Microsoft Security Blog
Your source for the latest in cybersecurity
Featured Posts
What’s new in Microsoft Security: September 2026
This month’s updates help you discover and control local AI agents, extend Zero Trust to agent traffic, and strengthen SOC foundations.
From guidance to action: Security fundamentals that materially reduce risk
AI has made fundamental changes to the operating environment for cybersecurity.
Improving email security outcomes with real-world Microsoft Defender insights
The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve.
Stay ahead of threats
Get expert insights, threat intelligence, and the latest cybersecurity reports from Security Insider.
AI and machine learning
-
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders. -
What’s new in Microsoft Security: September 2026
This month’s updates help you discover and control local AI agents, extend Zero Trust to agent traffic, and strengthen SOC foundations. -
Reimagining the SOC for the agentic era in Microsoft Defender
We are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for SIEM and threat protection together.
Modernize your security operations center
Confidently secure your multicloud, multiplatform environment with Microsoft Sentinel – a cloud-native security information and event management (SIEM) solution.
Latest posts
-
Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570
Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance. -
Beyond source code: A path to the keys to the kingdom
Explore how Storm-3068 turned a compromised identity into broader cloud access and the steps organizations can take to defend their identities, pipelines, and cloud infrastructure. -
NeedyMantis: Unpacking a post-compromise malware family used in targeted operations
Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations. -
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders.