Defender: Review Linux Memory Scan and WSLc

Microsoft Defender – Review Linux Memory Scan and WSLc

Microsoft updated the “What’s new” page for Microsoft Defender for Endpoint in early September 2026 with two preview notes that matter especially to smaller IT teams running Linux servers or developer endpoints with WSL. Microsoft now lists Memory Scan for Linux and plug-in support for WSL containers. Neither item calls for a rushed rollout, but … Read more

Entra Security Administrator: Review role by end of September

Microsoft Entra Security Administrator - role review September 2026

Microsoft is expanding the built-in Security Administrator role in Microsoft Entra. In the September edition of the Entra blog, Microsoft announced additional response actions for non-privileged users: disabling and enabling accounts, revoking active sessions, and forcing password resets. The rollout is expected to be completed by the end of September 2026. For smaller IT teams, … Read more

ASCII smuggling: Review phishing with Defender

ASCII smuggling - phishing detection in Microsoft Defender

Microsoft Threat Intelligence describes a phishing campaign that moves a technique known from AI security research into conventional email attacks: ASCII smuggling. The attackers inserted invisible Unicode tag characters into words such as “funding” so filters or tokenizers no longer saw one clean string. Microsoft also gives concrete detection and protection guidance for Microsoft Defender … Read more

Review Teams helpdesk impersonation with Defender XDR

Teams helpdesk - Review Defender XDR signals

Microsoft Threat Intelligence reports an active campaign in which external contacts in Microsoft Teams impersonate IT or helpdesk staff. The entry point is not a Teams vulnerability, but a trusted-looking support workflow: the user is persuaded to start or approve a remote session, after which the operator uses PowerShell to download and silently install an … Read more

Review counterfeit installers with Defender XDR

Fake Installer - Review Defender XDR signals

Microsoft Defender Experts is tracking an active campaign in which attackers use counterfeit software download pages to deliver malware through installers that appear legitimate. For small and midsized businesses, this matters because the entry point looks ordinary: a browser, a ZIP archive, and an installer. Microsoft, however, describes a chain with persistence, Microsoft Defender tampering, … Read more