Skip to main content
Microsoft Security

Microsoft Security Blog

A blue and white background with black text
Published
6 min read

Securing our future: April 2025 progress report on Microsoft’s Secure Future Initiative 

The Microsoft Secure Future Initiative (SFI) stands as the largest cybersecurity engineering project in history and most extensive effort of its kind at Microsoft. Now, we are sharing the second SFI progress report, which highlights progress made in our multi-year journey to improve the security posture of Microsoft, our customers, and the industry at large.

Latest posts
A woman using a tablet

New Star Blizzard spear-phishing campaign targets WhatsApp accounts 

In mid-November 2024, Microsoft Threat Intelligence observed the Russian threat actor we track as Star Blizzard sending their typical targets spear-phishing messages, this time offering the supposed opportunity to join a WhatsApp group. This is the first time we have identified a shift in Star Blizzard’s longstanding tactics, techniques, and procedures (TTPs) to leverage a […]

Building with windows and pillars on top of decorative background
Published
7 min read

Innovating in line with the European Union’s AI Act  

As our Microsoft AI Tour reached Brussels, Paris, and Berlin recently, we met with European organizations that were energized by the possibilities of our latest AI technologies and engaged in deployment projects. They were also alert to the fact that 2025 is the year that key obligations under the European Union’s AI Act come into effect, opening a new chapter in digital regulation as the world’s first, comprehensive AI law becomes a reality.

Retain Microsoft Security Experts

Microsoft Security Experts are now available to strengthen your team with managed security services. Learn how to defend against threats with security experts.

Woman with glasses at a laptop in an office

Analyzing CVE-2024-44243, a macOS System Integrity Protection bypass through kernel extensions 

Microsoft discovered a macOS vulnerability allowing attackers to bypass System Integrity Protection (SIP) by loading third party kernel extensions, which could lead to serious consequences, such as allowing attackers to install rootkits, create persistent malware, bypass Transparency, Consent, and Control (TCC), and expand the attack surface to perform other unauthorized operations.

CNAPP Banner
Published
3 min read

Microsoft Defender for Cloud named a Leader in Frost Radarâ„¢ for CNAPP for the second year in a row!  

In the ever-evolving landscape of cloud security, Microsoft continues to assert its dominance with its comprehensive and innovative solutions. The Frost Radarâ„¢: Cloud-Native Application Protection Platforms, 2024 report underscores Microsoft’s leadership in both – the innovation and growth index, highlighting several key strengths that set it apart from the competition.  Frost and Sullivan states in […]