Rabia Noureen profile picture

Follow Rabia

Rabia Noureen

News Editor

Rabia has a master's degree in Software Engineering and she has years of experience writing professionally about Microsoft products and other technologies. Rabia has also written for OnMSFT.com as well as Windows Report. She is always up to date on the latest trends in the IT Industry and has done extensive research in the data science industry.

LATEST

Microsoft logo

Hackers Exploit OAuth Device Code Flow to Breach Microsoft Entra Accounts

Threat actors are actively abusing Microsoft’s OAuth 2.0 Device Authorization flow to compromise Microsoft Entra (formerly Azure AD) accounts without triggering traditional phishing red flags. The attackers leverage social engineering techniques to trick victims into entering attacker-generated device codes on legitimate Microsoft login pages to obtain valid access and refresh tokens. According to a new…

View Article
Security – 4

Chinese APT Exploits Dell Zero-Day Flaw to Gain Persistent VMware Access

Chinese state-sponsored hackers have quietly leveraged a hard-coded credential flaw in Dell RecoverPoint for Virtual Machines for nearly two years, weaponizing it as a powerful zero-day entry point. The vulnerability grants attackers deep, persistent access to compromised environments, which enables long-term lateral movement and covert control over virtualized infrastructure. RecoverPoint for Virtual Machines (RP4VM) is…

View Article
Datacenter networking servers

Azure Automatic Zone Balance Enters Public Preview for Virtual Machine Scale Sets

Microsoft has announced a public preview of automatic zone balance for Azure Virtual Machine Scale Sets, expanding its resiliency toolkit for enterprise cloud deployments. The capability is built to proactively safeguard workloads by maintaining balanced VM distribution and minimizing the impact of unexpected availability zone failures. Azure Virtual Machine Scale Sets (VMSS) provide a way…

View Article
Hero approved Microsoft 365

Microsoft 365 Copilot Bug Exposes Confidential Emails Despite DLP Safeguards

Microsoft has acknowledged a newly discovered bug that allowed Microsoft 365 Copilot to summarize confidential emails without proper authorization. The flaw effectively bypassed data loss prevention (DLP) policies, compromising safeguards designed to prevent sensitive information from being accessed or processed by automated systems. Microsoft 365 Copilot Chat is an AI‑powered, enterprise‑ready chat experience that lets…

View Article
Microsoft logo

New Library Management in Microsoft Defender Simplifies Live Response Investigations

Microsoft has introduced a new Library Management experience in Microsoft Defender. This new feature is aimed at transforming how security analysts manage scripts and tools during live response investigations. Security analysts have long struggled with a fragmented, inefficient process for using scripts and tools during live threat investigations. Assets had to be uploaded in the…

View Article
Datacenter networking servers

Enterprises Rethink Virtualization Roadmaps as VMware Pricing Fears Persist

The anticipated mass departure from VMware never materialized, but the industry is now experiencing a strategic shift as organizations reassess their virtualization roadmaps. Broadcom’s sweeping changes have prompted IT leaders to steadily diversify their infrastructure choices. CloudBolt Software released a report dubbed “The Mass Exodus That Never Was: The Squeeze Is Just Beginning.” This survey…

View Article
Cloud Computing

Exchange Online PowerShell to Retire -Credential Parameter

Microsoft is retiring the -Credential parameter in the Exchange Online PowerShell module, effective for all versions released after June 2026. This change marks a shift toward modern, more secure authentication methods for administrators. In the Exchange Online PowerShell module, the -Credential parameter lets administrators pass a PSCredential object (username and password) to the Connect-ExchangeOnline cmdlet…

View Article
Security

Explosive AI Growth Leaves Organizations Grappling With New Attack Surfaces

As AI adoption surges toward a trillion annual enterprise transactions, IT leaders now face an attack surface expanding faster than traditional security models can contain. With nearly 40% of AI activity being blocked due to data‑exposure risks, the stakes for governing AI securely have never been higher. According to Zscaler ThreatLabz’ 2026 AI Security Report,…

View Article
warning-cyber-attack

Critical SCCM Vulnerability Turns Enterprise Management Tools Into Prime Hacker Targets

The US Cybersecurity and Infrastructure Security Agency has warned about a critical remote code execution (RCE) vulnerability in Microsoft Configuration Manager (ConfigMgr/SCCM). The vulnerability has rapidly escalated into a significant national‑level concern following the release of public exploit code. Microsoft Configuration Manager is an enterprise management platform that helps organizations centrally deploy software, enforce security…

View Article
Cloud Computing

Microsoft Sentinel Gets New Visibility Capabilities

Microsoft Sentinel is getting new updates aimed at improving how security teams understand and investigate risk. The latest changes add new connectors, clearer analytics, and more integrated insights to help teams work more efficiently across their environments. Microsoft has introduced new out-of-the-box connectors to simplify the onboarding of security data across cloud, SaaS, and on-premises…

View Article
Windows 11 approved hero 1

Microsoft Brings Native Sysmon Monitoring to Windows 11

Microsoft has started testing native System Monitor (Sysmon) integration in Windows 11, bringing advanced system activity monitoring directly into the OS. The feature is currently rolling out to Windows Insiders in the Dev and Beta channels for early evaluation. What is Sysmon? Microsoft first announced its plans to introduce native Sysmon functionality into Windows 11…

View Article
warning-cyber-attack

Russian Hackers Exploit Critical Microsoft Office Flaw to Steal Emails

Russian-hackers are exploiting a high-severity vulnerability that is affecting multiple versions of Microsoft Office. This security flaw could allow hackers to steal emails and deploy malicious payloads against organizations in Central and Eastern Europe. Specifically, CVE‑2026‑21509 is a security feature bypass vulnerability in Microsoft Office, which is triggered when victims open specially crafted RTF documents….

View Article
Go to page