Pentesters agree: Application allowlisting is THE most critical defense against compromise.
Our ACfB/WDAC training gives you the practical skills to deploy application control for business with confidence—blocking threats before they execute.
https://t.co/dZhloAgQL3
Make sure to checkout https://t.co/VekrGDfk0z as well to see what tooling we offer to beter manage and control your application allowlisting implementation.
#Cybersecurity #WDAC #AppControl #ZeroTrust #ThreatPrevention #AppControlforBusiness #ACFB
Notepad++ just patched 2 critical CVEs allowing arbitrary code execution.
Getting to 100% patch compliance fast is easier said than done. But with App Control for Business, it doesn't matter if a device isn't patched yet. ACFB only allows approved code to run — so even if an attacker tries to exploit the vulnerability, the code they try to launch simply won't execute.
Patch it you should. Drop everything to do so? Not anymore.
#wdac #acfb
Full post: https://t.co/R4KinhK72L
MMS always raises the bar every year. This time, the Opening Reception will be aboard the USS Midway, which was the longest-serving aircraft carrier in the 20th century. How cool is that?
Register for #MMSMidway: https://t.co/11ShrT3aHv
October 25-28 - San Diego
#MMSMOA #SanDiego #ITpros #MSIntune
Happy to announce that the one and only @wpninjasummit Podcast will be present at Workplace Ninjas Belgium 2026!
@oudendorp and @pdaalmans will be hosting the Workplace Ninja Podcast! Feel free to stop by and say hello.
Grab yours here: 🔗 https://t.co/eL7m2sua4u
🚨 New 7-Zip Flaws Let Attackers Execute Arbitrary Code and Compromise Systems
Source: https://t.co/WqnpW3mfn2
A critical heap buffer overflow vulnerability has been disclosed in 7-Zip version 26.00, enabling attackers to achieve arbitrary code execution via a vtable hijack by exploiting a defect in the tool's NTFS archive handler.
Tracked as CVE-2026-48095 and assigned advisory GHSL-2026-140, the flaw resides in the CInStream::GetCuSize() function inside NtfsHandler.cpp. The function computes the NTFS compression-unit buffer size using a 32-bit shift operation: (UInt32)1 << (BlockSizeLog + CompressionUnit).
Users are strongly advised to update 7-Zip to a patched version v26.01 immediately and avoid opening untrusted archive files or disk images of any extension until a fix is applied.
#cybersecuritynews
The AppControl team is present in Norway to promote application allowlisting. We continue to evangelize the need for application allowlisting. #wdac#acfb
I always recommend Artifact Signing for MDE deployments so we don't allow unsigned PowerShell scripts in Live Response
Back your scripts and WDAC polices in GitHub or similar (private repos), use a CI workflow to sign them for you - or use signtool :)
https://t.co/fmwLTYgarp
This is a weekly reminder that users (nor agents) should hold the privilege to run unvetted code from anywhere. It's the single biggest mistake orgs have made and keep making against the principle of least privilege. The time to start controlling what code to allow is now! #acfb
"We're actually working toward making PowerShell 7 be the default in the next version of Windows Server."
"We'll probably make PowerShell <5.1> an optional component or a feature on demand, and then we'll have PowerShell 7 be the default."
🥳 Source: https://t.co/g9hjKJ0RCL
Two of https://t.co/IDMmqbu4p7 's members, @tomdegreef and @TheWMIGuy visited the Microsoft #acfb team on campus this week for the regular in person get-together. Had an interesting morning, learned stuff that will help us build an even better product and make AppControl easier.
Controlled Configuration for Microsoft Defender antivirus settings is coming to Intune.
Microsoft describes it as an extension of Tamper Protection (AKA v2 :) ?) , with cloud delivered policy (MMP-C) becoming the source of truth.
That means Defender settings managed from Intune or Microsoft Defender for Endpoint security settings management should be better protected against local changes. This is a big shift in how Defender settings are protected and enforced.
Read the blog to find out more!
https://t.co/PMbMIpBpTw
#Intune #MSIntune #Defender
L'eh sigh.
#ConfigMgr peeps; remember rejoicing that it finally stopped trying to partially set Scan Source properties?
That hotfix (KB36495448) didn't make it into the HFRU (KB36949461) and thus reverts the behavior.
Yes, the release notes say otherwise but we confirmed it.
Spin up Autopilot test VMs in seconds with HyperV.VMFactory - a PowerShell module for Hyper-V that handles differencing disks, vTPM, Gen 2, custom screen resolution, and bulk creation out of the box.
https://t.co/1RntAQ6MFd
#Autopilot#HyperV#PowerShell#Intune
In case you missed it in the February KB5077241 update, Microsoft quietly added two new PowerShell cmdlets for Secure Boot verification:
Get-SecureBootSVN - checks the Secure Version Number of your firmware and bootloader and reports compliance status. This tells you whether your device is protected against boot manager rollback attacks (CVE-2023-24932).
Get-SecureBootUEFI -Decoded - finally displays Secure Boot keys and certificates in a human-readable format.
New solution available on my membership platform: Intune Driver Update Report.
Intune's Windows Driver Update profiles show you a count of affected devices. That's it. No device names, no user details, no way to drill down before you approve a driver that hits hundreds of machines.
This tool pulls the per-device data Microsoft left out of the portal. One command collects everything through Graph API, a WPF viewer lets you filter, sort, and export. You see exactly which users and devices will receive a driver before you approve it.
PowerShell 7, Graph SDK, read-only permissions. Runs from any admin workstation.
Available now for members: https://t.co/QoUl6MqgLK