< ciso
brief />
Tag Banner

All news with #microsoft tag

946 articles · page 7 of 48

Microsoft switches Windows backup to default-on for orgs

🛡️ Microsoft will enable the Windows settings backup and restore tool by default on Microsoft Entra-joined and Entra hybrid-joined enterprise devices when they upgrade to Windows 11 version 26H2. The feature, introduced as opt-in at Ignite 2024 and GA in August 2025, previously required admins to turn it on after installing the September 2025 cumulative update. Default-on applies only to eligible devices outside DMA-regulated regions and not in sovereign cloud environments, and explicit admin policies via Intune or Group Policy still take precedence. Restore remains disabled by default and requires explicit admin configuration.
read more →

Microsoft tests Cloud Rebuild for Windows 11 recovery

🛠️ Microsoft is testing the new Cloud Rebuild recovery option in Windows 11 Insider Experimental Preview Build 26300.8772, enabling a full OS reinstall from the cloud when devices become inoperable. The feature downloads the target Windows image and device drivers from Windows Update, restoring functionality without USB media or a custom image. Insiders can initiate the process from WinRE under Troubleshoot > Recovery and must confirm a data-loss warning before the rebuild proceeds.
read more →

Massive Microsoft 365 password spray attack exposed

🔒 Microsoft users experienced a large-scale automated password spray campaign that targeted accounts indiscriminately, including clients of security firm Huntress. Huntress reported 81 million login attempts against its customers between June 12 and 26, with at least 78 successful compromises. Attack traffic originated from an IPv6 range tied to LSHIY LLC, which has since cut service to the offending customer. The attackers abused the OAuth ROPC flow to replay valid credentials, bypassing protections where MFA was not enforced for all cloud apps or all user groups.
read more →

Improving security across Microsoft partner ecosystem

🔒 This post by Raji Dani, Microsoft Deputy CISO, explains how Microsoft secures its partner ecosystem—especially Microsoft Cloud Solution Providers (CSPs)—to reduce risk to downstream customers. It outlines vetting, mandatory security requirements for authorization, granular delegated administrative privileges (GDAP), telemetry and rapid access revocation capabilities. The article emphasizes shared responsibility between Microsoft and partners and a continual roadmap to raise security standards.
read more →

CISA Adds SharePoint RCE CVE-2026-45659 to KEV Catalog

🔒 CISA has added a high-severity SharePoint Server vulnerability, CVE-2026-45659 (CVSS 8.8), to its Known Exploited Vulnerabilities catalog following evidence of active exploitation. Microsoft patched the deserialization-based remote code execution flaw in May 2026 for SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. The issue can be triggered by any authenticated attacker with as little as Site Member permissions and does not require elevated privileges. Federal agencies are advised to apply updates by July 4, 2026, while Microsoft assesses public exploitation as "Exploitation Less Likely."
read more →

Microsoft named a leader in Frost Radar for CARS

🔒 Microsoft highlights its recognition in Frost & Sullivan’s 2026 Frost Radar for Cloud/Application Runtime Security, emphasizing a shift from visibility to contextual risk reduction across cloud infrastructure, applications, APIs, and runtimes. The post explains how Microsoft Defender for Cloud integrated with Microsoft Defender XDR correlates posture, identity, data, and runtime signals to prioritize exploitable attack paths. It argues that unified platforms reduce alert fatigue, speed remediation, and enable continuous risk operations across development and runtime.
read more →

Microsoft restores GIFs in Windows Emoji Panel

🛠️ Microsoft has restored GIF functionality in the Windows Emoji Panel after Tenor retired its API on June 30, causing GIF options to show as 'GIF service is not available' for some users. The company switched the provider to GIPHY in the preview KB5095093 cumulative update for Windows 11 24H2/25H2/26H1 released on June 23. Users can install the optional update via Settings > Windows Update or the Microsoft Update Catalog. Microsoft is still working on fixes for Windows 11 23H2 and Windows Server 2025.
read more →

Microsoft Accelerates Move to Post‑Quantum Cryptography

🔒 Microsoft announced an acceleration of its Quantum Safe Program to transition critical products and services to post‑quantum cryptography by 2029. The company plans to integrate PQC requirements into its Secure Future Initiative and emphasize crypto‑agility, TLS 1.3 adoption, and protection of trust chains such as code signing and certificates. Microsoft urged organizations to begin migration now due to advances in quantum research and rising risk of 'harvest now, decrypt later.'
read more →

Microsoft Expedites Transition to Post‑Quantum Cryptography

🔒 Microsoft says it is accelerating its move to post-quantum cryptography, citing advances in quantum R&D and a shifting "risk horizon." CTO Mark Russinovich announced a goal to migrate critical products and services to PQC by 2029, and linked the work to its Microsoft Quantum Safe Program and Secure Future Initiative. The company outlined three pillars—upgrading network cryptography to TLS 1.3, building crypto-agility for data at rest, and modernizing crypto trust chains—and provided practical steps for organizations to begin their PQC transition.
read more →

Microsoft accelerates quantum-safe transition to 2029

🔒 Microsoft has accelerated its quantum-safe roadmap, saying advances in quantum computing bring the need to replace current encryption sooner than expected. The company plans to transition critical products and services to post-quantum cryptography (PQC) by 2029 under its Quantum Safe Program and integrate quantum-safe requirements into its Secure Future Initiative. Microsoft emphasizes modernizing infrastructure, enabling crypto-agility, and updating trust chains to ease future migrations.
read more →

