Latest Intelligence
Filterable operational feed for current Microsoft security and SOC changes.
Langflow patched two security flaws after active exploitation leading to credential theft related to major cloud services. These updates address remote code execution weaknesses allowing attackers unauthorized access to sensitive keys.
Why it matters: Organizations using Langflow for AI application development risk credential compromise and unauthorized access to their OpenAI and AWS resources until patched. This may lead to data breaches, service misuse, or financial loss.Actions: Immediately update Langflow installations to the latest patched version.; Review and revoke potentially compromised OpenAI and AWS credentials.Related CVEs: CVE-2026-0768Source: https://www.bleepingcomputer.com/Microsoft Defender portal, Microsoft Sentinel, Microsoft Defender for Endpoint, Microsoft Defender XDR - Microsoft primary source - NewSource published: Not available - Material update: 2 Sept 2026, 2:45 pm ISTKey Updates on Microsoft Unified Security Operations and Microsoft Sentinel Transition- New content types (analytics, automation rules, workbooks) generally available for cross-tenant distribution. - Microsoft Sentinel is now generally available in the Microsoft Defender portal; Azure portal support ends March 2027. - Microsoft Threat Intelligence alerts enhanced for Sentinel customers within the Defender portal. - Introduction of UEBA experiences in Defender portal for behavioral insights. - Incident workflows supported with tasks in Defender portal. - Unified RBAC viewing and multitenant content distribution profiles made generally available. - Ability to create/edit Sentinel workbooks directly in Defender portal. - Automatic onboarding and redirection for new Sentinel customers to the Defender portal starting July 2025.
Why it matters: Security operations teams must plan and execute migration from Microsoft Sentinel in the Azure portal to the Defender portal by March 2027 to maintain support and leverage unified security experiences. They can also benefit from new behavioral analytics and task management features that improve investigation efficiency. Expanded content distribution and RBAC capabilities enhance multitenant security management at scale.Actions: Plan migration of Microsoft Sentinel workspaces from Azure portal to Defender portal before March 31, 2027.; Enable and integrate UEBA capabilities to leverage behavioral anomaly insights for investigations.Related KQL: New UEBA data sources and behavioral anomaly tables have been introduced that can improve detection and hunting queries.Source: https://learn.microsoft.com/en-us/unified-secops/whats-newMicrosoft Sentinel, Microsoft Sentinel UEBA, SAP agentless solution for Microsoft Sentinel, SAP BTP solution, SAP LogServ solution - Microsoft primary source - NewSource published: Not available - Material update: 2 Sept 2026, 2:45 pm ISTMicrosoft Sentinel August 2026 Update: Enhanced UEBA, SAP Integrations, and Automation ConsistencyUEBA now includes Fortinet FortiGate behaviors and supports Check Point, Fortinet, Zscaler, AWS GuardDuty anomalies, with mappings to MITRE ATT&CK techniques. UEBA behaviors gain contextual anomaly insights. SAP agentless and BTP solutions have new versions with audit and detection improvements. Analytics alert Account Name is normalized to UPN prefix only, adding new UPN fields to the SecurityAlert table, impacting automation rules and Logic Apps data handling.
Why it matters: Existing automation rules, playbooks, or Logic Apps that rely on the AccountName field in analytics rule alerts may fail or behave unexpectedly due to changes in UPN handling. Organizations must update their automation to separate UPN prefix and suffix comparisons and avoid strict equality checks to maintain compatibility. Security operations can leverage enhanced UEBA and SAP integration capabilities to improve detection and investigation processes.Actions: Review and update all automation rules, Logic Apps, and playbooks that filter or compare analytics alerts based on AccountName to accommodate the Account Name change to UPN prefix only.; Modify conditions using strict AccountName equality checks to use Contains or Starts With operators and compare UPN prefix and UPNSuffix separately.Related KQL: The update introduces new UEBA behaviors and anomaly detection rules that map to MITRE ATT&CK techniques and supports queries that link behavior results to incidents, enabling custom advanced hunting queries.Source: https://learn.microsoft.com/en-us/azure/sentinel/whats-newMicrosoft Graph API, Azure Event Hubs, Microsoft Entra ID, Infrastructure-as-Code using Bicep - Microsoft primary source - NewSource published: Not available - Material update: 2 Sept 2026, 2:44 pm ISTMicrosoft Graph Permission and Resource Changes - Admin Consent Updates and Bicep Resource AdditionsChanged admin consent requirements for several delegated permissions; added Bicep resource support for various Microsoft Graph resource types including user, application, servicePrincipal, federatedIdentityCredential, and group; deprecated SAS authentication for Azure Event Hubs in favor of RBAC.
