Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Microsoft Security Blog

16 articles

Microsoft Security Blog vendor Microsoft NEW 1h ago

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizati...

T1078

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft 1d ago

​​​​What’s new in Microsoft Security: July 2026

This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations dep...

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft 2d ago

​​Better security starts with better questions

Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems. The post ​​Better secu...

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft 4d ago

Rethinking security for the age of AI

Why security needs a new Cyber Stack — Introducing Project Perception The physics of cybersecurity are changing. Autonomous systems can now reason, adapt and...

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft 4d ago

Enhancing AI security through global AI red teaming

Microsoft's External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red teaming. By partnering with ...

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft Jul 23

Email threat landscape: Q2 2026 trends and insights

In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in sever...

T1566 T1204

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft Jul 22

Real world incident response: Microsoft and AXA XL strengthen cyber resilience

Our collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technic...

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft Jul 17

Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks

Join Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception. The post Mic...

T1195

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft Jul 16

ACR Stealer: Two observed intrusion chains amid increased threat activity

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are s...

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft Jul 16

Least privilege for AI agents: Identity, access, and tool binding

As AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure. The post Least privilege for AI agen...

T1598

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft Jul 16

Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery

Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack ch...

T1195

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft Intel Jul 15

Turning threat intelligence into decisive action with Defender Experts

Security teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a s...

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft Intel Jul 13

Defending SaaS-based applications against ShinyHunters OAuth abuse

Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (v...

T1566

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft Jul 13

Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID

Microsoft Entra ID makes passkeys the default sign-in experience and introduces a new model for SMS and voice authentication. Read about how to prepare.

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft Jul 10

Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative

Microsoft’s latest Secure Future Initiative report outlines progress on secure foundations, AI-powered defense, and future-ready cybersecurity. The post Secu...

Microsoft Security Blog → Details

Microsoft Security Blog vendor Microsoft Jul 9

GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware

GigaWiper, also tracked as BLUERABBIT, is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational pla...

Microsoft Security Blog → Details

FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA