Browse Security News (287)
Microsoft Security Research and Balaji Venkatesh S break down two ACR Stealer intrusion chains seen in customer environments, showing how ClickFix lures lead to WebDAV- and MSHTA-driven execution, credential theft from browsers via DPAPI, and file staging for exfiltration, with concrete Defender detections, hunting queries, and mitigations.
olivialiu-micro explains how SQL Server 2025 enables governed outbound calls to external AI services while keeping control inside the database security model, including permissions, enablement switches, authentication options, and built-in auditing for REST invocation and external model objects.
Yesenia Yser and Toby Kohlenberg explain why AI agents need to be treated as first-class security principals, with tightly scoped roles, controlled tool access, and end-to-end auditability to prevent quiet permission creep and hard-to-investigate incidents.
Ruben Rios announces a preview of Private Marketplace support in Visual Studio, aimed at organizations that need tighter control over how developers discover and install extensions for security, compliance, and governance reasons.
Microsoft Security Research, Ravikant Tiwari, Sagar Patil, Suriyaraj Natarajan and Arvind Gowda break down a coordinated compromise of the @asyncapi npm organization, where attackers abused a misconfigured GitHub Actions workflow and trusted publishing to ship import-time malware, and they provide concrete indicators, hunting queries, and remediation steps.
Allison summarizes new GitHub secret scanning and public monitoring improvements, including new partner detectors, expanded push protection defaults, a new webhook field to distinguish secret categories, and additional insight cards to help enterprises understand leak attribution and exposure scope.
mk_sunitha explains a secure pattern for calling Microsoft Fabric REST APIs from User Data Functions (UDFs), using a service principal plus Azure Key Vault to keep secrets out of application code while still enabling governed automation like triggering Fabric pipelines and managing workspaces.
Polly Davidson lays out a beginner-friendly roadmap for learning GitHub, from core Git concepts and essential commands to day-to-day collaboration with pull requests, issues, and projects. It also introduces GitHub Actions for CI/CD, GitHub Pages for publishing, and practical security basics like 2FA, secret scanning, Dependabot, and CodeQL.
Aarti Borkar announces Microsoft Defender Experts Threat Intelligence and expanded Microsoft Defender Experts MDR coverage, focused on closing the “intelligence-to-action” gap for security teams. The post explains how curated, expert-led intelligence and managed response workflows are being brought directly into the Defender portal and powered by Microsoft Sentinel.
Allison announces a public preview feature where GitHub code scanning surfaces AI-powered security detections directly on pull requests, helping teams catch issues in languages and frameworks that don’t have native CodeQL coverage. The update explains what’s included, how it runs, enablement requirements, and how billing works via AI credits.
Rahul Bhandari (MSFT) and Tara Overfield recap the July 2026 servicing releases for .NET and .NET Framework, including a list of fixed security vulnerabilities (CVEs) and direct links to release notes, installers, container images, Linux package instructions, and known issues for supported .NET versions.
Allison announces a new default safety behavior in Dependabot: version update pull requests will wait three days after a release appears in its registry, reducing the risk of immediately adopting compromised or broken dependency releases while keeping security updates immediate.
Allison announces a public preview feature in the GitHub Copilot app: the /security-review slash command, which runs an on-demand security review of your in-flight code changes and returns prioritized findings with suggested fixes you can apply and re-check without leaving Copilot.
Allison announces generally available GitHub REST API endpoints for creating, updating, listing, and deleting secret scanning custom patterns across repository, organization, and enterprise scopes, with dry runs and publishing still handled in the UI.
Allison announces a new billing estimate view for GitHub Code Quality in public preview, showing active committers and an estimated monthly license cost so enterprises can understand expected charges before general availability.
Microsoft Security Research and the Microsoft Defender Security Research Team break down ShinyHunters-linked campaigns abusing OAuth trust in Salesforce and related SaaS integrations, then map practical detection and governance steps using Microsoft Defender for Cloud Apps, including new Salesforce connector telemetry, posture insights, and KQL hunting queries.
shiv_narayanan summarizes recent Dataverse Fabric Link updates that make it easier to control which Dataverse tables are synced into Microsoft Fabric, improve production-ready authentication options, and reduce sync latency so operational data shows up faster in OneLake-backed analytics workloads.
ofer announces a new OneLake Architectural Guidance whitepaper and summarizes five repeatable enterprise patterns for building a unified, governed data foundation in Microsoft Fabric, aimed at analytics modernization and AI readiness, including data access unification, medallion architecture, governed data mesh, platform simplification, and external data sharing.
sbaynes announces changes to Microsoft Entra ID authentication: passkeys become the default MFA experience starting September 1, 2026, and Microsoft-provided SMS/voice delivery is retired on February 1, 2027. The post explains why phishing-resistant methods matter and outlines concrete admin steps and a rollout timeline.
Allison announces CodeQL 2.26.0 updates for GitHub code scanning, including Kotlin 2.4.0 support, improved C# Razor Pages dataflow for SQL injection detection, new JavaScript/TypeScript system prompt injection coverage, and multiple query accuracy improvements across Go, Python, Swift, and GitHub Actions.
