Microsoft Security Blog
Your source for the latest in cybersecurity
Featured Posts
​​​​​​​​What’s new in Microsoft Security: September 2026​​
This month’s updates help you discover and control local AI agents, extend Zero Trust to agent traffic, and strengthen SOC foundations.
From guidance to action: Security fundamentals that materially reduce riskÂ
AI has made fundamental changes to the operating environment for cybersecurity.
Improving email security outcomes with real-world Microsoft Defender insights
The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve.
Stay ahead of threats
Get expert insights, threat intelligence, and the latest cybersecurity reports from Security Insider.
AI and machine learning
-
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders. -
​​​​​​​​What’s new in Microsoft Security: September 2026​​
This month’s updates help you discover and control local AI agents, extend Zero Trust to agent traffic, and strengthen SOC foundations. -
Reimagining the SOC for the agentic era in Microsoft Defender
We are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for SIEM and threat protection together.
Modernize your security operations center
Confidently secure your multicloud, multiplatform environment with Microsoft Sentinel – a cloud-native security information and event management (SIEM) solution.
Latest posts
-
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders. -
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment. -
​​​​​​​​What’s new in Microsoft Security: September 2026​​
This month’s updates help you discover and control local AI agents, extend Zero Trust to agent traffic, and strengthen SOC foundations. -
Reimagining the SOC for the agentic era in Microsoft Defender
We are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for SIEM and threat protection together. -
From guidance to action: Security fundamentals that materially reduce riskÂ
AI has made fundamental changes to the operating environment for cybersecurity.