CIA Brief 20261003

image

Security

  • Insights from the 2026 Microsoft Digital Defense Report

    Microsoft’s 2026 Digital Defense Report, introduced by Terrell Cox, looks across an environment where threats span infrastructure, identities, applications, cloud, and software supply chains. The post says threat actors are using AI in reconnaissance, social engineering, malware and exploit development, and post-compromise work, while agents that reach enterprise data and tools need identity, access, and monitoring controls. It also covers AI-assisted vulnerability discovery and why defenders get more from connecting signals across systems than from any single source.

    Insider Threat Mitigation Guide

  • CISA’s Insider Threat Mitigation Guide is written for critical infrastructure stakeholders on what insider threats are, the forms they take, and how to build or improve a mitigation program. The 2026 edition updates case studies, statistics, and interactive features from the 2020 edition, and adds material on hybrid and remote work and on Super Intelligence. The guide covers intentional and unintentional threats, detection, assessment, threat management, and steps to stand up a program.

    Phishing Abuses RMM Tools for Persistent Access

  • Microsoft Defender Experts describes July 2026 phishing that delivered a legitimate MSP360 remote-management installer under deceptive names, using lures such as meeting invitations, PDF themes, and software-update prompts. After installation, the MSP360 agent was used to download and silently install a ConnectWise ScreenConnect client, giving a second remote-access channel; Microsoft says it did not see ScreenConnect itself exploited. Follow-on activity included credential access and local data collection, and a similar pattern was also seen with Faronics Deploy. Microsoft has not attributed the campaigns to a named threat actor.

    Star Blizzard refines phishing and malware delivery with the RedFlick technique

  • Since January 2026, Microsoft has seen the Russian state actor Star Blizzard move toward larger phishing campaigns, accounts on compromised websites, and a delivery technique it tracks as RedFlick. RedFlick uses scheduled tasks to deploy the CosmicPulse backdoor after a single user interaction, a shift from earlier ClickFix chains that needed several victim steps. Campaigns have targeted Ukrainian individuals and institutions and international NGOs, think tanks, governments, and financial organisations linked to Ukraine policy, with Microsoft reporting impact on over 100 organisations, mainly in the United States and the United Kingdom.

    NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

  • Microsoft Threat Intelligence describes NeedyMantis, a modular post-compromise malware family seen in a limited set of targeted intrusions against telecommunications organisations, universities, medical nonprofits, intergovernmental organisations, and government contractors. Activity dates to at least October 2025 and was found while following indicators from the DAEMON Tools supply-chain compromise; Microsoft associates at least some use with Storm-3069 and with operators it links to China, without attributing every case to one actor. The malware is typically deployed after access already exists, and uses DLL sideloading, custom encrypted archives, and loadable modules for longer-term access.

    Storm-3168: Agentic-driven cloud attacks using compromised service principals

  • Microsoft Security Research reports Azure activity it tracks as Storm-3168, expanding on the JADEPUFFER agentic ransomware operation Sysdig described in July 2026. In one tenant, compromised service principals enumerated resources and then, in a short destructive sequence, deleted many storage accounts plus a Key Vault, Function App, and App Service plan, while SQL database deletions failed because of an unsupported API version. The same identity later listed storage account keys. Microsoft did not see a ransom note or confirm data theft in the activity described, and notes a client secret for one principal had earlier been exposed in a public GitHub issue, though it could not confirm that secret was the one used.

    Product announcements

  • Action Required: Upgrade ExchangeOnlineManagement PowerShell Module to Version 3.10.1 or Newer

    Microsoft says ExchangeOnlineManagement 3.10.1 and newer add security changes to Exchange Online PowerShell authentication, and it plans stricter logon enforcement from 31 March 2027. After that date, versions older than 3.10.1 may fail in some interactive sign-in scenarios, while 3.10.1 and later should keep working. People most likely to be affected are those on older module versions, PowerShell 7, and interactive authentication with Web Account Manager disabled; certificate-based authentication is not expected to be affected, but Microsoft still recommends the upgrade.

    EWS Deprecation Is Here – What This Means To You

  • Exchange Web Services deprecation in Exchange Online starts with this post, dated 1 October 2026. From early October 2026, setting EWSEnabled to True is no longer enough on its own: an EWSAllowedAppIDs allow list is required for apps that should still use EWS. Microsoft will record affected worldwide tenants at the end of 2 October (Pacific Time), populate allow lists on 8–9 October from the previous 60 days of use, and turn on the requirement from 10 October, with a later phase for tenants that never changed EWSEnabled and never created an allow list.

