Microsoft Defender for Endpoint Archives | Microsoft Security Blog

Microsoft Security Blog

3 min read Original article ↗
  • 17 min read

    Email threat landscape: Q2 2026 trends and insights

    In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly automated and multi-stage attack chains.

  • 24 min read

    The Gentlemen ransomware: Dissecting a self-propagating Go encryptor

    Microsoft Threat Intelligence presents a comprehensive analysis of The Gentlemen, a Go-based ransomware deployed by affiliates of Storm-2697 that combines per-file ephemeral key encryption with an aggressive self-propagation module to deploy itself across an entire network using series of simultaneous lateral movement techniques per target.

  • 9 min read

    Exposing Fox Tempest: A malware-signing service operation

    Fox Tempest is a financially motivated threat actor operating a malware‑signing‑as‑a‑service (MSaaS) used by other cybercriminals, including Vanilla Tempest and Storm groups, to more effectively distribute malicious code, including ransomware.

  • 11 min read

    Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise

    Microsoft Incident Response investigated an attack operated through legitimate and trusted administrative mechanisms to blend seamlessly into routine operations and remain undetected demonstrating that intrusions have increasingly avoided using noisy exploits, obvious malware, or custom tooling, instead leveraging systems that organizations already trust within their environments.