Microsoft Security Blog
Your source for the latest in cybersecurity
Featured Posts
What’s new in Microsoft Security: September 2026
This month’s updates help you discover and control local AI agents, extend Zero Trust to agent traffic, and strengthen SOC foundations.
From guidance to action: Security fundamentals that materially reduce risk
AI has made fundamental changes to the operating environment for cybersecurity.
Improving email security outcomes with real-world Microsoft Defender insights
The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve.
Stay ahead of threats
Get expert insights, threat intelligence, and the latest cybersecurity reports from Security Insider.
AI and machine learning
-
Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026
This year at Microsoft Ignite, we spotlight our AI-first, end-to-end security platform designed to protect identities, devices, data, applications, clouds, infrastructure, and the AI agents now working alongside your teams. -
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders. -
What’s new in Microsoft Security: September 2026
This month’s updates help you discover and control local AI agents, extend Zero Trust to agent traffic, and strengthen SOC foundations.
Modernize your security operations center
Confidently secure your multicloud, multiplatform environment with Microsoft Sentinel – a cloud-native security information and event management (SIEM) solution.
Latest posts
-
Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026
This year at Microsoft Ignite, we spotlight our AI-first, end-to-end security platform designed to protect identities, devices, data, applications, clouds, infrastructure, and the AI agents now working alongside your teams. -
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance. -
Beyond source code: A path to the keys to the kingdom
Explore how Storm-3068 turned a compromised identity into broader cloud access and the steps organizations can take to defend their identities, pipelines, and cloud infrastructure. -
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations.