Feed aggregator
Are organoids useful for Alzheimer's research?
Article URL: https://www.owlposting.com/p/are-organoids-useful-for-alzheimers
Comments URL: https://news.ycombinator.com/item?id=49833333
Points: 1
# Comments: 0
New York sues Polymarket, calling it an unlicensed gambling operation
Article URL: https://apnews.com/article/polymarket-new-york-lawsuit-gambling-b75b753e3c3cd069cdf8d6af175c9fbb
Comments URL: https://news.ycombinator.com/item?id=49833322
Points: 1
# Comments: 0
ArchitectureKit: A CQRS/ES Application Framework for Golang
Article URL: https://github.com/thenativeweb/architecturekit-golang/
Comments URL: https://news.ycombinator.com/item?id=49833308
Points: 1
# Comments: 0
Show HN: Why is my PDF so big? – See every byte of a PDF as a treemap
Came across this cool tool when I needed to see what exactly was causing the size of my PDF to skyrocket.
Not affiliated in any way just a cool find!
Comments URL: https://news.ycombinator.com/item?id=49833293
Points: 2
# Comments: 0
Show HN: Personal Jarvis an open-source alternative to GrokBot
Article URL: https://github.com/PersonalJarvis/PersonalJarvis
Comments URL: https://news.ycombinator.com/item?id=49833292
Points: 1
# Comments: 0
NAZA, a documentary on Israeli war crimes will be free to stream in November
Article URL: https://twitter.com/yuval_abraham/status/2103061893913162054
Comments URL: https://news.ycombinator.com/item?id=49833269
Points: 4
# Comments: 0
The AI Build-Out Is Becoming the Biggest Economic Bet in U.S. History
Article URL: https://www.wsj.com/economy/the-ai-build-out-is-becoming-the-biggest-economic-bet-in-u-s-history-c60716dd
Comments URL: https://news.ycombinator.com/item?id=49833264
Points: 2
# Comments: 1
Show HN: Blackbear.app – Thoughtful, Private Collaboration
Hello! My name is Rheisen (https://rheisen.me) and I’m the founding engineer / creator of https://blackbear.app. For the busy, here is the quick version of what Blackbear is: A private collaborative workspace. Completely free for single devices, $2/mo or $20/yr if you want managed data sync and collaboration.
This project is coming out of a strong beta period. Over 200 people have created accounts, and over 50% of people who found the project a few months ago are still using it. Kinda insane.
--
Blackbear comes with a lot: calendars, routines, task management, messaging, voice/video calling, podcast discovery, news aggregation, etc.
But the most important feature is exactly what makes Linux great: Files.
Blackbear has over 13 native file editors. Markdown notes and documents, slides, sheets / kanban boards / charts, e-readers for epub/mobi/pdf, freehand canvases, audio and image files, pages, scripts, keychains, etc. with a few more still on the roadmap (video is next, spoiler).
Most of these file types (notes, docs, sheets, slides, canvases, etc.) support real-time collaboration with the people you connect with, so you can work together in real-time, with the server still only seeing encrypted cipher text.
The thing I’m most proud to say is that your data is absolutely, 100% yours. Everything runs on your device, and is transmitted end-to-end encrypted to all of your other devices and those you connect with if you use cloud sync.
And it’s 2026, so there is AI, for those who want it, included in the app. Blackbear uses a ZDR neocloud provider (Fireworks) to provide flash models, but it’s a model and provider agnostic harness that I’ve built. You can set up Blackbear’s AI (Pax) with your own keys: Anthropic, OpenAI, Gemini, Open Router, and on-device Ollama are all supported (image generation models are next, spoiler).
Right now the project works from any web browser as a PWA, and has a native Mac App and CLI. Windows app pending, and mobile apps for iOS and Android are awaiting app store approvals.
--
So why did I build this thing? What’s the vision for it?
