< ciso
brief />
Tag Banner

All news with #microsoft defender xdr tag

51 articles

Microsoft adds integrated SOC features to Defender

๐Ÿ”’ Microsoft now offers Integrated Security Operations Center (ISOC) capabilities inside Microsoft Defender for Microsoft 365 E5 and E7 customers at no extra license cost during public preview. ISOC combines SIEM-like functions with Defender XDR, threat intelligence, automation and AI in a single portal, and ingests Microsoft product logs without charges. From Oct. 1, third-party data ingestion will be metered at $2.40 per GB, and more advanced features require an ISOC workspace and Azure subscription.
read more โ†’

New Microsoft Defender zero-day blocks updates

๐Ÿ›ก๏ธ A security researcher, Abdelhamid Naceri (aka Nightmare Eclipse), released a proof-of-concept named BigDiskBuster that prevents Microsoft Defender from applying definition and platform updates while it runs in the background. The researcher says the tool affects all supported Windows versions and resembles prior PoCs like UnDefend, though it is described as somewhat buggy. Microsoft did not immediately comment on the report and some earlier flaws disclosed by the researcher remain unpatched.
read more โ†’

Detect and Disrupt AI-Themed Attacks with Defender

๐Ÿ›ก๏ธ Microsoft Threat Intelligence outlines how attackers are leveraging AI brands like ChatGPT and Copilot to craft convincing phishing, malvertising, and malware campaigns that exploit urgency and trust. Microsoft Defender provides layered defensesโ€”anti-phishing, Safe Links, Safe Attachments, and post-delivery filteringโ€”and correlates signals across email, identities, endpoints, and SaaS to detect and disrupt multi-stage attacks. Attack disruption has contained tens of thousands of compromises monthly, illustrating the value of connected prevention, detection, and response.
read more โ†’

Microsoft Defender misclassifies Google search URLs

๐Ÿ” Microsoft is investigating why Defender for Office 365 is incorrectly showing โ€œOpening this website might not be safeโ€ for legitimate Google search links. The company logged the incident as MO1465962 and says the root cause is an inaccurate security classification; copying and pasting the links does not avoid the block. Admins may see related alerts in Microsoft Sentinel and the Defender portal; Microsoft is working to remediate the misclassification.
read more โ†’

Counterfeit installers enable persistent system compromise

๐Ÿ›ก๏ธ Microsoft Defender Experts are tracking an active campaign that uses counterfeit software-download sites impersonating trusted vendors to distribute malicious installers. The campaign targets users seeking popular software and has caused compromises across multiple industries, with a concentration on China-based operations and Chinese-speaking users. The malicious installers establish persistence, evade defenses, and communicate with attacker infrastructure; Microsoft disrupted activity and recommends enabling protections such as SmartScreen, network protection, tamper protection, and Microsoft Defender XDR.
read more โ†’

August 2026 Microsoft Security updates overview

๐Ÿ›ก๏ธ This update details new Microsoft Security capabilities for August 2026, focusing on AI agent visibility, broader threat coverage, and improved management across environments. Highlights include expanded Microsoft Defender Experts MDR coverage for third-party data sources, Microsoft Entra Tenant Governance for multi-tenant visibility, and Windows device management improvements. Other updates boost data protection with increased auto-labeling throughput in Microsoft Purview and introduce Secure Now guidance for agentic containment.
read more โ†’

Microsoft Defender driver can be abused for kernel ops

๐Ÿ”’ Check Point Research demonstrated that Microsoft Defender's boot-time remediation driver, BTR.sys, can be repurposed to perform arbitrary kernel-level file and registry operations on Windows 7 through Windows 11 25H2 without exploiting a software flaw. The researcher published a proof-of-concept tool, BTR_CLI, and presented results at Black Hat USA 2026 and DEF CON 34, showing the driver can delete or move protected binaries and schedule actions for the next reboot. The technique requires administrative privileges (SeLoadDriverPrivilege) and leverages the driver's embedded RC4-encrypted protocol, making the component difficult to block without disrupting Defender. Check Point reported no evidence of real-world abuse and shared detection indicators and mitigation guidance focused on restricting SeLoadDriverPrivilege.
read more โ†’

Hunting MacSync Stealer via behavioral pivots

๐Ÿ” Microsoft Defender Experts expanded earlier reporting on MacSync Stealer, a macOS information stealer that rotates infrastructure rapidly. The investigation correlated recurring command-line, request, and upload traits to link over 30 domains and show active staged collection and chunked HTTP PUT exfiltration. The write-up maps payload retrieval, C2 check-in, collection, staging, and cleanup to durable hunting pivots.
read more โ†’

Microsoft Named Leader in 2026 MDR/MXDR Report

๐Ÿ”’ Microsoft announced it was named a Leader in the 2026 IDC MarketScape: Worldwide MDR/MXDR for the Enterprise. Microsoft Defender Experts MDR is a 24/7 managed detection and response service that operates natively on Microsoft Defender, combining global threat intelligence, AI-assisted workflows, and human experts. The service emphasizes continuous detection improvements, proactive hunting, and clear incident reporting to extend customer SOC capabilities.
read more โ†’

Microsoft Security: July 2026 innovations and updates

๐Ÿ”’ Microsoft announced new AI-native security capabilities across Defender, Entra, Purview, and Intune to help organizations secure AI environments, accelerate SecOps, and protect data and identities. Highlights include Project Perception, expanded Defender protections like prompt injection blocking, tenant governance and passkey defaults in Entra, Purview network-level DLP for shadow AI apps, and Intune Suite inclusion in Microsoft 365 E5 to strengthen endpoint management.
read more โ†’

