In case you missed it, back in October we published a brand new guide for deploying phishing-resistant passwordless in your organization with Entra ID: https://t.co/ge35hitR01 ! This is the outcome of a ton of effort across Microsoft, please use it to begin your journey!
@RedTeamTactics We’re using it for mapping out our #mitigations and looking at the maturity for an area at the time. It’s a great tool to establish a common understanding of what a control is (or is not). #taxonomy
Oh, I just saw that it's actually even better than that:
Notepad will now be a vector for up-selling you.😵💫
So if you're writing that term paper--in *Notepad*--and you want to rely heavily on integrated Gen AI help, make sure you keep track of your credits or buy CoPilot.
Did you vote in America yesterday? If so, you just got doxed
This site takes voter records that can be hard to source and puts them all into one place. Name, address, voter history, for free. It turns voting into a privacy and security risk https://t.co/UUzraqKLcj
@guyrleech Perhaps a module or script you can include or pipe to when needed? Extra features in specific purpose scripts tend to grow old… or at least put a version number in so that you can easily update (find, even) the latest revision of your «dump error objects» routine.
The ‘Windows Server 2025 Security Book’ is also available at
https://t.co/XH0MdhKwPi
Two things that caught my eye:
▪️Credential Guard is now enabled by default on servers.
▪️Delegated Managed Service Account (DMSA) is now introduced.
Acting as digital detectives, we uncovered the sale of a bypass tool on underground forums. This investigation began when a bad actor tried to test an EDR bypass tool. Read what we learned from there: https://t.co/QiR8jM3zv8