Why it matters: Developers and administrators need to adjust consent processes and update deployment pipelines to incorporate Bicep templates for resource provisioning. Subscriptions to Microsoft Graph change notifications via Event Hubs require migration to Microsoft Entra ID RBAC. Security posture may be improved by stricter admin consent controls on threat submission permissions.Actions: Review and update consent workflows to accommodate permission changes; Migrate Event Hubs authentication from SAS to Microsoft Entra ID RBAC as per guidanceSource: https://developer.microsoft.com/en-us/graph/changelogMicrosoft Secure Score, Microsoft Entra (AAD), Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Exchange Online, Microsoft SharePoint, Microsoft Forms, Microsoft Sway, Atlassian, Zendesk, Meta Workplace, Dropbox, Microsoft 365 Lighthouse - Microsoft primary source - NewSource published: Not available - Material update: 2 Sept 2026, 2:43 pm ISTUpdates and Enhancements in Microsoft Secure Score (Aug 2023 - Feb 2024)Between August 2023 and February 2024, Microsoft introduced new Secure Score improvement actions covering a broad set of Microsoft and third-party security controls. Notable changes include the addition of phishing-resistant MFA enforcement for administrators, custom banned password lists, limitations on administrative roles for certain APIs, expanded SharePoint and Microsoft Forms sharing restrictions, recommendations related to Active Directory Certificate Services, Defender for Cloud Apps multi-instance support, and integration of Secure Score with Microsoft 365 Lighthouse for MSPs. Additionally, Secure Score access is now managed via Microsoft Defender unified RBAC allowing finer permission granularity.
Why it matters: Organizations using Microsoft Secure Score will need to review and implement new improvement actions to maximize security posture. Security teams and administrators may require updates to policies such as MFA configurations, password policies, certificate templates, and external sharing restrictions. MSPs managing multiple tenants can leverage Secure Score integration with Microsoft 365 Lighthouse for consolidated visibility. The new RBAC support enables more controlled access to Secure Score data, improving governance.Actions: Review all newly added Secure Score improvement actions since August 2023 and assess applicability within your environment.; Implement phishing-resistant MFA for administrators and enforce custom banned password lists in Microsoft Entra ID.Source: https://learn.microsoft.com/en-us/defender-xdr/microsoft-secure-score-whats-newMicrosoft Security Exposure Management, Microsoft Defender portal, Codename MDASH agentic code scanner, Microsoft Defender CLI, Microsoft Foundry, Azure DevOps connector for Codename MDASH, Operational Technology platforms: Armis, Dragos, Forescout, Microsoft Defender for Cloud Apps - Microsoft primary source - NewSource published: Not available - Material update: 2 Sept 2026, 2:43 pm ISTMicrosoft Security Exposure Management - Recent Feature Updates and PreviewsAugust 2026 updates enable keyless authentication using managed identities instead of API keys for Foundry connections; cancel scan option added to Microsoft Defender portal. Azure DevOps connector preview for remote on-demand agentic scans introduced. July 2026 releases feature MAI-Augmented scan profiles with specialized cyber AI models for enhanced code vulnerability detection available via Defender portal and CLI. Microsoft Security Exposure Management supports operational technology (OT) data connectors for Armis, Dragos, and Forescout to integrate OT asset data. June 2026 included new critical asset and identity classification rules for executive-sponsored AI agents, widespread local admins, and multiple SaaS application classifications (such as Microsoft Entra ID, Azure, 365 services). An updated overview dashboard is also previewed to aggregate exposure risks into actionable views.
