Skip to content
Microsoft Security Blog

Microsoft Security Blog

www.microsoft.com September 7, 2026

Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps

Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative

Beyond the benchmark: Advancing security at AI speed

Stay ahead of threats

Get expert insights, threat intelligence, and the latest cybersecurity reports from Security Insider.

AI and machine learning

August 27 2 min read ​​​​​​What’s new in Microsoft Security: August 2026 This month’s updates provide new capabilities to help organizations gain insights into agent activity, expand security coverage across supported environments, and enhance security management across their environments.

​​​​​​What’s new in Microsoft Security: August 2026

August 25 6 min read The patch window is collapsing: Why security needs a new control plane Organizations need protection that operates in the gap between discovery and remediation.

The patch window is collapsing: Why security needs a new control plane

Modernize your security operations center

Confidently secure your multicloud, multiplatform environment with Microsoft Sentinel – a cloud-native security information and event management (SIEM) solution.

September 4 6 min read How to secure edge AI in customer-owned environments As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models.

How to secure edge AI in customer-owned environments

September 2 16 min read Impersonating IT support: how threat actors turn a remote session into enterprise-wide access Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

September 1 18 min read Counterfeit installers to system compromise: Tracking a deceptive software download campaign An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives.

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

September 1 4 min read Cybersecurity IR Workshop: The workshop you shouldn’t miss Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response.

Cybersecurity IR Workshop: The workshop you shouldn’t miss

August 28 16 min read TerminalFix campaign deploys a reverse tunnel through multistage intrusion Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

Extracted Entities

Attack Types (1)

Campaigns (1)

Malware (1)

MITRE ATT&CK (1)

Tools (1)