I built it because I don't think most tech companies have incentives that align with respecting people. As a long-time software engineer, I know very well how these companies operate, and I don't trust them. I wanted to build something that I wouldn't need to trust, that was simply aligned from the bottom up to respect people.
People deserve better. People deserve technology that is affordable, respectful, and private. Blackbear will continue to receive updates and improvements for as long as I'm able. That’s all there is to it.
I'll be around today and if you have any questions about the tech stack or anything, I'm happy to answer!
Comments URL: https://news.ycombinator.com/item?id=49833248
Points: 1
# Comments: 0
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments
- Who is Storm-2570?
- Storm-2570 attack chain: From initial foothold to impact
- What Storm-2570 activity means for defenders
- Mitigation and protection guidance
- Microsoft Defender detections
- Hunting queries
Activity associated with Storm-2570, a ransomware affiliate linked to multiple ransomware payloads, illustrates how tracking and responding to ransomware attacks by payload alone can obscure the affiliates carrying out intrusions and the recurring behaviors that defenders can use to detect and disrupt them. Microsoft Threat Intelligence has observed Storm-2570 using consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware. Across multiple investigations, Storm-2570 has maintained largely uniform tradecraft, infrastructure overlaps, and repeated use of the same remote access and cloud exfiltration tooling despite operating across multiple ransomware ecosystems.
These findings reinforce the value of examining threat actor behavior across the attack chain rather than treating each ransomware payload as an isolated activity set. Recurring remote access, credential access, lateral movement, security tampering, and data exfiltration activity can help defenders connect related intrusions and respond before ransomware deployment, even when the final payload changes.
In this blog post, we delve into the attack techniques attributed to Storm-2570. While Storm-2570’s methodology aligns with the tactics, techniques, and procedures (TTPs) of many tracked ransomware actors, analysis of their post-compromise tactics provides essential insights into how organizations can harden and defend against ransomware threat actors, informing opportunities to disrupt attackers even if they have gained initial access to a network. At the end of this blog, we also provide a comprehensive recommendation section with detection details.
Who is Storm-2570?Storm-2570 is a ransomware affiliate that Microsoft Threat Intelligence has tracked since April 2025. We assess that Storm-2570 has operated across multiple ransomware as a service (RaaS) ecosystems, including Qilin, DragonForce, Anubis, and BERT.
To date, Microsoft Threat Intelligence has observed Storm-2570 in multiple investigated intrusions affecting organizations in United States, Canada, United Kingdom, Spain, Netherlands, and Puerto Rico, including healthcare and public health, education, government agencies and services, financial services, energy, consumer retail, Information technology (IT), food and agriculture, consumer services, commercial facilities, non-government organization (NGO), chemicals, critical manufacturing, and transportation.
Unlike actors that consistently support a single ransomware operation, Storm-2570 appears to be a cross-ecosystem threat actor that works with multiple ransomware groups and shifts between operations as opportunities arise, giving the threat actor the flexibility to use and deploy multiple families and improve opportunities for payouts. As a result, organizations could encounter the same actor, tools, and intrusion methods despite different ransomware payloads being deployed.
Figure 1. Storm-2570’s RaaS deployment timeline Storm-2570 attack chain: From initial foothold to impactWhile the method through which Storm-2570 gains initial access remains unconfirmed, observed intrusion chains indicate subsequent use of remote management tooling and hands-on-keyboard activity to progress toward credential access, lateral movement, exfiltration, and ransomware deployment.
Across incidents, Microsoft has observed the use of commodity tools in the pre-ransom attack stage even when the ransomware payload changed. These tools include:
- Remote monitoring and management (RMM) tools, including Atera, MeshAgent, ScreenConnect, Splashtop, Remotely_Agent, and NinjaRMM
- Discovery and lateral movement tools, including NetScan, Nmap, PsExec, Impacket, NetExec, and Remote Desktop Protocol (RDP) batch scripts
- Data collection and exfiltration tools, including s5cmd and Rclone
These tools enable remote administration, command execution, persistence, and tunneling or proxy access.
