Automatic disruption of human-operated attacks through containment of compromised user accounts

Credit to Author: Microsoft Threat Intelligence| Date: Wed, 11 Oct 2023 16:00:00 +0000

We added user containment to the automatic attack disruption capability in Microsoft Defender for Endpoint, a unique and innovative defense mechanism that stops human-operated attacks in their tracks. User containment is automatically triggered by high-fidelity signals and limits attackers’ ability to move laterally within a network regardless of the compromised account’s Active Directory state or privilege level.

The post Automatic disruption of human-operated attacks through containment of compromised user accounts appeared first on Microsoft Security Blog.

Read more

Defending new vectors: Threat actors attempt SQL Server to cloud lateral movement

Credit to Author: Microsoft Threat Intelligence| Date: Tue, 03 Oct 2023 16:30:00 +0000

Microsoft security researchers recently identified an attack where attackers attempted to move laterally to a cloud environment through a SQL Server instance. The attackers initially exploited a SQL injection vulnerability in an application within the target’s environment to gain access and elevated permissions to a Microsoft SQL Server instance deployed in an Azure Virtual Machine (VM). The attackers then used the acquired elevated permission to attempt to move laterally to additional cloud resources by abusing the server’s cloud identity.

The post Defending new vectors: Threat actors attempt SQL Server to cloud lateral movement appeared first on Microsoft Security Blog.

Read more

Celebrate 20 years of Cybersecurity Awareness Month with Microsoft and let’s secure our world together

Credit to Author: Vasu Jakkal| Date: Mon, 02 Oct 2023 16:00:00 +0000

It’s Cybersecurity Awareness Month! Celebrate security with us and prioritize it year-round. Explore how Microsoft is continuously innovating and creating the #BeCybersmart kit to help you and your organization stay safe online.

The post Celebrate 20 years of Cybersecurity Awareness Month with Microsoft and let’s secure our world together appeared first on Microsoft Security Blog.

Read more

New security features in Windows 11 protect users and empower IT

Credit to Author: David Weston| Date: Tue, 26 Sep 2023 17:00:00 +0000

Windows 11 is designed to simplify security with features from the chip to the cloud that are on by default. Since its launch, we’ve seen a 58 percent reduction in security. Learn more about the new features.

The post New security features in Windows 11 protect users and empower IT appeared first on Microsoft Security Blog.

Read more

Microsoft 365 Defender demonstrates 100 percent protection coverage in the 2023 MITRE Engenuity ATT&CK® Evaluations: Enterprise 

Credit to Author: Tanmay Ganacharya| Date: Wed, 20 Sep 2023 13:00:00 +0000

​For the fifth consecutive year, Microsoft 365 Defender demonstrated leading extended detection and response (XDR) capabilities in the independent MITRE Engenuity ATT&CK® Evaluations: Enterprise. The attack used during the test highlights the importance of a unified XDR platform and showcases Microsoft 365 Defender as a leading solution, enabled by next-gen protection, industry-first capabilities like automatic attack disruption, and more.

The post Microsoft 365 Defender demonstrates 100 percent protection coverage in the 2023 MITRE Engenuity ATT&CK® Evaluations: Enterprise  appeared first on Microsoft Security Blog.

Read more

Forrester names Microsoft a Leader in the 2023 Zero Trust Platform Providers Wave™ report

Credit to Author: Joy Chik| Date: Tue, 19 Sep 2023 16:00:00 +0000

Microsoft is proud to be recognized as a Leader in The Forrester Wave™: Zero Trust Platform Providers, Q3 2023 report.

The post Forrester names Microsoft a Leader in the 2023 Zero Trust Platform Providers Wave™ report appeared first on Microsoft Security Blog.

Read more

Peach Sandstorm password spray campaigns enable intelligence collection at high-value targets

Credit to Author: Microsoft Threat Intelligence| Date: Thu, 14 Sep 2023 16:30:00 +0000

Since February 2023, Microsoft has observed a high volume of password spray attacks attributed to Peach Sandstorm, an Iranian nation-state group. In a small number of cases, Peach Sandstorm successfully authenticated to an account and used a combination of publicly available and custom tools for persistence, lateral movement, and exfiltration.

The post Peach Sandstorm password spray campaigns enable intelligence collection at high-value targets appeared first on Microsoft Security Blog.

Read more