Rabia Noureen profile picture

Follow Rabia

Rabia Noureen

News Editor

Rabia has a master's degree in Software Engineering and she has years of experience writing professionally about Microsoft products and other technologies. Rabia has also written for OnMSFT.com as well as Windows Report. She is always up to date on the latest trends in the IT Industry and has done extensive research in the data science industry.

LATEST

Microsoft Azure

Microsoft to Tighten Cloud Security with Mandatory MFA for Azure Resource Management

Microsoft will soon begin enforcing Multi-Factor Authentication (MFA) for all Azure resource management actions. The company has announced that this change will go into effect on October 1, 2025. In a support document, Microsoft detailed that the mandatory MFA enforcement will apply to Azure CLI, PowerShell, SDKs, REST APIs, Infrastructure as Code (IaC) tools, and…

View Article
Network Security

Russian Hackers Abuse Device Code Flow to Infiltrate Microsoft 365 Accounts

Cybersecurity researchers have discovered a new watering hole campaign orchestrated by a Russian state-sponsored hacking group. The operation exploits Microsoft’s device code authentication flow to trick users into authorizing attacker-controlled devices, granting them unauthorized access to Microsoft 365 accounts. How did Russian hackers exploit Microsoft authentication? According to Amazon’s threat intelligence team, the Russian threat…

View Article
Cloud Computing

Microsoft Intune Update Brings Smarter Controls and Multi-Admin Workflows

Microsoft has rolled out a range of new Intune capabilities for August 2025, including smarter app control, multi-admin approvals for sensitive actions, enhanced Apple update visibility, and more. These updates are designed to streamline IT management while strengthening security across organizations. App Control targeting Microsoft has made App Control for Business generally available to commercial…

View Article
Security

Storm-0501 Shifts to Cloud Ransomware in Sophisticated Hybrid Attack

Cybercriminal group Storm-0501 recently carried out a ransomware-style attack that breached both on-premises and cloud environments of an enterprise victim. The campaign highlights the group’s shift from traditional endpoint-focused tactics to more sophisticated cloud-based ransomware operations. Storm-0501 is a financially driven cybercriminal group that has been active since 2021. It’s known for launching ransomware attacks…

View Article
Laptop-Windows-10

Windows Backup for Organizations Now Available to All Commercial Customers

Windows Backup for Organizations, a new tool that launched in limited public preview, is now generally available for commercial customers. This new feature allows organizations to take a backup of their Windows PC settings and preferences and then restore them on a Microsoft Entra-joined device. Microsoft first announced Windows Backup for Organizations at its Ignite…

View Article
warning-cyber-attack

Massive Attack Campaign Hits Microsoft’s Remote Desktop Services

Security researchers have warned about a new attack campaign that targets Microsoft’s Remote Desktop Protocol (RDP) services. Nearly 2,000 malicious IPs have specifically hit RD Web Access and RDP Web Client authentication portals in recent days. Threat intelligence firm GreyNoise detected a significant increase in RDP scans from around 2,000 IP addresses on August 21….

View Article
Windows Logo

Microsoft to Add Quality Updates Option to Windows 11 OOBE for Enterprises

Microsoft will soon introduce a new policy that will let administrators enable Windows quality updates by default during the Out-of-Box Experience (OOBE) on Windows 11 devices. Starting in September, this feature will be available on eligible Microsoft Entra-joined and hybrid-joined devices running Windows 11 version 22H2 or later. With this update, Windows 11 devices will…

View Article
Security

Secure Coding Gaps Leave 74% of Enterprises Exposed to Breaches

Despite regular secure coding training, nearly 74% of enterprises experienced breaches or serious vulnerabilities in the past year. The findings from SecureFlag’s latest research expose a troubling gap between education efforts and real-world security outcomes. SecureFlag researchers found that insecure code continues to be a major challenge for organizations. In the past year, about 74%…

View Article
Cloud Computing

Microsoft’s VM Conversion Tool Eases VMware to Hyper-V Migration

Microsoft is making virtual machine migration easier with the public preview of its new VM Conversion tool in Windows Admin Center. This free agentless tool automates the process of converting VMware VMs to Windows Server with Hyper-V, saving IT admins time and effort. Microsoft highlighted the difficulty and manual effort required to convert virtual machines…

View Article
Cloud Computing

Microsoft Entra Conditional Access Gets Token Protection to Block Token Theft Attacks

Microsoft has introduced a new feature called Token Protection in Microsoft Entra Conditional Access. This new security feature binds authentication tokens to trusted devices to protect organizations against one of the most dangerous attack vectors—token theft. How does Token Protection prevent token theft attacks? Specifically, Token Protection is a security feature that ties authentication tokens…

View Article
Cloud Computing

Exchange Online Imposes Stricter Email Limits on onmicrosoft.com Domains

Microsoft is enforcing stricter controls on the use of onmicrosoft.com domains in Exchange Online. Starting on October 15, the company will start throttling outgoing emails to reduce misuse and improve trust. The default onmicrosoft.com domains are mainly used for setting up and testing Microsoft 365 tenants. However, these Microsoft Online Email Routing Address (MOERA) domains…

View Article
Security – 4

Microsoft Fixes Critical Copilot Flaw Allowing Audit Log Evasion

Microsoft has quietly patched a critical flaw in Microsoft 365 Copilot that could allow hackers to access and summarize enterprise files without generating any record in the audit log. This loophole meant attackers could steal sensitive data while leaving no trace for security teams to detect. In a blog post, Zack Korman, CTO of cybersecurity…

View Article
Go to page