A newly disclosed Microsoft SharePoint vulnerability has quickly escalated from a research finding to an active security threat, just days after a public proof-of-concept exploit was released. Attackers are already using the vulnerability to target exposed SharePoint environments. Rapid7 security researcher Stephen Fewer has recently published a detailed technical analysis on CVE-2026-55040 along with a…
You’ve heard it before: I thought you handled that This is where the conversation gets interesting. The vendor can secure the platform. The Microsoft Service Provider (MSP) can secure the tenant. But if users are pasting sensitive data into public AI tools, creating accounts, owning the relationship with the AI, then the whole shared responsibility…
Microsoft has released the August 2026 Patch Tuesday updates for Windows 11. This month, the company fixed 398 vulnerabilities in Windows, Microsoft Office, Azure, Exchange Server, SharePoint, Teams, Power BI, .NET, Visual Studio and other products. Microsoft is reminding customers that Windows 11 version 24H2 Home and Pro editions will reach end of support on…
Microsoft has announced the public preview of Azure Private Link over IPv6, expanding private connectivity options for organizations adopting IPv6. The new capability allows customers to securely connect to Azure Platform-as-a-Service (PaaS) resources via private IPv6 endpoints, reducing their reliance on IPv4-based connectivity. According to Microsoft, many organizations are increasingly adopting IPv6 networks, but Azure…
Microsoft has officially launched Microsoft Entra Tenant Governance, giving organizations a centralized way to discover, secure, and manage increasingly complex multi-tenant environments. The new solution helps IT teams discover hidden or unmanaged tenants, close security gaps, and enforce consistent governance before configuration issues turn into serious risks. Organizations operate multiple Microsoft tenants for production, testing,…
Microsoft has pulled the plug on Domain Exclusion for Microsoft 365 Copilot just days after introducing the feature to give organizations greater control over web-grounded AI responses. This rollback highlights the growing challenges of balancing Copilot’s access to external information with the security, reliability, and governance demands of enterprise customers. Last month, Microsoft announced Domain…
Most organizations still approach Copilot readiness from a procurement standpoint. They confirm the prerequisites, budget for the per-user add-on, assign licenses, and turn it on. And they assume that once they complete those steps, the hard part will be done. But the hard part hasn’t even started. That’s because Microsoft Copilot uses the access model…
Microsoft is giving businesses more time to protect their Windows Server 2016 workloads as the platform moves closer to the end of support. With Azure Arc-enabled Extended Security Updates (ESUs) now generally available, organizations can continue receiving critical security patches without moving their legacy servers to Azure. Microsoft plans to end extended support for Windows…
Microsoft is reminding businesses that the biggest AI risks often stem from familiar security weaknesses rather than entirely new threats. The company has detailed new AI containment strategies to better control autonomous systems, limit potential damage, and build a stronger foundation for secure AI adoption. As AI agents become more autonomous, they can act faster…
Microsoft Entra ID sits underneath Microsoft 365, Azure, and thousands of enterprise Software-as-a-Service (SaaS) applications. If users, groups, app registrations, Conditional Access policies, roles, or service principals are deleted or misconfigured, the impact is not limited to the identity team. Users can lose access to core business applications, administrators can lose privileged access workflows, and…
Microsoft will retire the MemberOf rule operator in Microsoft Entra ID later this year. This change will require organizations to update or replace affected configurations before November 2026. In Microsoft Entra ID, the MemberOf rule operator was introduced as a preview feature, allowing administrators to build dynamic groups, administrative units, or entitlement policies based on…
Microsoft is making Azure virtual machines more secure out of the box with the general availability of Trusted Launch as Default (TLaD) for new Generation 2 (Gen2) VMs and virtual machine scale sets. The update automatically applies key security protections to new deployments without adding cost or administrative overhead. Trusted Launch is a security capability…