ACR Stealer campaigns use ClickFix lures and fileless tradecraft

๐Ÿ” Microsoft Defender Experts observed heightened ACR Stealer activity from late April to mid-June 2026, using ClickFix social engineering to lure users into running commands that ultimately harvest browser credentials, tokens, and sensitive documents. Two prevalent campaigns were detailed: one using WebDAV-delivered DLLs, staged PowerShell, Python loaders, and optional blockchain-backed dead-drop C2 resolution; the other using fileless MSHTA, obfuscated PowerShell, and steganography-assisted in-memory execution. Both aim to exfiltrate credentials and enterprise data, and Microsoft recommends monitoring for ClickFix lures, suspicious WebDAV/MSHTA activity, obfuscated PowerShell, and attempts to access browser credential stores while leveraging Defender capabilities to detect and respond.
read more โ†’

Microsoft patches RoguePlanet Defender flaw

๐Ÿ›ก๏ธ Microsoft released a security update addressing a privilege escalation bug in the Microsoft Malware Protection Engine, tracked as CVE-2026-50656. The issue, dubbed RoguePlanet, is a race condition that can allow an attacker to spawn a SYSTEM-level shell to run arbitrary code. The fix is included in engine version 1.1.26060.3008 and includes defense-in-depth hardening.
read more โ†’

Microsoft named a leader in Frost Radar for CARS

๐Ÿ”’ Microsoft highlights its recognition in Frost & Sullivanโ€™s 2026 Frost Radar for Cloud/Application Runtime Security, emphasizing a shift from visibility to contextual risk reduction across cloud infrastructure, applications, APIs, and runtimes. The post explains how Microsoft Defender for Cloud integrated with Microsoft Defender XDR correlates posture, identity, data, and runtime signals to prioritize exploitable attack paths. It argues that unified platforms reduce alert fatigue, speed remediation, and enable continuous risk operations across development and runtime.
read more โ†’

June 2026 Microsoft Security product updates

๐Ÿ”’ This update summarizes June 2026 releases across Microsoft Security that strengthen identity, multicloud, data, and developer protections. Highlights include codename MDASH for multi-model agentic vulnerability scanning, expanded Microsoft Defender agent and MCP detection, GA for Microsoft Entra Backup and Recovery, and extended database threat protection for AWS RDS. New reporting, multicloud coverage, and a unified identity risk score help teams detect, prioritize, and recover faster.
read more โ†’

CISA: BlueHammer bug now exploited by ransomware

๐Ÿ›ก๏ธ CISA confirms ransomware actors are exploiting the high-severity Microsoft Defender privilege escalation flaw dubbed BlueHammer (CVE-2026-33825). The bug was leaked with proof-of-concept code by researcher "Nightmare Eclipse" in April and later patched by Microsoft on April 14. CISA added the flaw to its KEV Catalog and ordered federal agencies to patch, and has now flagged it as used in ransomware campaigns.
read more โ†’

Microsoft named Leader in Forrester XDR Wave 2026

๐Ÿ›ก๏ธ Microsoft has been named a Leader in The Forrester Waveโ„ข: Extended Detection and Response Platforms, Q2 2026, earning the top Strategy and Vision scores. The report highlights Microsoft Defender and Microsoft Threat Intelligence for high marks across identity detection, cloud detection, SIEM replacement, threat hunting, and more. Microsoft emphasizes an XDR foundation that unifies signals across identities, endpoints, email, SaaS, and cloud workloads to enable coordinated, AI-assisted attack disruption and faster SOC operations.
read more โ†’

Microsoft Confirms RoguePlanet Defender Zero-Day

๐Ÿ›ก๏ธ Microsoft disclosed it is preparing a patch for a Defender zero-day tracked as RoguePlanet, now identified as CVE-2026-50656 with a CVSS score of 7.8. The company classifies the issue as a privilege escalation in the Microsoft Malware Protection Engine and says it is working on a quality security update. The exploit was publicly released by researcher Chaotic Eclipse (aka Nightmare-Eclipse), who described it as a race condition that can yield SYSTEM-level shells and may work irrespective of real-time protection settings.
read more โ†’

AI-Driven Identity Security: Microsoft Entra Updates

๐Ÿ”’ AI is accelerating cyberattacks, increasing speed and scale across the attack chain while identity remains a primary entry point. Microsoft highlights integrated visibility and response through Microsoft Entra and Microsoft Defender, including a unified identity risk score and an updated Entra ID Protection experience. New features aim to reduce fragmentation, enable least-privilege response roles, and automate policy optimization to help teams prevent, detect, and respond faster.
read more โ†’

Microsoft developing patch for Defender RoguePlanet zero-day

๐Ÿ”’ Microsoft is investigating and preparing a security update for a Microsoft Defender elevation-of-privilege vulnerability publicly dubbed RoguePlanet. The flaw, now tracked as CVE-2026-50656, was disclosed with a proof-of-concept last week and reportedly allows spawning SYSTEM-level command prompts via a Defender race condition on fully patched Windows 10 and 11 devices. Microsoft confirmed it is working on a high-quality security update and will publish details in the CVE entry when available.
read more โ†’

Microsoft previews automatic device isolation feature

๐Ÿ›ก๏ธ Microsoft is previewing an automatic device isolation feature in Defender for Endpoint to help contain active cyberattacks by severing most network traffic while preserving connections to security services. The capability is part of its auto attack disruption tool within Defender XDR, and Microsoft says actions are time-limited and can be tuned or reversed by administrators. A new SANS Institute paper warns threshold-driven autonomous containment can be weaponized to disable user accounts, underscoring the need for careful configuration and governance.
read more โ†’