Defender: Review real-time protection for AI agents

Defender real-time protection for AI agents

Microsoft updated its documentation in September on how Microsoft Defender can monitor AI agents during runtime and block risky actions before they execute. For organizations testing agents in Copilot Studio, Agent 365, or on Windows endpoints, this is more than another portal setting. Agents can access data, call tools, and run commands. Teams should decide … Read more

Review AI-assisted invoice fraud with Defender

Warning symbol for AI-assisted invoice fraud

Microsoft describes an observed campaign using AI-assisted executive impersonation and fraudulent invoices. The attackers posed as internal leaders and as a known vendor, used convincing invoice content, and targeted finance teams. For small and midsize businesses, this matters now because these messages do not look like classic malware. They look like internal approval, a supplier … Read more

Passkey lures: Review cloud identities now

Passkey lures - Review Entra ID and cloud access

Microsoft Security Research reports active cloud-based intrusions in which passkey, MFA, or SSO themes are used as social-engineering pretexts. The point is not that passkeys are weak. Microsoft describes how a convincing passkey message can lead users into adversary-in-the-middle phishing or device-code authentication, after which compromised identities are used across Microsoft Graph, SharePoint, OneDrive, and … Read more

September 2026 Patch Tuesday: Windows flaws are exploited

September 2026 Patch Tuesday - Windows flaws are exploited

Microsoft has released the September 2026 Security Updates and marked two Windows vulnerabilities in MSRC as already exploited. For small and midsized businesses, this is more than a routine patch notice: both issues are local elevation-of-privilege vulnerabilities, both can allow SYSTEM privileges if exploited successfully, and Microsoft marks both with “Customer Action Required: Yes”. What … Read more

Microsoft Purview: Review DLP for Box, Dropbox and Salesforce

Microsoft Purview – Review DLP for non-Microsoft apps

In August 2026, Microsoft extended Microsoft Purview Data Loss Prevention to non-Microsoft connected apps. Microsoft Learn says DLP policies can now detect, monitor, and protect sensitive data at rest in connected SaaS applications such as Box, Dropbox, Google Workspace, and Salesforce. For organizations that use cloud storage beyond Microsoft 365, this is a practical reason … Read more