ARCHIVES
Auteur/autrice : net2admin
N2S04.08.2026
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected environments, and practical guidance for detection, hunting, and remediation. The post ChainDrop supply chain compromise: Anatomy of a self-propagating worm appeared first on Microsoft Security Blog.
Lire l’article → N2S04.08.2026
Microsoft expands its Zero Trust for AI strategy to enhance security for AI and DevSecOps environments with new tools and guidance. The post Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps appeared first on Microsoft Security Blog.
Lire l’article → N2S04.08.2026
Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread. The post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET appeared first on Microsoft Security Blog.
Lire l’article → N2S04.08.2026
No major category of widely deployed internet-facing infrastructure is immune to vulnerabilities. Citrix NetScaler has been targeted, as have products from all other major network vendors. The question is not whether edge products will continue to be targeted, but what …
Lire l’article → N2S03.08.2026
Last week I had the joy of participating in Amazon’s “Bring Your Kids to Work Day” with my 7 year old son. We commuted together into the New York City office, his first real rush hour train ride, and spent the day exploring how Amazon uses AI, machine learning, and robotics to deliver packages to […]
Lire l’article → N2S31.07.2026
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft appeared first on Microsoft Security Blog.
Lire l’article → N2S29.07.2026
Work has moved to the browser. Employees, contractors, partners, and third parties now access SaaS and private applications from managed and unmanaged devices. Sensitive information moves through everyday browser actions, including AI prompts, uploads, downloads, and copy and paste. This …
Lire l’article → N2S27.07.2026
Last week I had the privilege of spending three days in São Paulo with technical builders from across Latin America, brought together for a regional tech event full of deep-dive sessions, hands-on workshops, and conversations with customers and partners. What struck me most wasn’t any single session, it was the energy of a technical community […]
Lire l’article → N2S20.07.2026
Last week, my team visited Seoul to meet AWS Korea User Group (AWSKRUG) leaders. AWSKRUG is the largest cloud developer community in Korea, with 20 meetup groups organized by topic and area that collectively host over 100 events each year, primarily in Seoul. My team regularly visits countries across the Asia-Pacific region, listens to feedback […]
Lire l’article → N2S20.07.2026
Over the past few weeks, noise that there’s an AI investment bubble which is about to burst has picked up. In this post, I’ll dig into what that might look like and how you can think about your company’s AI …
Lire l’article →