August 2026 Patch Tuesday: Windows flaw is exploited

Patch Tuesday - exploited Windows flaw CVE-2026-68820

Microsoft has released the August 2026 Security Updates. For small and midsized businesses, the key point is not the sheer number of vulnerabilities but one Windows issue that Microsoft already marks as exploited: CVE-2026-68820 in the Windows Ancillary Function Driver for WinSock. In the Security Update Guide, Microsoft lists it as “Exploitation Detected”. That moves … Read more

DeadLock ransomware: Microsoft lists Defender protections

DeadLock ransomware – Defender protections

Microsoft Threat Intelligence describes DeadLock as a ransomware operation observed since July 2025 that combines encryption, data theft, and a resilient recovery and leak infrastructure. The new Microsoft report matters for organizations that protect Windows endpoints with Microsoft Defender and Defender XDR: it does not only describe malware internals, but also lists concrete settings that … Read more

Conditional Access: custom controls are being retired

Conditional Access - custom controls retire in May 2027

Microsoft is retiring custom controls in Conditional Access and replacing them with external MFA. From September 2026, no new custom controls can be created and existing ones can no longer be edited; in May 2027 the feature is switched off entirely. This affects every company that has plugged a third-party provider such as Duo, RSA … Read more

Passkeys become the default in Entra ID as SMS MFA ends

Passkeys become the default in Microsoft Entra ID

Microsoft is making passkeys the default sign-in experience in Microsoft Entra ID and ending its own delivery of one-time codes by SMS and voice call. From 1 September 2026, users currently enabled for SMS or voice will be automatically enabled for passkeys and prompted to register one at their next sign-in with MFA. From 1 … Read more

Defender XDR isolates devices automatically in 128 seconds

Defender XDR – Automatic device isolation in 128 seconds

Microsoft is extending automatic attack disruption in Defender XDR with a new response action. When the system identifies a compromised workstation as an active attack foothold with high confidence, it can isolate the device from the network automatically. In an incident documented by Microsoft at QNET, only 128 seconds passed between the first detection and … Read more