Microsoft Updates

Windows, Intune, Azure, Defender, and Microsoft 365 updates relevant to enterprise operations.

Microsoft UpdateALERT Medium

Turn specs into evals for any agent with ASSERT

Adaptive Spec-driven Scoring for Evaluation and Regression Testing (ASSERT) is an open-source framework for converting natural language behavior requirements into executable evaluations of AI models and agents. The post Turn specs into evals for any agent with...

Microsoft UpdateALERT Medium

Reconstructing AI activity in investigations

Learn how to investigate AI activity in Microsoft 365 Copilot and Azure AI services using a structured, telemetry-driven approach. This playbook helps security teams reconstruct events, assess data exposure, and detect potential threats faster. The post Recons...

Microsoft UpdateALERT Medium

AI brands as bait: How threat actors are using the AI hype in social engineering

As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure. The post AI brands as bait: How threat actors are using the AI hype in social engineering appeared first...

Microsoft UpdateALERT Medium

Securing CI/CD in an agentic world: Claude Code Github action case

Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This research examines the attack chain, responsible disclosure process, Anthropic's mitigation...

Microsoft UpdateALERT Medium

Updating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught us

A surge in real-world attacks against agentic AI systems is reshaping how we think about risk. Based on 12 months of red teaming, this update introduces seven new failure modes, from supply chain compromise to goal hijacking, and the practical mitigations team...

Microsoft UpdateALERT Medium

Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign

A large-scale npm supply chain attack compromised over 90 versions of @redhat-cloud-services packages, silently infecting CI/CD environments and developer systems. The malicious code steals credentials from GitHub, cloud platforms, and local machines, then spr...

Microsoft UpdateALERT Medium

Introducing Microsoft Scout: Your always-on personal agent

Microsoft Scout is integrated across the Microsoft 365 apps you use every day, keeping it grounded in your flow of work. The post Introducing Microsoft Scout: Your always-on personal agent appeared first on Microsoft 365 Blog.

Microsoft UpdateALERT Medium

Microsoft Build 2026: Securing code, agents, and models across the development lifecycle

Discover how Microsoft enables fast, secure AI development with MDASH and new security capabilities. The post Microsoft Build 2026: Securing code, agents, and models across the development lifecycle appeared first on Microsoft Security Blog.

Microsoft UpdateALERT Medium

Announcing the new Work IQ APIs

Work IQ is a new intelligence layer for Microsoft 365, designed to understand how work gets done across your organizations. The post Announcing the new Work IQ APIs appeared first on Microsoft 365 Blog.

Microsoft UpdateALERT Medium

Malicious npm packages abuse dependency confusion to profile developer environments

A dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments. This report details the attack chain, observed tradecraft, and detection opportunities to help organizations identify and...

Microsoft UpdateALERT Medium

Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection

Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. The post Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection appeared first on Microsoft Security Blog.

Microsoft UpdateALERT Medium

Typosquatted npm packages used to steal cloud and CI/CD secrets

The Mini Shai-Hulud campaign used malicious npm packages to target cloud and CI/CD credentials across developer environments. This report details the attack chain, detection opportunities, and mitigation guidance to help organizations identify and disrupt rela...

Microsoft UpdateALERT Medium

Introducing Microsoft 365 Business with Copilot: The new standard for small business

On July 1, we're introducing new Microsoft 365 SKUs with Copilot built-in, designed to fit into the way small businesses already work. The post Introducing Microsoft 365 Business with Copilot: The new standard for small business appeared first on Microsoft 365...

Microsoft UpdateALERT Medium

Introducing a new design for Microsoft 365 Copilot

We’ve redesigned the Copilot app and how Copilot shows up across Microsoft 365 apps to better move with it: cleaner, faster, and in the flow of your work. The post Introducing a new design for Microsoft 365 Copilot appeared first on Microsoft 365 Blog.

Microsoft UpdateALERT Medium

New and improved: Computer-using agents, a new workflows experience, and real-time voice experiences

Learn what’s new in Copilot Studio, May 2026: computer-using agents are now generally available, plus redesigned workflows and Work IQ extensibility. The post New and improved: Computer-using agents, a new workflows experience, and real-time voice experiences...

Microsoft UpdateALERT Medium

New and improved: Agent governance, intelligent workflows, and connected app experiences

See what's new in Copilot Studio, April 2026: updates to workflows, increased control over agent operations, and an expanded agent usage estimator. The post New and improved: Agent governance, intelligent workflows, and connected app experiences appeared first...

Microsoft UpdateALERT Medium

Copilot Cowork: From conversation to action across skills, integrations, and devices

Today, we’re announcing additional capabilities in Cowork to expand on what it can make possible for you. The post Copilot Cowork: From conversation to action across skills, integrations, and devices appeared first on Microsoft 365 Blog.

Microsoft UpdateALERT Medium

Microsoft 365 Copilot, human agency, and the opportunity for every organization

As AI and agents take on more of the execution, people have more agency than ever to unlock their ambition, direct what gets done, and own the outcomes. The post Microsoft 365 Copilot, human agency, and the opportunity for every organization appeared first on...

Microsoft UpdateALERT Medium

Microsoft Agent 365, now generally available, expands capabilities and integrations

Microsoft Agent 365 helps you take control of agent sprawl as your control plane to observe, govern, and secure agents and their interactions. The post Microsoft Agent 365, now generally available, expands capabilities and integrations appeared first on Micros...

Microsoft UpdateALERT Medium

Copilot’s agentic capabilities in Word, Excel, and PowerPoint are generally available

From first draft to final polish, Copilot acts as a true collaborator, taking action while you stay in control. The post Copilot’s agentic capabilities in Word, Excel, and PowerPoint are generally available appeared first on Microsoft 365 Blog.

Microsoft UpdateALERT High

Windows Update Causing VPN Failures in Enterprise Networks

Reports indicate KB507001 can interrupt split-tunnel VPN connectivity for domain-joined endpoints.