Figure 2. Storm-2570 attack chain Frequent use of remote management tooling across the attack chainMeshAgent, a remote device management software, stands out as one of Storm-2570’s most frequently observed remote access and execution tools across multiple intrusions. Rather than appearing as a one-off utility, MeshAgent repeatedly shows up at key points in Storm-2570 attack chains, often after the actor has gained access and is preparing to expand control, run commands, deploy additional tooling, or move toward ransomware impact. In several cases, Storm-2570 used MeshAgent along with MeshCentral as an operational bridge between initial hands-on-keyboard activity and later-stage actions, such as account manipulation, discovery, credential access, security tampering, and ransomware deployment.
Many intrusions tracked by Microsoft have shown Storm-2570 tailoring MeshAgent deployments to the compromised environment. The actor renames MeshAgent-related binaries or services with victim-themed names, likely to make the tool appear more legitimate in the environment. For example, Storm-2570 renames the variant of the meshagent64 RMM tool to include the name of the compromised organization, such as meshagent64-[organization name].exe and uses Base64-encoding to obfuscate the commands being executed. In one such intrusion, MeshAgent was used alongside NinjaRMM before the activity progressed to ntdsutil for credential dumping, network scanning, and Qilin deployment.
Storm-2570 uses a diverse set of remote access tools rather than relying on a single capability. The threat actor rotates among commercially available RMM platforms, remote desktop components, and tunneling utilities, often deploying multiple tools during the same intrusion. For example, Storm-2570 uses Atera to install agents and execute interactive commands, while ngrok and Cloudflared.exe expose RDP services or establish persistent outbound tunnels. Storm-2570 uses AteraAgent to issue commands and to further download and install Splashtop Streamer in compromised environments. Splashtop appears to be the interactive remote control component delivered through Atera, giving the threat actor hands-on keyboard access. The actor also uses tools such as ScreenConnect for command execution and account or domain reconnaissance and installs Remotely_Agent as a persistent remote management service.
Use of tunneling utilities for persistent remote accessStorm-2570 also pairs remote access tooling with tunneling utilities such as Cloudflared.exe to create resilient outbound access paths. In one intrusion, Storm-2570 installed MeshAgent and later created a persistent Cloudflare Tunnel service on the victim host. The tunnel was configured to run automatically as a service under LocalSystem, allowing the threat actor to maintain an encrypted outbound channel from inside the network. This type of tunnel can help bypass inbound firewall restrictions and provide covert remote access for follow-on activity.
Discovery and credential accessPost-compromise, Storm-2570 routinely conducts internal network discovery using tools such as NetScan, SoftPerfect Network Scanner Portable, and Nmap, alongside native discovery commands and file-searching activity. These activities are used to identify reachable hosts and services, map internal networks and remote systems, and locate systems, network shares, and files that may facilitate data collection, credential access, or encryption operations.
For credential access and harvesting, Storm-2570 uses tools like Mimikatz, LaZagne, and pypykatz. Storm-2570 also uses ntdsutil in intrusions for NTDS.dit credential dumping, a credential theft technique against Active Directory domain credentials. The ntdsutil command usage pattern is consistent with creating an Install From Media (IFM) copy of Active Directory database material. In an intrusion context, attackers can use this to obtain NTDS.dit and related registry hives for offline extraction of password hashes and credential material.
The command uses the legitimate Windows ntdsutil.exe to activate the NTDS Active Directory instance and create a full IFM backup in C:\Windows\Temp\<XXXXXXXXX>.