Microsoft accelerates quantum-safe security timeline

🔐 Microsoft is advancing its quantum-safe timeline, now targeting transition of critical products and services to post-quantum cryptography by 2029. The company is embedding PQC requirements into its Secure Future Initiative to ensure clear ownership, measurable milestones, and platform readiness. Priorities include modernizing network cryptography, enabling crypto-agility, and securing chains of trust across keys, certificates, and signing. Microsoft urges organizations to begin discovery and modernization now to reduce long-term risk.
read more →

Microsoft Warns of Poisoned MCP Tool Risk

🛡️ New Microsoft research shows attackers can hijack AI agents by poisoning a tool's description so the agent quietly exfiltrates company data. The attack leverages MCP tool descriptions—plain text that agents read—to inject hidden instructions, allowing malicious actions without obvious rule violations. Microsoft recommends treating tool descriptions as system prompts, restricting approved tools, enforcing human approval for risky actions, and monitoring agent identities and behavior.
read more →

Microsoft strengthens bot protections for Teams

🔒 Microsoft introduced a Teams admin policy that prevents third-party bots from joining meetings without organizer approval. The feature, announced earlier in the Microsoft 365 roadmap, will roll out across Windows, macOS, Android, and iOS for multi-tenant and GCC customers. When enabled, Teams detects potential bots, places them in the lobby, identifies them clearly, and prompts organizers to admit them. Microsoft plans further controls such as allow lists, blocking policies, and audit reports to enhance visibility and governance.
read more →

Microsoft adds smarter bot protection to Teams

🛡️ Microsoft introduced a Teams admin policy that prevents third-party bots from joining meetings without organizer approval. The feature, announced in March, will roll out across Windows, macOS, Android, and iOS for standard multi-tenant and GCC clouds. When enabled, Teams detects potential bots, places them in the lobby, clearly identifies them, and prompts organizers to confirm admission. Additional controls planned include allow lists, blocking policies, reports, and audit logs to give admins greater visibility and control.
read more →

Microsoft extends Windows Server 2022 hotpatching until 2027

🛠️ Microsoft has extended hotpatching for Windows Server 2022 Datacenter: Azure Edition through October 2027, one year beyond the mainstream end date of October 2026. This extension is effective immediately and applies only to systems enrolled in Hotpatch updates, preserving the existing monthly hotpatch cadence. Hotpatching applies security fixes to in-memory code of running processes to avoid restarts, though updates from the regular channel still require reboots. The change helps maintain uptime and reduce servicing disruptions while non-hotpatch updates, such as non-security and .NET patches, still need restarts.
read more →

Optimizing PostgreSQL on Azure within VS Code

🔍 Microsoft highlights tighter integration for PostgreSQL on Azure by embedding performance tools directly into Visual Studio Code. The PostgreSQL extension centralizes query authoring, server metrics, Azure‑specific telemetry, and Azure Advisor recommendations to shorten detection-to-resolution time. Enhanced query plan visualization and AI‑assisted analysis help teams troubleshoot and tune queries faster, while schema‑aware authoring and Entra ID integration support secure, consistent workflows at enterprise scale.
read more →

Microsoft extends free Windows 10 ESU to 2027

📰 Microsoft quietly extended free Windows 10 Extended Security Updates (ESU) for consumer devices by one year, now covering devices through October 12, 2027. The change appeared in documentation updates and an editor's note on the Windows Experience Blog dated June 25, 2026. Enrolled users will remain covered automatically, and the consumer ESU remains unavailable for domain-joined or MDM-managed systems. The extension aims to give consumers more time to upgrade to Windows 11 or newer devices.
read more →

Microsoft named Leader in Forrester Wave 2026

🔒 Microsoft is recognized as a Leader in The Forrester Wave™: Endpoint Management Platforms, Q2 2026, reflecting Intune’s role in connecting identity, security, compliance, and AI governance across endpoints. The report highlights Intune’s cross-platform management, AI-powered Endpoint Privilege Management, and integrated Security Copilot features that enable faster remediation and device onboarding. Forrester also cited Microsoft’s partner strategy and licensing value as factors supporting enterprise adoption.
read more →

Amazon RDS Custom adds latest Microsoft SQL Server updates

🛈 Amazon RDS Custom for SQL Server now supports the latest Cumulative Updates (CU) and General Distribution Release (GDR) updates for Microsoft SQL Server, including SQL Server 2019 CU32+GDR (KB5090407) and SQL Server 2022 CU25 (KB5081477). These GDR updates address vulnerabilities described in CVE-2026-40370. You can apply the updates via the Amazon RDS Management Console, AWS SDK, or AWS CLI, and guidance is available in the Amazon RDS Custom User Guide.
read more →

CNAPP evolution: Microsoft aligns with cloud risk platforms

🔍 Cloud security is shifting from mere visibility to context-aware risk reduction across multicloud, Kubernetes, APIs, and AI workloads. The Frost & Sullivan 2026 Frost Radar positions CNAPP as an operational cloud risk platform that correlates posture, workload, identity, data, and runtime signals. Microsoft Defender for Cloud is highlighted among leading vendors for connecting findings into prioritized, actionable attack paths and enabling continuous risk validation across the application lifecycle.
read more →