Windows 10 End of Support (Oct 2025): Unpatched Endpoints in Your Microsoft 365 Estate
On October 14, 2025, Microsoft ended support for Windows 10. After that date, Windows 10 devices stopped receiving free security updates, unless enrolled in...
Insights
Articles in Retrospectives.
On October 14, 2025, Microsoft ended support for Windows 10. After that date, Windows 10 devices stopped receiving free security updates, unless enrolled in...
After Windows 10 end of support, unpatched devices shouldn't access company data. Intune compliance policies and Conditional Access can enforce minimum...
Use this checklist to plan a Windows 11 migration with security improvements built in.
The short version: Windows 10 stopped receiving free security updates on October 14, 2025. Every Windows 10 computer still in use without paid extended...
Supply-chain worms like Shai-Hulud steal cloud credentials from developer machines and CI runners. Here is how to detect leaked credentials and respond quickly.
Package ecosystem worms leave signals across developer endpoints, code platforms and cloud logs. These detections help spot an infection and its use of...
The short version: In September 2025, a self-spreading worm infected hundreds of open-source software packages. When developers installed them, it stole...
In September 2025, security researcher Dirk-jan Mollema published details of a critical flaw in Microsoft Entra ID that could have allowed an attacker to...
Cross-tenant and undocumented token flaws are rare but serious. Customers can't prevent provider bugs, but can reduce exposure and improve visibility. Here...
When identity platform flaws limit logging of the initial access, you can still detect what attackers do next. These detections focus on cross-tenant...
The short version: In 2025, a researcher found a flaw in Microsoft Entra ID — the system that controls sign-in for Microsoft 365 and Azure — that could have...
SaaS-to-SaaS integrations hold OAuth tokens that can read and export your data. The Salesloft Drift campaign showed how one compromised vendor can reach...
Stolen OAuth tokens used for data theft show up as bulk API activity from integrations. These detections help catch it.
The short version: In August 2025, attackers stole access tokens from Salesloft's Drift chatbot integration and used them to download data from hundreds of...
ToolShell showed the risk of internet-facing on-premises SharePoint Server. Here is how to migrate to SharePoint Online — or isolate servers you must keep.
SharePoint Server exploitation leaves traces in web logs, file system changes and process activity. These detections target behaviors seen in ToolShell and...
The short version: In July 2025, Chinese state hackers and ransomware groups exploited flaws in SharePoint servers that companies ran themselves —...
Prompt injection can manipulate AI assistants into exposing data they can access. You can't fully prevent it, but you can limit what Copilot can reach and...
Prompt injection against AI assistants is hard to detect directly. You can, however, monitor for the conditions that make it dangerous and for signs of misuse.
The short version: In 2025, researchers found a way to trick Microsoft 365 Copilot into leaking data simply by sending an email with hidden instructions —...
AI agents are a fast-growing category of identities with access to company data and systems. Here is how to inventory and govern them in Microsoft Entra ID.
Use this checklist to govern AI agent identities in your organization.
The short version: AI agents — software that can read your data and take actions on its own — are spreading quickly across companies. In 2025, Microsoft...
Attackers who convince a help desk to reset a password often then register their own MFA method. Locking down password reset and MFA re-registration in...