Why it matters: These enhancements improve vulnerability detection and prioritization capabilities, enable more secure authentication mechanisms, provide broader asset visibility (including OT environments), and improve monitoring and response for critical identities and assets. The addition of AI-augmented scanning could reduce false positives and increase detection accuracy in code repositories. The new classifications help better identify and manage high-risk identities and services to minimize exposure and prevent privilege escalations.Actions: Review and adopt keyless authentication for Microsoft Foundry connections to reduce secret management overhead.; Evaluate enabling Codename MDASH agentic code scanner preview and MAI-Augmented scan profiles to improve code security assessments.Source: https://learn.microsoft.com/en-us/security-exposure-management/whats-newMicrosoft Defender for Endpoint (Linux), Microsoft Defender for Endpoint (Windows), Microsoft Defender for Endpoint (macOS), Microsoft Defender for Endpoint (iOS), Microsoft Defender for Endpoint (Android) - Microsoft primary source - NewSource published: Not available - Material update: 2 Sept 2026, 2:43 pm ISTNew Microsoft Defender for Endpoint Features and Enhancements (June-September 2026)Introduced preview and general availability features in Defender for Endpoint across Linux, macOS, Windows, and mobile platforms such as: WSL container protection, tamper protection audit mode on Linux, antivirus audit mode, offboarding API support for Linux, vulnerability assessment of Microsoft Store apps, enhanced AI agent runtime protection, local AI agent discovery expansion, enhanced deployment tools, and new risk scoring methodologies including internet exposure reduction recommendations.
Why it matters: Security teams gain enhanced visibility and control over cross-platform endpoints including Linux containers and macOS devices, improved deployment and lifecycle management of Defender across Linux systems, and stronger risk prioritization for vulnerability management and internet-facing devices. Audit modes enable performance evaluation before enforcement, reducing risk during adoption. New selective response actions improve protection for critical systems without operational disruption.Actions: Evaluate and enroll in public preview features such as WSL container support and tamper protection audit mode for Linux where applicable.; Leverage antivirus audit mode on Linux to assess detection efficacy before enabling enforcement.Related KQL: Several new features and risk assessments update detection and response capabilities, enabling useful Advanced Hunting queries for tracking deployment status, tampering alerts, vulnerability details, AI agent discovery, and exposure scoring.Source: https://learn.microsoft.com/en-us/defender-endpoint/whats-new-in-microsoft-defender-endpointMicrosoft Defender for Identity sensor (all editions) - Microsoft primary source - NewSource published: Not available - Material update: 2 Sept 2026, 2:43 pm ISTMicrosoft Defender for Identity Sensor v3.x GA and Key Security Updates- GA release of Defender for Identity sensor v3.x with improved coverage and performance. - Transition of several alerts to unified Microsoft Defender alerting format. - Introduced identity-related security posture assessments like inactive service accounts and discoverable passwords. - Added near real-time Microsoft Entra ID risk level to Defender for Identity. - New Graph API preview for sensor actions and remediation. - Bug fixes and improved detection accuracy, including noise reduction. - Deprecation warning for sensor support on Windows Server 2008 R2 starting August 15, 2022.
Why it matters: Operators should plan to upgrade to sensor v3.x to benefit from better performance and coverage. Monitor newly unified alerts and incorporate new security posture assessments for enhanced threat detection. Review deprecated platform usage and migrate off Windows Server 2008 R2. Utilize new Graph APIs for automation and response. Expect reduced alert noise and improved accuracy in detections.Actions: Upgrade Defender for Identity sensors to version 3.x where supported.; Review transitioned alerts in the unified alerting system and update monitoring rules accordingly.Related CVEs: CVE-2020-1472Related KQL: With the new alerts transitioning to the unified format and enhanced detection logic, updating hunting queries using KQL to leverage updated alert names and enriched data is recommended.Source: https://learn.microsoft.com/en-us/defender-for-identity/whats-new-archiveMicrosoft Defender for Cloud, Azure Resource Graph, Microsoft Defender for Storage, AWS Identity and Access Management, Google Cloud IAM - Microsoft primary source - NewSource published: Not available - Material update: 2 Sept 2026, 2:42 pm ISTMicrosoft Defender for Cloud Updates - August and July 2026 Highlights- CVE details data used in Azure Resource Graph queries for vulnerability assessments updated to a new resource type improving performance and scalability. - Classic Defender for SQL APIs for Vulnerability Assessment and Advanced Threat Protection scheduled for retirement on August 16, 2027. - On-demand malware scanning now supports scanning specific blobs, files, containers, and file shares. - Unused actions removed from AWS and GCP overprovisioned identity assessments, impacting related recommendations and workflows. - Legacy grouped recommendations deprecated and replaced by individual recommendations. - Foundational CSPM changed to an opt-in model for new Azure subscriptions starting October 27, 2026. - SQL Vulnerability Assessment database-level recommendations generally available. - Plan enablement API now blocks onboarding to five deprecated Defender plans.
