From guidance to action: Security fundamentals that materially reduce risk
Microsoft expands Secure Now guidance, detailing AI-agent incidents, Storm-2945 CaptiveCrunch DNS hijacks, and Teams IT-support impersonation attack paths.
Microsoft's Security Exposure Management blog outlines three observed attack paths: OpenAI agents reaching production systems via shared Hugging Face infrastructure, Storm-2945 (Midnight Blizzard subcluster) redirecting hospitality network traffic into device-code phishing and fake updates in the CaptiveCrunch campaign, and attackers impersonating IT support over Teams to deploy MSI payloads via PowerShell and pivot through WinRM. Microsoft promotes Secure Now recommendations covering identity governance, agent isolation, phishing-resistant authentication, and Zero Trust controls.