Storm-2570 uses this command to dump or stage Active Directory database NTDS.dit and supporting registry hive material, then copy it off-host and potentially extract domain credential hashes offline, indicating that the actor has high-privilege access to a victim’s domain controller:
Defense evasionAfter acquiring privileged credentials, Storm-2570 uses defense evasion tactics preceding ransomware deployment, including antivirus tampering and the modification of Microsoft Defender settings and Defender exclusions. In multiple observed intrusions, Storm-2570 disabled real-time monitoring, added Defender exclusions for C:\PerfLogs to weaken endpoint detections, and modified registry values under Microsoft Defender service keys to further impair protections.
These tactics are consistent across Storm-2570 ransomware intrusions involving Qilin, DragonForce, and Anubis deployment, including cases where the actor used registry changes to alter DisableAntiSpyware, DisableRealtimeMonitoring, and WinDefend service behavior.
Lateral movement and deployment preparationStorm-2570 moves into lateral movement and deployment preparation phase typically by using a mix of legitimate administrative tooling, offensive frameworks, and remote execution utilities.
Across multiple investigated intrusions, Storm-2570 was observed leveraging PsExec, Impacket, NetExec, RDP batch scripts, and admin shares to reach additional systems, execute commands remotely, and stage tooling across the environment. The actor uses these capabilities to facilitate data exfiltration and prepare victim networks for ransomware deployment. These tools frequently appear alongside earlier discovery activity, credential access, and remote access tooling such as MeshAgent, and often precede the use of s5cmd for exfiltration or ransomware payload execution.
PsExec is one of the most consistent lateral movement and deployment tools used by Storm-2570. The actor frequently uses PsExec, sometimes with host lists such as @ip.txt, to move laterally and install renamed MeshAgent binaries across compromised environments. Storm-2570 utilizes MeshAgent during the lateral movement phase in several intrusions as a remote access tool deployed onto newly compromised systems.
The following are examples of PsExec commands with host lists @ip.txt:
Storm-2570 also uses RDP and RDP-enabling scripts as part of this phase. If RDP is not allowed in the environment, Storm-2570 needs admin privileges to modify the policy and enable it. In several intrusions, rdp.bat script appeared with PsExec, including cases where PsExec ran rdp.bat across hosts using @ip.txt.
The RDP batch script (rdp.bat) enables inbound Remote Desktop access by modifying Terminal Server settings and adding a firewall rule to allow TCP port 3389, as observed in the command below:
Additionally, the threat actor uses ngrok to expose TCP 3389 (default port for RDP), after which PsExec-related activity and security tampering appears. These examples show Storm-2570 combining RDP access, tunneling, and remote execution to sustain hands-on-keyboard control and reach additional systems.
Storm-2570’s use of Impacket and NetExec over Server Message Block (SMB) further supports their lateral movement pattern. Impacket is a collection of open-source Python classes designed for working with network protocols, and is popular with adversaries due to its ease of use and wide range of capabilities. Microsoft Defender for Endpoint has a dedicated attack surface reduction rule to defend against lateral movement techniques used by Impacket; protecting lateral movement pathways can also mitigate Impacket.
The following NetExec SMB command is used to conduct credential theft and reconnaissance against internal Windows hosts:
Data collection and exfiltrationStorm-2570 frequently performs data theft using cloud and file-transfer utilities that are capable of moving large volumes of data quickly from compromised environments to a remote attacker-owned cloud resource. Microsoft has observed Storm-2570 using s5cmd or Rclone to stage and exfiltrate data, often after the actor has already completed discovery, credential access, lateral movement, and remote access setup. Tools like Rclone provide data synchronization capabilities, moving newly created or updated files to cloud resources in real-time to enable continuous exfiltration throughout all stages of the attack without needing attacker interaction.
Most commonly, Storm-2570 relies on s5cmd, a command-line utility designed for managing Amazon S3 and compatible object storage services, for S3-based exfiltration. In multiple intrusions, the actor staged s5cmd.exe alongside a credentials file and used it to copy documents, spreadsheets, images, databases, mail-related files, archives, and other business-relevant file types to S3 buckets. Storm-2570 identifies high-value drives and network shares, stages s5cmd.exe and a credentials file, and then executes run copy (cp) operations with extension filters to transfer selected data to attacker-controlled S3 buckets. To interact with the destination S3 bucket, s5cmd requires credentials for authentication and the credentials file stores the AWS access keys for authentication to the S3 bucket.
