September 2026

Protecting organizations from AI-assisted executive impersonation and invoice fraud

In this article Attack chain overview Email Delivery Domain registration Generative AI usage Mitigation and protection guidance Microsoft Defender detections Microsoft Security Copilot Threat intelligence reports MITRE ATT&CK Techniques observed Indicators of compromise (IOC) Learn More Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims,

Protecting organizations from AI-assisted executive impersonation and invoice fraud Read More »

Detect and disrupt AI-themed attacks with Microsoft Defender

Every wave of technology excitement creates a new opportunity for cyberattackers, and AI is no exception. Microsoft Threat Intelligence has published research showing a growing set of campaigns that impersonate popular AI platforms and tools, including ChatGPT, Microsoft Copilot, DeepSeek, and Claude.1 The goal is to make phishing, search-driven malware campaigns, and malvertising—which is malicious

Detect and disrupt AI-themed attacks with Microsoft Defender Read More »

Unmasking EvilTokens: Getting to the root of device code phishing

In this article What is device code phishing? EvilTokens platform and operations EvilTokens phishing emails Mitigation and protection guidance Microsoft Defender XDR detections Hunting queries Following its emergence in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, providing cybercriminals with AI capabilities for tailoring phishing lures and analyzing compromised

Unmasking EvilTokens: Getting to the root of device code phishing Read More »

From guidance to action: Security fundamentals that materially reduce risk 

AI has already made fundamental changes to the operating environment for cybersecurity. Cyberattackers are testing more paths, adapting their techniques, and moving across digital environments with greater speed and persistence. The weaknesses they exploit remain familiar: excessive permissions, unprotected authentication flows, unpatched systems, exposed execution paths, and gaps between controls. What has changed is how

From guidance to action: Security fundamentals that materially reduce risk  Read More »

Vivid orange killifish discovered in the Brazilian Amazon

Researchers have described a new species of brilliantly coloured fish from a network of forest streams in the Brazilian Amazon, and have already recommended it for listing as Endangered because of the pressures facing its only known home. The fish, named Laimosemion laranja, is a killifish measuring less than three centimeters in standard length. Males

Vivid orange killifish discovered in the Brazilian Amazon Read More »