SecurityMicrosoft has detailed how the EvilTokens phishing-as-a-service platform industrialized device code phishing to steal tokens and compromise more than 12,000 inboxes across 10,000 organizations. The report matters for security teams because it includes mitigation guidance, Defender XDR detections, and hunting recommendations to reduce risk from token theft and post-compromise persistence.
3 min read · Sep 22, 2026
SecurityMicrosoft shared new email security benchmarking results showing Defender missed fewer high-severity threats than competing secure email gateway vendors from May through July 2026. The update also highlights stronger post-delivery remediation, AI-driven detection improvements, and new protections that matter as phishing and impersonation attacks become more convincing.
3 min read · Sep 17, 2026
SecurityMicrosoft is urging organizations to move from broad security guidance to concrete exposure-reduction actions as AI accelerates cyberattacks across identities, endpoints, apps, and networks. Through Secure Now in Microsoft Security Exposure Management, security teams can prioritize foundational controls that reduce risk from autonomous attacks, phishing, lateral movement, and weak authentication paths.
3 min read · Sep 17, 2026
SecurityMicrosoft Security Research detailed a large-scale fraud campaign that used AI-assisted email templates, executive impersonation, and fake invoices to pressure accounts payable teams into sending ACH payments. The campaign highlights how generative AI is making business email compromise-style attacks more convincing, increasing the need for stronger email defenses, user awareness, and payment verification controls.
3 min read · Sep 10, 2026
SecurityMicrosoft is warning that attackers are increasingly using trusted AI brands like ChatGPT, Copilot, Claude, and DeepSeek in phishing, malvertising, and malware campaigns. The company says Microsoft Defender can help security teams detect, correlate, and disrupt these multi-stage attacks across email, identities, endpoints, and SaaS apps.
3 min read · Sep 10, 2026
SecurityMicrosoft has introduced a new cloud web applications threat matrix aligned to MITRE ATT&CK to help defenders map, prioritize, and investigate threats across cloud-hosted web apps and serverless platforms. The framework matters because modern attack paths often span application code, identities, deployment pipelines, managed runtimes, and connected cloud resources, making siloed investigations incomplete.
3 min read · Sep 9, 2026
SecurityMicrosoft Security Research is tracking active attacks that use passkey, MFA, and SSO-themed social engineering to compromise cloud identities and access Microsoft 365 data. The campaigns rely on AiTM phishing, device code abuse, and unauthorized authentication method changes, making rapid detection and response critical for security teams.
3 min read · Sep 9, 2026
SecurityMicrosoft outlines how organizations can secure Edge AI deployments running in customer-owned environments, where models, data, credentials, and system authority move outside the provider’s cloud. The guidance focuses on runtime attestation, artifact provenance, and deterministic mediation to reduce risks such as prompt injection, model tampering, and compromised local infrastructure.
3 min read · Sep 4, 2026
SecurityMicrosoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, known as ASCII smuggling, to evade email filters in finance-themed lures. The technique, previously associated with AI prompt injection, shows how AI-era evasion methods are now crossing into traditional phishing, making layered email security and hunting more important for defenders.
3 min read · Sep 3, 2026
SecurityMicrosoft Threat Intelligence detailed a human-operated attack that abuses Microsoft Teams external collaboration to impersonate IT support and trick users into granting remote access. Once inside, attackers use legitimate tools like PowerShell, MSI installers, Node.js, and WinRM to establish persistence, conduct reconnaissance, and move laterally toward high-value systems such as domain controllers.
3 min read · Sep 3, 2026
SecurityMicrosoft is tracking an active malware campaign that uses fake software download sites to impersonate trusted brands and deliver malicious installers. The activity has affected multiple industries, with a focus on China-based operations and Chinese-speaking users, making it important for security teams to strengthen download controls and ensure Defender protections are enabled.
2 min read · Sep 3, 2026
SecurityMicrosoft is promoting its Cybersecurity Incident Response Readiness Workshop, a 2- to 3-day engagement led by the Detection and Response Team (DART) to help organizations test incident response plans against realistic attack scenarios. The workshop gives security teams practical feedback on people, processes, tools, and telemetry so they can identify gaps before a live incident exposes them.
3 min read · Sep 1, 2026