    An IT pro’s guide to Windows 11, version 26H2

  • Windows 11, version 26H2 is generally available as the next annual feature update, delivered as an enablement package for devices already on version 25H2 or 24H2. The post groups what it turns on across security (including administrator protection, built-in Sysmon, Smart App Control without a clean install, and post-quantum cryptography APIs), management and deployment, and everyday Windows experiences such as File Explorer, Search, Start, and Task Manager. Support resets to 24 months for Home and Pro and 36 months for Enterprise and Education. The first monthly security update for 26H2 is slated for 13 October 2026.

    Now in public preview: Microsoft 365 SharePoint Storage and OneDrive Storage

  • Microsoft 365 SharePoint Storage and Microsoft 365 OneDrive Storage are in public preview for eligible commercial customers, using pay-as-you-go billing tied to an Azure subscription. They add capacity when a tenant goes past included SharePoint quota or a user goes past their OneDrive licensed quota, without a fixed extra storage subscription. Admins can cap extra OneDrive storage per user, and the post explains how active SharePoint storage can be billed together with Microsoft 365 Archive at a lower blended rate. While a tenant is enrolled in SharePoint Storage, quota warning email and admin-center banners are suppressed.

    AI and Copilot

  • Available today: OpenAI’s GPT-6.1 Sol and Claude Sonnet 5.5 in Microsoft Copilot

    Microsoft is adding GPT-6.1 Sol and Claude Sonnet 5.5 to Copilot model choice, after Claude Opus 5.5 and GPT-6 Sol earlier in the month. Both new models start rolling out with usage-based billing in Copilot Cowork and Copilot Studio. They also begin a phased rollout over the coming week in Word, Excel, PowerPoint, and Chat under the user subscription licence, with limits that Microsoft says most people are not expected to hit; users are warned as they approach a limit and can switch to Auto or another model. The post says Work IQ grounds responses in the organisation’s files, meetings, chats, and business data within existing permissions.

    What’s New in Microsoft Copilot | September 2026

  • The September roundup points back to the new Copilot with Home, Code, and Autopilot, then lists other changes for users and admins. User items include a refreshed Copilot Chat in Teams and Outlook, inline agents and skills, a Teams Phone agent, citations and image editing in Word, skills and connectors in PowerPoint, and general availability for Copilot in SharePoint and OneDrive. Admin items include authoritative sources for Copilot Search in the Microsoft 365 admin center (up to 100 SharePoint sites) and targeted Pulse surveys from the Copilot Dashboard. Several items are called out as rolling out in October, including the Edge new-tab Copilot experience and long-running PowerPoint tasks.

    Work IQ: Business and workplace intelligence in the flow of work

  • Work IQ now grounds Copilot and agents in Dynamics 365 and Power Platform business data, in preview from 30 September 2026 with rollout continuing through October 2026. The post describes a shared semantic model, reusable business skills, and governed actions so Copilot can answer business questions and update source records within the user’s permissions, with Dataverse as the store behind the model and skills. Dynamics 365 Finance and Operations support is noted as rolling out in late October 2026. Governance stays split across the Microsoft 365 admin center, Power Platform admin, and makers, under Microsoft Agent 365.

    Microsoft releases Copilot update: Here’s what you need to know

  • This CNBC Television segment, titled on YouTube as in the Teams post, covers Microsoft’s Copilot update as it competes with other work agents. The report describes one app that brings together work, coding, and an Autopilot mode for background tasks and custom agents, instead of keeping Office Copilot separate from GitHub Copilot. It also says users can switch among OpenAI, Anthropic, and Microsoft models, and that charging for some of these tools is moving from a flat subscription toward usage-based pricing.

    The new Copilot is here: The opportunity for Microsoft partners

  • One post shares the Microsoft Partner Blog article under this title. A later post in the same channel, headed “Cowork will be enabled by default with CSP”, quotes the 25 September 2026 partner announcement: starting 2 November 2026, usage-based billing will be enabled by default for new Microsoft 365 Copilot Business licences purchased through CSP, and says that makes it easier to activate eligible experiences such as Copilot Cowork. Both posts use the same partner article URL.

    After hours

    How do Graphics Cards Work? Exploring GPU Architecture – https://www.youtube.com/watch?v=h9Z4oGN89MU

    Editorial

    If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

    If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

    Watch out for the next CIA Brief next week

Leave a comment