Microsoft Scout just got a SERIOUS update.
Version 0.23.578 gives Scout a lot more hands inside Microsoft 365.
> Teams transcripts and room booking
> SharePoint Lists and schema tools
> Outlook rules and meeting drafts
> File access controls for Microsoft 365 links
> Co-Create workspaces in OneDrive and SharePoint
> Better chat and automation schedules
The new permissions alone show 12 tools across SharePoint Lists, List Schema and Meetings.
Give the agent tools.
Give it permissions.
Give it systems to act inside.
Now we're cooking.
What are you testing first?
Microsoft Threat Intelligence is tracking active Mini Shai-Hulud npm supply chain attacks in which a threat actor compromised trusted maintainer accounts to distribute credential-stealing malware.
Compromised packages (confirmed malicious) include:
- [email protected]
- [email protected]
- [email protected]
- [email protected]
- qlik/[email protected]
- cacheable/memory, /utils, /net
- 17+ servicetitan/* packages (eslint-config, anvil-themes, table, form, log-service, etc.)
In this attack, a malicious preinstall hook launches an obfuscated dropper (setup.mjs) that downloads a Bun binary from GitHub and executes a credential-stealing payload, either Math_Symbol.js or Math_Init.js.
The payload is a Mini Shai-Hulud variant, a self-propagating npm supply-chain malware family. It harvests npm, GitHub, cloud and continuous integration (CI) credentials, exfiltrates collected secrets, and uses stolen publishing access to inject itself into package tarballs, increment their versions and republish the compromised releases.
Microsoft observed the same pattern across all affected packages, suggesting a single actor using multiple stolen tokens.
Microsoft Defender for Endpoint customers should act on these alerts: “Trojan:npm/MalBun.A”
Say HELLO to my little friend, Task Manager OG!
I'm please to announce the immediate availability of the MacOS version of TMOG today; Windows support will follow shortly, so follow for the update!
TMOG is a free application; I may do a Pro version at some point, but everything here is and will remain free.
Get the beta: https://t.co/29uNVV2pHU
Microsoft Scout just dropped a HUGE update.
>Live model switching.
>Max context windows.
>Reasoning controls.
>Better automations.
>Microsoft To Do + Teams channel tools.
>Mermaid, Excalidraw, CSV and TSV inside Co-Create.
>Major MCP upgrades.
>Feedback button.
Scout is becoming a seriously powerful desktop AI agent… fast.
Full release notes:
https://t.co/rKX6rJqPos
If you’re a person who’s made a bunch of fun utilities either for just yourself or for others, and you need a webpage to showcase or utilities, you get one for free at TinyToolTown! Go submit your utilities and claim your page!
What started as a routine ransomware investigation uncovered something more complex: One intrusion. Two cyberattackers.
Our 9th cyberattack series report reveals:
➡️ What our investigators uncovered
➡️ What organizations can do to strengthen their defenses
Read the report: https://t.co/xUSalsgKKg
36 hours after they left, multiple cancelled flights, redirected to the wrong city, changes to rental cars, etc.. still waiting on luggage - including hockey gear - kinda important when you were supposed to play.. hours ago.
Sigh.. time for something different. 2/2
@AmericanAir doing their best to lose customers this weekend. After a complete disaster of a travel day for my family yesterday, including missing huge portions of the event they're traveling for - they've now been waiting for 2 hours for bags to unload from a flight at RSW. 1/2
Totally get what Pedro is saying here, very different “community” vibe between MacOS and Windows. Difficult to find discussions or even podcasts around tooling/productivity like you’d find in the Mac space.
im struggling to reach the right audience of Windows users who would love Raycast as much as the macOS one
almost all my followers are on Mac
what do i do? i'm not a fan of sponsoring influencers. i want the real deal who can help spread the word to the right ppl
dm me
Since February 2026, Microsoft Defender Experts have tracked a cryptocurrency clipper campaign that combines clipboard theft, wallet address replacement, worm-like functionality, and Tor-based communications, enabling both financial gain and continued access to devices. https://t.co/tngq6Gmx30
This campaign uses malicious .lnk files to deliver a worm and a script-based stealer. Upon execution, the clipper deploys a portable Tor client, routes traffic through a local SOCKS5 proxy, and blends data theft with remote code execution, turning a financially motivated stealer into a lightweight backdoor.
Due to the nature of this attack chain, defenders should hunt for correlated behaviors rather than investigate isolated events. Read our latest blog to get our full analysis, as well as detection and mitigation guidance to help security teams investigate and contain similar activity in enterprise environments.
This May threat landscape review pulls together Microsoft Security Research’s work across the key campaigns we saw and the posture actions defenders should prioritize now.
https://t.co/ebokM25L2s
@DarrellPrichard@BenThePCGuy I still do this right now, works fantastic.
14 is a lot more travel friendly imho. Love the screen real estate of the 16 but if you like to roll light it’s a bit much. (I have both currently)
Hey folks, some personal news.
I’m leaving Microsoft.
It’s been a privilege to work here, and I’m incredibly grateful for the people I’ve worked with, the customers I’ve learned from, and the support so many of you have shown me along the way.
I’m now starting out on my own and chasing a dream I’ve had for a long time: building software that makes security more practical, accessible, and useful for the people doing the work every day.
Why now?
With all the change happening around us, I feel like new possibilities are opening up. I want to spend this next chapter building things I care deeply about, solving problems that matter, and doing work that brings me joy.
I’m excited. Nervous. Grateful.
My newsletters, podcast, Maester and other tools will all be part of this next chapter, and I’ll share more in the coming weeks.
Thank you for being part of the journey so far. I’m looking forward to building this next chapter with your support.