The following is an example of s5cmd data exfiltration command lines:
Overall, Storm-2570’s exfiltration tradecraft shows a strong preference for tools that blend into legitimate administrative or cloud-transfer workflows, allowing double-extortion operations: first collecting sensitive data through cloud-transfer tooling, then deploying ransomware.
What Storm-2570 activity means for defendersStorm-2570 illustrates common human-operated ransomware attacks and how modern ransomware affiliates increasingly operate independently of a single ransomware brand. Ransomware affiliates’ use of common tools, intrusion methods, and operational patterns remain remarkably consistent. Although Storm-2570’s techniques are not novel, recognizing the patterns used by ransomware affiliates can be important for defenders to know to improve prevention, detection, and incident response.
Mitigation and protection guidanceTo defend against Storm-2570 TTPs and similar activity, Microsoft recommends the following mitigation measures:
- Follow the defending against ransomware guidance in Microsoft’s ransomware as a service blog post which details how to build credential hygiene as well as how to limit lateral movement using the principle of least privilege.
- Turn on tenant-wide tamper protection features to prevent attackers from stopping security services or using antivirus exclusions. Without tamper protection, attackers could simply turn off Microsoft Defender Antivirus without the need to acquire higher privileges.
- Customers running Intune or Microsoft Defender for Endpoint Security Configuration can enable DisableLocalAdminMerge to prevent modification of antivirus exclusions via GPO.
- In addition to tamper protection, you can also enable and configure Microsoft Defender Antivirus always-on protection in Group Policy.
- If there is an issue with a device during roll out of various antivirus features, the device can be placed in Troubleshooting mode to turn off Tamper Protection temporarily without impacting the wider organizational security policy.
- For approved RMM systems used in your environment, enforce security settings where possible to implement MFA. If an unapproved RMM installation is discovered in your network, reset passwords for accounts used to install the RMM services. If a System-level account was used to install the software, further investigation may be warranted.
- Configure automatic attack disruption in Microsoft Defender XDR. Automatic attack disruption is designed to contain attacks in progress, limit the impact on an organization’s assets, and provide more time for security teams to remediate the attack fully.
- Microsoft Defender XDR customers can turn on attack surface reduction rules to prevent common attack techniques used in ransomware attacks:
- Block process creations originating from PSExec and WMI commands (Some organizations might experience compatibility issues with this rule on certain server systems but should deploy it to other systems to prevent lateral movement originating from PsExec and WMI.)
Microsoft Defender customers can refer to the list of applicable detections below. Microsoft Defender coordinates detection, prevention, investigation, and response across endpoints, identities, email, apps to provide integrated protection against attacks like the threat discussed in this blog.
