Skip to main content
Microsoft Security

Microsoft Security Blog

A blue and white background with black text
Published
6 min read

Securing our future: April 2025 progress report on Microsoft’s Secure Future Initiative 

The Microsoft Secure Future Initiative (SFI) stands as the largest cybersecurity engineering project in history and most extensive effort of its kind at Microsoft. Now, we are sharing the second SFI progress report, which highlights progress made in our multi-year journey to improve the security posture of Microsoft, our customers, and the industry at large.

Latest posts
Layout of education-related items on a desk and a representation of cyberthreat vectors, next to the title text “Cyber Signals Issue 8, From Classrooms to Research Labs: Cyberthreats in K-12 and Higher Education, by Cyber Signals, A Microsoft Threat Intelligence Report.”
Published
12 min read

​​Cyber Signals Issue 8 | Education under siege: How cybercriminals target our schools​​ 

​This edition of Cyber Signals delves into the cybersecurity challenges facing classrooms and campuses, highlighting the critical need for robust defenses and proactive measures. From personal devices to virtual classes and research stored in the cloud, the digital footprint of school districts, colleges, and universities has multiplied exponentially.​

Man in coffee shop at laptop

File hosting services misused for identity phishing 

Since mid-April 2024, Microsoft has observed an increase in defense evasion tactics used in campaigns abusing file hosting services like SharePoint, OneDrive, and Dropbox. These campaigns use sophisticated techniques to perform social engineering, evade detection, and compromise identities, and include business email compromise (BEC) attacks.

Retain Microsoft Security Experts

Microsoft Security Experts are now available to strengthen your team with managed security services. Learn how to defend against threats with security experts.

Two engineers wearing safety goggles work on a desktop PC at a manufacturing plant.

Storm-0501: Ransomware attacks expanding to hybrid cloud environments 

Microsoft has observed the threat actor tracked as Storm-0501 launching a multi-staged attack where they compromised hybrid cloud environments and performed lateral movement from on-premises to cloud environment, leading to data exfiltration, credential theft, tampering, persistent backdoor access, and ransomware deployment. The said attack targeted multiple sectors in the United States, including government, manufacturing, transportation, […]

Decorative image
Published
5 min read

Microsoft Trustworthy AI: Unlocking human potential starts with trust    

At Microsoft, we have commitments to ensuring Trustworthy AI and are building industry-leading supporting technology. Our commitments and capabilities go hand in hand to make sure our customers and developers are protected at every layer. Building on our commitments, today we are announcing new product capabilities to strengthen the security, safety and privacy of AI systems. 

North Korean threat actor Citrine Sleet exploiting Chromium zero-day 

Microsoft identified a North Korean threat actor exploiting a zero-day vulnerability in Chromium (CVE-2024-7971) to gain remote code execution (RCE) in the Chromium renderer process. Our assessment of ongoing analysis and observed infrastructure attributes this activity to Citrine Sleet, a North Korean threat actor that commonly targets the cryptocurrency sector for financial gain.