Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment.

The post Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments appeared first on Microsoft Security Blog.

Continue reading Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments→

Reimagining the SOC for the agentic era in Microsoft Defender

We are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for SIEM and threat protection together.

The post Reimagining the SOC for the agentic era in Microsoft Defender appeared first on Microsoft Security Blog.

Continue reading Reimagining the SOC for the agentic era in Microsoft Defender→

CVE-2026-70125 Microsoft Outlook Remote Code Execution Vulnerability

Information published. This CVE was addressed by updates that were released in September 2026, but the CVE was inadvertently omitted from the September 2026 Security Updates. This is an informational change only. Customers who have already installed th… Continue reading CVE-2026-70125 Microsoft Outlook Remote Code Execution Vulnerability→