Zerologon (Aug–Sept 2020): Taking Over a Domain Controller in Seconds
In August 2020, Microsoft patched CVE-2020-1472, a critical flaw in the Netlogon Remote Protocol used by Windows domain controllers. In September,...
Insights
News, breach teardowns, how-to guides, detections and CIO briefings for Microsoft 365, Entra ID, Azure, AWS and AI agents.
In August 2020, Microsoft patched CVE-2020-1472, a critical flaw in the Netlogon Remote Protocol used by Windows domain controllers. In September,...
Domain controllers hold the keys to your on-premises identity — and, in hybrid environments, a path to the cloud. Here is how to patch and monitor them...
Attacks on Active Directory — including Zerologon exploitation, DCSync and Kerberos abuse — leave specific traces. Microsoft Defender for Identity and...
The short version: In 2020, a flaw called Zerologon let attackers take over a company's core identity system — Active Directory — in seconds, without a...
At Microsoft Ignite in September 2020, Microsoft reorganized its security products under a single brand: Microsoft Defender. The change reflected its...
Microsoft's security product names have changed many times. Here is a practical map of the Microsoft Defender family — what each product does and how to...
Owning Microsoft Defender licenses isn't the same as being protected. Use this checklist to onboard the Defender XDR products properly.
The short version: Many companies pay for Microsoft 365 E5 or similar licenses that include a full suite of security tools — and use only part of it....
On July 15, 2020, the Twitter accounts of Barack Obama, Joe Biden, Elon Musk, Bill Gates, Apple and others posted a cryptocurrency scam. Attackers had taken...
Microsoft Entra Privileged Identity Management (PIM) makes administrative access temporary, approved and audited. Here is how to use it to protect admin...
Attackers who social-engineer employees often go straight for administrative tools. Detecting unusual admin access helps you catch them before they act.
The short version: In 2020, attackers took over the Twitter accounts of world leaders and celebrities — not by hacking Twitter's systems directly, but by...
In July 2020, Microsoft warned about a rise in consent phishing (also called illicit consent grant) campaigns, many using COVID-19 themes. Instead of...
Malicious OAuth apps can read mail and files without a password. Here is how to find and remove them in Microsoft 365.
Illicit consent grants give attackers persistent access to Microsoft 365 data. Detecting them quickly is essential because password resets don't remove them.
The short version: In 2020, attackers began tricking employees into clicking "Accept" on a Microsoft permission screen for a fake app. The employee signs in...
In July 2020, Blackbaud — a cloud software provider widely used by nonprofits, universities and healthcare organizations for fundraising and donor...
SaaS vendors hold your data, and their security directly affects yours. Here is a practical approach to assessing SaaS vendors before you sign —...
You can't monitor a SaaS vendor's internal systems, but you can monitor signals that indicate rising risk — and your own exposure if something goes wrong.
The short version: In 2020, Blackbaud — software used by thousands of charities and schools — was hit by ransomware and paid the attackers. Its customers...
In early 2020, as remote work exploded, "Zoom-bombing" entered the vocabulary: uninvited people joined online meetings and classrooms to disrupt them with...
Microsoft Teams meeting policies decide who can join, present and record. Here is how to tighten them without making meetings painful.
Meeting disruption and eavesdropping are rare, but when they happen in sensitive meetings the impact is high. These detections help you spot unusual meeting...
The short version: In 2020, uninvited strangers began crashing online meetings — "Zoom-bombing." It was a wake-up call: video meetings had become as...