Allison announces a terminology update in GitHub Secret Scanning that renames detector types to better reflect how secrets are found, while keeping detection behavior unchanged. The post clarifies the difference between provider vs generic secrets and pattern-based vs AI-based detection, and confirms no API or webhook changes.
Salim Chawro summarizes Microsoft’s July 2026 Secure Future Initiative (SFI) progress report, covering measurable improvements in identity and configuration hardening, AI-assisted proactive defense for vulnerability discovery and remediation, and preparations for post-quantum cryptography—plus concrete steps organizations can apply now.
Allison announces a public preview of agentic autofix for GitHub code scanning alerts, where Copilot explores the repo, proposes and validates a fix by rerunning CodeQL, then opens a draft pull request. The post also covers how to trigger it, required licenses, and how AI Credits and Actions minutes are consumed.
sbaynes explains how Microsoft AI collaborated with poet William Sieghart and Gravity Road to build Ode Poetry, a real-time voice experience that transcribes user speech, responds empathetically, and recommends poems using MAI-Transcribe and MAI-Voice, with a strong focus on safety testing and quality iteration.
Tina Schuchman announces general availability updates in Microsoft Foundry, including OpenAI’s GPT‑5.6 model family, a new Asia-Pacific Data Zone, and production-ready hosted agents in Foundry Agent Service. The post also highlights governance features like tracing/evaluation, cost controls, and options for publishing agents to Teams and Microsoft 365 Copilot.
Michael Recachinas explains how GitHub enforced validated repository ownership across a 14,000+ repo organization to unblock security workflows like secret scanning remediation, reduce risk, and make governance and compliance scoping reliable.
Alicia Li summarizes the 2026 Q2 updates for Microsoft Fabric Eventstreams, covering new and updated connectors, the now-GA SQL operator, preview features like mirrored database change feed ingestion and business events publishing, plus AI Skills that generate and deploy eventstream topologies via Fabric REST APIs.
Allison announces a public preview update to GitHub Code Quality that lets organization owners enable or disable Code Quality for a targeted subset of repositories, with optional enforcement to prevent repo admins from changing the setting.
Microsoft Threat Intelligence breaks down GigaWiper, a Golang backdoor that bundles disk wiping, ransomware-like encryption, and system sabotage into modular commands, and maps its C2, persistence, and destructive behaviors to concrete Defender detections and hardening steps defenders can apply.
Wes Steyn shows how to scale a Microsoft Agent Framework “claw” using the Agent Harness: on-demand skills (including centrally managed Foundry skills via MCP), approval-gated shell access, CodeAct for sandboxed code execution, and concurrent background agents, with runnable samples in both .NET and Python.
Allison announces general availability of GitHub Advanced Security innersource advisories, letting enterprises publish internal security advisories with visibility limited to enterprise-owned repositories. The update includes a new REST API for creating, updating, and withdrawing vulnerabilities, and uses Dependabot to notify affected repos and open upgrade pull requests.
David Pine explains how the .NET Aspire team uses GitHub Agentic Workflows to turn merged product pull requests into SME-reviewed documentation pull requests in a separate repo, while keeping security tight through a “safe-outputs” contract and narrowly scoped GitHub App permissions.
Allison announces enterprise-managed OpenTelemetry export controls for GitHub Copilot in VS Code and Copilot CLI, letting organizations centrally mandate OTLP endpoints, protocols, resource attributes, and capture settings without relying on per-developer OTEL_* environment variables.
Jakub Oleksy’s June 2026 GitHub availability report summarizes six production incidents (including Copilot outages) and the reliability work behind GitHub’s ongoing Azure migration, with concrete mitigations like dependency pinning, stronger config validation, improved traffic blocking, and tighter production access controls.
Allison summarizes what’s new in actions/setup-java v5.5.0 for GitHub Actions workflows, including optional GPG signature verification for JDK downloads, a new Kona JDK distribution, and several Maven-focused improvements around toolchains, caching, and quieter CI logs.
Salim Chawro explains how Microsoft’s Secure Future Initiative (SFI) is being enforced with a multi-agent AI system that continuously evaluates live cloud services, looking for cross-domain weaknesses across code, identity, network, and runtime configuration to drive faster, higher-quality hardening.
Rochak Mittal, Amit Ganguli, Surya Sripathi Raju and Molina Sharma explain how Azure’s resiliency approach has evolved beyond uptime into a lifecycle that covers infrastructure resiliency, data resiliency, and cyber recovery, with practical guidance for zone-first and multi-region designs in regulated and sovereign environments.
Allison announces npm v12 GA, focusing on new install-time security defaults for npm install and a phased deprecation of 2FA-bypass granular access tokens, with timelines and migration guidance for safer publishing workflows.
Allison announces that Kimi K2.7 Code is now available to GitHub Copilot Business and Copilot Enterprise customers, including how admins can enable it and what to consider before turning on an open-weight model.
Allison announces generally available extended metadata checks for GitHub secret scanning, adding richer context (like owner, creation/expiry dates, and org/project details) plus multipart validity checks for secret types that require supplementary metadata to validate.