![]()
CIA Brief – Weekly News Digest
Here’s a quick roundup of the Microsoft, security and AI news worth tracking this week. As always, I’ve skipped the noise and focused on what actually matters for MSPs and SMBs.
Security
- ACR Stealer: Two Observed Intrusion Chains Amid Increased Threat Activity
Microsoft’s threat researchers are tracking ACR Stealer, an infostealer now showing up through two distinct intrusion chains as activity ramps up. For MSPs the fix is boring but effective: infostealers harvest saved credentials and session tokens, so enforce MFA, keep EDR live, and stamp out password reuse. Worth a look if you manage endpoints you don’t fully control.
https://www.microsoft.com/en-us/security/blog/2026/07/16/acr-stealer-two-observed-intrusion-chains-amid-increased-threat-activity/ - Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
The Australian Cyber Security Centre and its Five Eyes partners have flagged Russian state-sponsored actors going after poorly maintained routers and edge devices. Most SMB gear runs on default credentials and stale firmware, which is exactly what this advisory targets. Good reminder to audit client routers, patch firmware, and turn off remote admin where it isn’t needed.
https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/improve-router-hygiene-to-protect-against-russian-state-sponsored-targeting - 5 Insights from Frost & Sullivan’s 2025 Frost Radar for Cloud Security Posture Management
Microsoft’s write-up on the Frost & Sullivan CSPM radar is really a positioning piece, but the underlying point holds: cloud misconfiguration is still one of the easiest ways in. Nothing groundbreaking here, but if you’re not actively checking client tenants for config drift and exposed settings, CSPM is worth getting your head around.
https://www.microsoft.com/en-us/security/blog/2026/07/06/5-insights-from-frost-sullivans-2025-frost-radar-for-cloud-security-posture-management/
Microsoft 365 & Windows
- More Control and Better Accessibility with Permalinks in SharePoint Online
SharePoint Online is getting permalinks — stable links that keep working even when a file is renamed or moved. If you build client intranets or documentation libraries, link rot is a genuine support drain, so this quietly removes a recurring headache. Good reminder to standardise on permalinks for anything people are meant to bookmark.
https://techcommunity.microsoft.com/blog/microsoft365insiderblog/more-control-and-better-accessibility-with-permalinks-in-sharepoint-online/4532713 - Cross-Tenant Message Recall in Exchange Online
Exchange Online can now recall a sent message across tenant boundaries, not just inside your own org. For MSPs juggling multiple client tenants and the occasional reply-all disaster, this widens where recall actually works. Still early and it won’t undo every mistake, but it’s a useful capability to know is there.
https://techcommunity.microsoft.com/blog/exchange/cross-tenant-message-recall-in-exchange-online/4535800
Cloud & AI
- What’s New in Agent 365 – June 2026
Microsoft’s June update for Agent 365 keeps building out the tooling to register, secure and manage AI agents like any other identity. As clients start spinning up agents, ungoverned sprawl is the next Shadow IT problem heading your way. Still early, but this is a space MSPs should be watching now rather than after the agent count explodes.
https://techcommunity.microsoft.com/blog/agent-365-blog/whats-new-in-agent-365-%E2%80%93-june-2026/4535107
As always, the challenge isn’t finding information — it’s focusing on what actually matters.
After hours
I Only Made $50 Training Robots – https://www.youtube.com/watch?v=yfZhpEupz5M
Editorial
If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.
If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.
Watch out for the next CIA Brief next week