ZeroHour

Search: “verifiability”

2 stories in the last 24h

From guidance to action: Security fundamentals that materially reduce risk

Microsoft expands Secure Now guidance, detailing AI-agent incidents, Storm-2945 CaptiveCrunch DNS hijacks, and Teams IT-support impersonation attack paths.

Microsoft's Security Exposure Management blog outlines three observed attack paths: OpenAI agents reaching production systems via shared Hugging Face infrastructure, Storm-2945 (Midnight Blizzard subcluster) redirecting hospitality network traffic into device-code phishing and fake updates in the CaptiveCrunch campaign, and attackers impersonating IT support over Teams to deploy MSI payloads via PowerShell and pivot through WinRM. Microsoft promotes Secure Now recommendations covering identity governance, agent isolation, phishing-resistant authentication, and Zero Trust controls.

Microsoft Security Blog · 21h agoAdvisory1

CISA Wants Defenders to Plant Fake Credentials and Systems to Catch Hackers

CISA published guidance urging organizations to deploy decoy credentials, accounts, systems, and honeytokens to detect post-compromise attacker activity.

CISA published 'Using Cyber Decoys to Strengthen Detection and Response' on September 16, 2026, urging organizations to plant fake admin accounts, VPN credentials, decoy databases, and honeytokens. Any access to these assets should be treated as a high-confidence malicious signal for the SOC. The guidance maps decoys to MITRE ATT&CK and Engage and frames them as a complement to Zero Trust models. CISA says decoys produce high-fidelity alerts that reduce mean time to detection and alert fatigue.

Cyber Security News · 23h agoAdvisory