Tactic Observed activity Microsoft Defender coverage ExecutionStorm-2570 delivers tools such as PsExec, Impacket, NetExec, and RDP batch scripts, to carry out post-compromise activityMicrosoft Defender Antivirus– Behavior:Win32/PsexecRemote
Microsoft Defender for Endpoint
– Hands-on-keyboard attack involving multiple devices
– Remote access software
– Suspicious PowerShell command line
– Suspicious PowerShell download or encoded command execution
– Ransomware-linked threat actor detectedPersistenceStorm-2570 uses RMM tools for persistence, payload delivery, and lateral movementMicrosoft Defender for Endpoint
– Suspicious Atera activity
– File dropped and launched from remote locationDefense ImpairmentStorm-2570 disables Microsoft DefenderMicrosoft Defender for Endpoint
– Defender detection bypass
– Attempt to turn off Microsoft Defender Antivirus protectionCredential AccessStorm-2570 has used tools like Mimikatz, LaZagne, and pypykatz for credential access and harvesting and NTDS.dit for credential dumpingMicrosoft Defender Antivirus – HackTool:Win32/Mimikatz – HackTool:Win64/Mimikatz – HackTool:Linux/LaZagne – HackTool:Win32/LaZagne – HackTool:Win64/LaZagne Microsoft Defender for Endpoint
– Exposed credentials at risk of compromise
– Compromised account credentials
– Process memory dumpExfiltrationStorm-2570 uses Rclone and s5cmd for data theftMicrosoft Defender for Endpoint
– Potential human-operated malicious activity
– Renaming of legitimate tools for possible data exfiltration
– Possible data exfiltration
– Hidden dual-use tool launch attemptImpactStorm-2570 deploys Anubis, DragonForce, Qilin, and BERT ransomwareMicrosoft Defender Antivirus
– Ransom:Win32/Qilinloader – Behavior:Win32/Ransomware!Qilin – Ransom:Linux/Qilin – Ransom:Win32/Qilin – Ransom:Win32/DragonForce – Ransom:Win64/Anubis
Microsoft Defender for Endpoint
– Possible ransomware activity based on a known malicious extension
– Possible compromised user account delivering ransomware-related files
– Potentially compromised assets exhibiting ransomware-like behavior
– Ransomware behavior detected in the file system
– File dropped and launched from remote location Microsoft Security Copilot
Microsoft Security Copilot is embedded in Microsoft Defender and provides security teams with AI-powered capabilities to summarize incidents, analyze files and scripts, summarize identities, use guided responses, and generate device summaries, hunting queries, and incident reports.
Customers can also deploy AI agents, including the following Microsoft Security Copilot agents, to perform security tasks efficiently:
- Threat Intelligence Briefing agent
- Phishing Triage agent
- Threat Hunting agent
- Dynamic Threat Detection agent
Security Copilot is also available as a standalone experience where customers can perform specific security-related tasks, such as incident investigation, user analysis, and vulnerability impact assessment. In addition, Security Copilot offers developer scenarios that allow customers to build, test, publish, and integrate AI agents and plugins to meet unique security needs.
Threat intelligence reportsMicrosoft Defender XDR customers can use the following threat analytics reports in the Defender portal (requires license for at least one Defender XDR product) to get the most up-to-date information about the threat actor, malicious activity, and techniques discussed in this blog. These reports provide the intelligence, protection information, and recommended actions to prevent, mitigate, or respond to associated threats found in customer environments.
- Actor Profile: Storm-2570
- Tool Profile: Qilin ransomware
- Tool Profile: Anubis ransomware
- Tool Profile: DragonForce ransomware
Microsoft Security Copilot customers can also use the Microsoft Security Copilot integration in Microsoft Defender Threat Intelligence, either in the Security Copilot standalone portal or in the embedded experience in the Microsoft Defender portal to get more information about this threat actor.
