Review Teams helpdesk impersonation with Defender XDR

Teams helpdesk - Review Defender XDR signals

Microsoft Threat Intelligence reports an active campaign in which external contacts in Microsoft Teams impersonate IT or helpdesk staff. The entry point is not a Teams vulnerability, but a trusted-looking support workflow: the user is persuaded to start or approve a remote session, after which the operator uses PowerShell to download and silently install an … Read more

Review counterfeit installers with Defender XDR

Fake Installer - Review Defender XDR signals

Microsoft Defender Experts is tracking an active campaign in which attackers use counterfeit software download pages to deliver malware through installers that appear legitimate. For small and midsized businesses, this matters because the entry point looks ordinary: a browser, a ZIP archive, and an installer. Microsoft, however, describes a chain with persistence, Microsoft Defender tampering, … Read more

Entra CAE: Revoke service principal tokens faster

Microsoft Entra CAE - revoke service principal tokens

Microsoft describes an important Entra update for automated access: access tokens issued to service principals can be made unusable faster with Continuous Access Evaluation when a workload identity is disabled, deleted, or detected as risky. For small and midsize organizations, this matters because scripts and integrations often run with broad application permissions. If a secret … Read more

Review reverse tunnels with Defender

TerminalFix - Review reverse tunnels with Microsoft Defender

Microsoft Threat Intelligence is warning about a TerminalFix campaign that extends the familiar ClickFix tactic: a fake Cloudflare CAPTCHA page tricks users into running a copied terminal command themselves. For small and midsized businesses, this matters because the attack does not stop at a simple infostealer after first execution. Microsoft describes a multistage chain with … Read more

Microsoft Entra: Review custom CSS by October

Microsoft Entra - CSS review for branded sign-ins

Microsoft Entra ID is restricting custom branding for sign-in pages. Beginning October 26, 2026, custom CSS layout and positioning properties will be blocked globally. Organizations that styled their Microsoft 365 sign-in experience with custom CSS should review it now. Logos, images, and text generally remain available, but affected rules for positioning, spacing, visibility, or overlapping … Read more