale AI safely without driving shadow IT.
3 min read · Apr 5, 2026
AzureMicrosoft announced an AI for nuclear collaboration with NVIDIA to help streamline nuclear plant permitting, design, construction, and operations. The initiative uses Azure-based AI, digital twins, and simulation technologies to reduce documentation bottlenecks, improve traceability, and help energy organizations deliver carbon-free power faster and more predictably.
3 min read · Apr 5, 2026