Hunting queries Microsoft SentinelMicrosoft Sentinel customers can run the following advanced hunting queries to find related activity in their networks:
Hunt for PsExec-based remote execution and deployment
DeviceProcessEvents | where Timestamp > ago(30d) | where FileName in~ ("psexec.exe", "psexec64.exe") or ProcessCommandLine has_any ("psexec.exe", "psexec64.exe") | where ProcessCommandLine has_any ("@ip.txt", "-accepteula", "\\") | project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256, DeviceId, ReportId | order by Timestamp descHunt for renamed MeshAgent binaries and services
let MeshAgentTerms = dynamic(["meshagent", "meshagent64", "meshcentral"]); union isfuzzy=true ( DeviceProcessEvents | where Timestamp > ago(30d) | where FileName has_any (MeshAgentTerms) or ProcessCommandLine has_any (MeshAgentTerms) or InitiatingProcessCommandLine has_any (MeshAgentTerms) | project Timestamp, DeviceName, ActionType, FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256, RegistryKey="", RegistryValueName="", SourceTable="DeviceProcessEvents" ), ( DeviceFileEvents | where Timestamp > ago(30d) | where FileName has_any (MeshAgentTerms) or FolderPath has_any (MeshAgentTerms) or InitiatingProcessCommandLine has_any (MeshAgentTerms) | project Timestamp, DeviceName, ActionType, FileName, FolderPath, ProcessCommandLine="", InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256, RegistryKey="", RegistryValueName="", SourceTable="DeviceFileEvents" ), ( DeviceRegistryEvents | where Timestamp > ago(30d) | where RegistryKey has_any (MeshAgentTerms) or RegistryValueName has_any (MeshAgentTerms) or RegistryValueData has_any (MeshAgentTerms) or InitiatingProcessCommandLine has_any (MeshAgentTerms) | project Timestamp, DeviceName, ActionType, FileName="", FolderPath="", ProcessCommandLine="", InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256="", RegistryKey, RegistryValueName, SourceTable="DeviceRegistryEvents" ) | order by Timestamp desc Learn moreFor the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.
To get notified about new publications and to join discussions on social media, follow us on LinkedIn, X (formerly Twitter), and Bluesky.
To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat Intelligence podcast.
The post Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments appeared first on Microsoft Security Blog.
What’s new in Microsoft Security: September 2026
AI agents are now running on employee devices, cloud platforms, and across developer workflows. Security teams need to see those agents, govern what they can reach, and contain them when something goes wrong. This month’s updates help you discover and control local AI agents, extend Zero Trust to agent traffic, and strengthen the security operations center (SOC) foundations that AI-era operations depend on.
Here’s what’s new:
Extend protection and support investigations with Microsoft Defender Bring more context into email investigation and hunting with Microsoft Security CopilotAvailable for organizations using both Microsoft Defender and Microsoft Security Copilot, a new email detonation summary delivers AI-generated explanations of URL and file sandboxing results, helping SOC teams investigate faster by reducing the manual effort required to correlate detonation evidence and contextual signals.
Prevent and disrupt threats with Microsoft Defender Protect sensitive data in motion with Microsoft Purview and Microsoft Entra Stop sensitive data from reaching shadow AI over the networkNow generally available, Microsoft Purview and Microsoft Entra Global Secure Access bring data security to the network across human actions and on-behalf-of (OBO) agentic traffic. Context-aware Microsoft Purview classification and policies are enforced by Entra at the network layer. Organizations can discover sensitive files and text in real time and block them from being shared to risky destinations. For example, if an employee or OBO agent tries to upload a sensitive document to an unsanctioned AI tool, the policy can stop the transfer before the data leaves.
Prevent employees from sharing proprietary or sensitive organizational data to potentially risky locations such as consumer AI apps. Protect, investigate, and clean up enterprise data with Microsoft Purview Manage labeling at enterprise scale with less administrative overheadMicrosoft Purview auto-labeling helps organizations automatically apply data security controls to sensitive content at enterprise scale. New auto-labeling enhancements improve policy scale, admin experience, and reporting. Policies now support simulations of up to 20 million items and up to 50,000 sites through adaptive scopes. Administrators can edit a policy without re-running simulation. New audit insights and reporting show policy coverage and processing activity. Together, these enhancements help organizations scale auto-labeling across larger environments with less administrative effort.
Investigate content created in Copilot apps such as Microsoft Loop, Copilot pages through established compliance processesMicrosoft Purview eDiscovery now supports search, hold, review, and export content in user-owned SharePoint embedded containers, to help streamline eDiscovery processes for legal, regulatory, and internal investigations. Investigators can find content from AI-powered experiences, including Microsoft Loop, Copilot Pages, Copilot Notebooks, and applications, such as Outlook newsletters, mapped to a user without requesting the container URL from a SharePoint administrator. An optional HTML conversion produces a more readable version for downstream legal tools, improving the review and export experience for experts.
