Uncategorized

Detect and disrupt AI-themed attacks with Microsoft Defender

Every wave of technology excitement creates a new opportunity for cyberattackers, and AI is no exception. Microsoft Threat Intelligence has published research showing a growing set of campaigns that impersonate popular AI platforms and tools, including ChatGPT, Microsoft Copilot, DeepSeek, and Claude.1 The goal is to make phishing, search-driven malware campaigns, and malvertising—which is malicious

Detect and disrupt AI-themed attacks with Microsoft Defender Read More »

Protecting organizations from AI-assisted executive impersonation and invoice fraud

In this article Attack chain overview Email Delivery Domain registration Generative AI usage Mitigation and protection guidance Microsoft Defender detections Microsoft Security Copilot Threat intelligence reports MITRE ATT&CK Techniques observed Indicators of compromise (IOC) Learn More Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims,

Protecting organizations from AI-assisted executive impersonation and invoice fraud Read More »

Improving email security outcomes with real-world Microsoft Defender insights

Every benchmark tells a story. The most valuable ones tell us where to improve next. For five consecutive quarters Microsoft has published email security benchmarking reports to provide greater transparency into real-world protection outcomes. The results have shown strong Microsoft Defender performance across pre-delivery and post-delivery scenarios, while revealing where threats and defenses continue to

Improving email security outcomes with real-world Microsoft Defender insights Read More »

Unmasking EvilTokens: Getting to the root of device code phishing

In this article What is device code phishing? EvilTokens platform and operations EvilTokens phishing emails Mitigation and protection guidance Microsoft Defender XDR detections Hunting queries Following its emergence in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, providing cybercriminals with AI capabilities for tailoring phishing lures and analyzing compromised

Unmasking EvilTokens: Getting to the root of device code phishing Read More »

From guidance to action: Security fundamentals that materially reduce risk 

AI has already made fundamental changes to the operating environment for cybersecurity. Cyberattackers are testing more paths, adapting their techniques, and moving across digital environments with greater speed and persistence. The weaknesses they exploit remain familiar: excessive permissions, unprotected authentication flows, unpatched systems, exposed execution paths, and gaps between controls. What has changed is how

From guidance to action: Security fundamentals that materially reduce risk  Read More »