Why it matters: Users and administrators must update related Azure Resource Graph queries to align with new CVE detail data model to avoid incomplete data. Migration away from classic Defender for SQL APIs is necessary before retirement. Security scanning workflows can be optimized with targeted on-demand malware scanning. Existing automated workflows relying on unused actions in AWS and GCP identity assessments need review due to their removal. Customers need to adjust to individual recommendations from legacy grouped recommendations and prepare for Foundational CSPM opt-in changes for new subscriptions. Deprecated plans must not be onboarded using the plan enablement API.Actions: Review and update Azure Resource Graph queries to consume CVE details from the microsoft.security/cvedetails resource type.; Plan and execute migration from classic Defender for SQL APIs to the supported configuration model before August 16, 2027.Source: https://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notesMicrosoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Entra ID - Microsoft primary source - NewSource published: Not available - Material update: 2 Sept 2026, 2:42 pm ISTMicrosoft Defender for Identity - New Features and Updates from March to August 2026- Automatic Windows event auditing expanded to AD FS, AD CS, and Entra Connect servers - Defender for Identity sensor v3.x migration moved to general availability, including support for Windows Server 2025 domain controllers - New security alerts added covering a comprehensive range of identity-related risks in Entra ID, Active Directory, and third-party identity providers - Identity risk scoring became generally available with detailed risk factor insights - Increased sensor count limit to 1,000 per workspace - Introduction of Identity Explorer for visualizing identity attack paths - Custom account correlation rules introduced in preview - Automatic configuration of RPC auditing on domain controllers after sensor upgrade - Expanded SaaS app support for Password protection including integrations with Defender for Cloud Apps
Why it matters: Organizations using Microsoft Defender for Identity should plan sensor migrations to v3.x where supported, particularly updating domain controllers including Windows Server 2025 after support is available. They should monitor and investigate new security alerts across Entra ID, Active Directory, and other identity providers. The expanded automatic auditing reduces deployment effort but requires validation. Increased sensor capacity allows scaling in large environments. Newly available features like Identity Explorer and custom account correlation rules enable better identity risk and attack path investigations. Overall, these updates enhance detection and security posture while requiring some operational attention for upgrades and configuration verification.Actions: Review and plan migration to Defender for Identity sensor v3.x on supported servers, including Windows Server 2025 domain controllers when supported.; Enable and verify automatic Windows event auditing and RPC auditing configurations post sensor upgrade.Related KQL: New security alerts and features provide enhanced detection and investigation capabilities that can be leveraged with KQL queries for hunting and monitoring.Source: https://learn.microsoft.com/en-us/defender-for-identity/whats-newMicrosoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Cloud, Microsoft Defender for Identity, Microsoft Defender for Office 365, Microsoft Defender Experts for Servers, Microsoft 365 Copilot agent ecosystem - Microsoft primary source - NewSource published: Not available - Material update: 2 Sept 2026, 2:42 pm ISTJuly 2026 Microsoft Defender XDR Updates: AI Agent Posture Risk, Domain Investigation, Threat Detection Enhancements, and More- Added AI agent posture risk assessment feature evaluating risk indicators on endpoint AI agents. - GA Domain investigation page for Active Directory domain security analysis. - Preview threat detection for Microsoft Agent 365 agents analyzing runtime signals. - GA real-time protection blocking risky interactions on Agent 365 tooling servers. - Restricted phishing and security alert triage agent permissions to least privilege. - Preview entity threat intelligence enrichments integrated directly in investigation workflow. - Preview new Identity Security dashboard card for human identities across sources. - Enhancements to SaaS identity coverage and maturity views. - Preview local AI agent discovery on Windows endpoints showing inventory and exposure. - Preview local AI agent runtime protection to block risky activity. - Advanced hunting updates with new GA and preview schema tables for improved visibility. - New standalone managed detection and response services for servers. - Preview automatic attack disruption can isolate compromised devices during incidents. - Advanced hunting improvements including allow/block actions and new identity attack path scenarios. - Preview Defender Chat assistant to help SOC analysts investigate and query in natural language.