Archive and permanently remove inactive content to improve AI readinessWith Microsoft Purview Data Lifecycle Management, administrators can now archive inactive SharePoint content without archiving the entire site. Archived content remains subject to retention and legal hold policies, and remains discoverable for eDiscovery, while dropping out of Microsoft 365 Copilot indexing (until reactivated). Organizations can also use Priority Cleanup to permanently delete approved content, including stale Teams recordings and transcripts, so it is no longer discoverable in eDiscovery, SharePoint search, or Microsoft 365 Copilot. Together, these capabilities help organizations meet compliance regulations, including those in highly regulated industries.
Explore Microsoft Purview data compliance solutions Advanced endpoint management extends to GCC High and DoD with Microsoft Intune Bring modern endpoint management to regulated environmentsMicrosoft Intune Enterprise Application Management, Microsoft Cloud PKI, and Intune Remote Help are coming to Government Community Cloud with High security needs (GCC High), with Enterprise Application Management also being offered to organizations of the Department of Defense (DoD). These capabilities help government and defense organizations simplify application management, modernize certificate lifecycle management, resolve device issues faster, and reduce total cost of ownership, all while operating within their accredited cloud environment.
Learn more about Microsoft Intune endpoint protection solutions Stay in the LoopMicrosoft Security continually ships meaningful innovations across our portfolio, as well as research-driven insights and reports for the security community. In the Loop posts are your reliable source of what’s new across Microsoft Security and what it means for your security strategy. Check back for the next drop.
And join us at Microsoft Ignite, from November 17 to 20, 2026, in San Francisco or online, to see Microsoft Security innovations in action and go hands-on with the team that built it.
To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.
The post What’s new in Microsoft Security: September 2026 appeared first on Microsoft Security Blog.
Kontext Security Emerges With $4 Million for AI Agent Runtime Controls
The startup’s runtime enforcement platform evaluates AI agents in real time to provide visibility and control over their actions.
The post Kontext Security Emerges With $4 Million for AI Agent Runtime Controls appeared first on SecurityWeek.
OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data
Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information.
The post OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data appeared first on SecurityWeek.
A draft architecture published under the Dutch Digitalisation Strategy spells out what full software sovereignty requires and why full hardware sovereignty remains out of reach
She HN: Quick route, a simple single page route planning tool
Article URL: https://theinstant.cc/route
Comments URL: https://news.ycombinator.com/item?id=49830398
Points: 1
# Comments: 0
Jev Does Not Play Dice: 83% probability, 19% accuracy on a hidden fair die roll
Article URL: https://kantahayashiai.github.io/posts/jev-does-not-play-dice/
Comments URL: https://news.ycombinator.com/item?id=49830385
Points: 1
# Comments: 0
Amazon to Expand Robot-Making Capacity with New, $100M Indiana Hub
Article URL: https://www.wsj.com/tech/amazon-to-expand-robot-making-capacity-with-new-100-million-indiana-hub-87fce322
Comments URL: https://news.ycombinator.com/item?id=49830376
Points: 1
# Comments: 0
Databricks Acquires Row Zero, Bringing Live, Governed Spreadsheets to Genie
Show HN: Site MCP – Let any AI agent read your website, free, no install
Article URL: https://sitemcp.dev
Comments URL: https://news.ycombinator.com/item?id=49830373
Points: 1
# Comments: 0
What Is Happening with PostgreSQL 19
Article URL: https://www.snowflake.com/en/blog/engineering/postgresql-19-release-delay-feature-reverts/
Comments URL: https://news.ycombinator.com/item?id=49830369
Points: 1
# Comments: 0
California's Shadow Welfare System
Article URL: https://www.city-journal.org/article/california-illegal-immigrants-shadow-welfare
Comments URL: https://news.ycombinator.com/item?id=49830361
Points: 1
# Comments: 0