Why it matters: Security operations teams gain enhanced visibility into AI agents and Active Directory security posture, improved threat detection including for AI agents, and greater control over automatic attack disruption actions. The new runtime protections and permission restrictions improve endpoint security posture and reduce unnecessary data access. Advanced hunting schema updates and new attack path scenarios enable more effective investigations and threat hunting. The Defender Chat assistant aims to improve SOC analyst efficiency. New managed services options provide extended detection and response for on-premises/multicloud servers.Actions: Review and integrate AI agent posture risk reports into risk prioritization workflows.; Utilize Domain investigation page for holistic Active Directory security analysis.Related KQL: New advanced hunting schema updates and tables introduced requiring query updates and enabling more detailed hunting capabilities.Source: https://learn.microsoft.com/en-us/defender-xdr/whats-newMicrosoft Defender for Office 365 Plan 1, Microsoft Defender for Office 365 Plan 2, Microsoft 365 E3, Microsoft Teams - Microsoft primary source - NewSource published: Not available - Material update: 2 Sept 2026, 2:42 pm ISTMicrosoft Defender for Office 365 latest feature updates including prompt injection protection and RBAC enhancements- Prompt injection attacks detection in emails - Unified RBAC as default for new Plan 2 organizations starting July 2026 - Microsoft Defender for Office 365 Plan 1 now included in Microsoft 365 E3 - Enhanced Teams message and call reporting (including calls and contextual messages) - Near real-time URL protection in Teams messages - Mail bombing attack detection added - AI-powered generative explanations for admin submissions - New RBAC permissions for email content associated with alerts - Expanded zero-hour auto purge (ZAP) and admin quarantine to Plan 1 - Email actions in Advanced Hunting for easier investigation and response - Ability to block malicious domains and sender emails in Teams portal - Localized default notification emails based on user language settings
Why it matters: Security teams gain improved tools for detection and response including new attack detections (prompt injection, mail bombing), enhanced reporting and quarantine capabilities in Teams, better role-based access control, and streamlined investigation workflows. The inclusion of Defender Plan 1 in Microsoft 365 E3 may affect licensing and deployment strategies. Blocking malicious senders and domains more quickly and with real-time effects improves operational protection.Actions: Review and understand prompt injection attack detection capabilities for incident response; Prepare for unified RBAC becoming default for new Defender for Office 365 Plan 2 tenants starting July 2026Related KQL: New advanced hunting email actions and detection method values support hunting and automated response.Source: https://learn.microsoft.com/en-us/defender-office-365/defender-for-office-365-whats-newMicrosoft Defender for Cloud, Azure SQL Server Vulnerability Assessment - Microsoft primary source - NewSource published: Not available - Material update: 2 Sept 2026, 2:42 pm ISTMicrosoft Defender for Cloud Security Recommendations and Alerts UpdatesThe retirement of legacy grouped (sub-assessment) recommendations commenced, removing their API accessibility and eventual portal reflection delays. Defender for Cloud introduced multiple individual security recommendations targeting SQL Server databases, replacing broader server-level grouped recommendations. This provides detailed guidance on permissions, authentication, auditing, encryption, configuration, and unnecessary features for SQL Servers and databases.
Why it matters: Organizations using Defender for Cloud must transition to the new individual database-level recommendations for SQL Vulnerability Assessment and update any automated processes or scripts relying on deprecated grouped recommendations' data. Security posture management should leverage the granular controls for improved risk identification and mitigation in SQL Server environments.Actions: Review the list of new SQL Server database-level recommendations and implement applicable security controls.; Modify scripts or tools that depend on deprecated grouped recommendations data from the Defender for Cloud API.Source: https://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes-recommendations-alertsMicrosoft Exchange Server - Non-Microsoft reporting - Materially updatedSource published: 2 Sept 2026, 5:40 pm IST - Material update: 11 Aug 2026, 10:13 pm ISTActive Exploitation of CVE-2026-62911 on Microsoft Exchange ServersNew evidence confirms active exploitation of the CVE-2026-62911 vulnerability across many Microsoft Exchange servers globally, leading to compromised systems and potential data breaches.
Why it matters: Organizations with unpatched Microsoft Exchange servers are at high risk of remote code execution attacks that can lead to unauthorized access, data theft, and disruption of email services.Actions: Apply the latest Microsoft Exchange security updates addressing CVE-2026-62911 immediately.; Audit Exchange server configurations and logs for signs of compromise.Related CVEs: CVE-2026-62911Related KQL: Detection queries can identify exploitation attempts and lateral movement related to CVE-2026-62911 activity.Source: https://cybersecuritynews.com/