Insights — Latest thinking

Articles on Microsoft cloud security, identity architecture and AI readiness.

Storm-1175 hits in 24 hours — how to protect your hybrid M365 stack from Medusa

April 20, 2026

Microsoft Threat Intelligence reports that Storm-1175 deploys Medusa ransomware within a single day of initial access. Here is what we check first at HaggeBurger.

RedSun and UnDefend now weaponized — two Defender zero-days still unpatched

April 18, 2026

BlueHammer is patched, but RedSun and UnDefend are now actively exploited with no fix yet. Here is how to protect Defender-based Windows endpoints.

Critical SharePoint flaw CVE-2026-32201 — patch before the weekend

April 18, 2026

CISA added CVE-2026-32201 to KEV and the flaw is being exploited against SharePoint Server. Here is how to check whether your environment is exposed.

Critical Windows IKE RCE CVE-2026-33824 — verify the April patch this week

April 17, 2026

An unauthenticated RCE with CVSS 9.8 in the Windows IKE Service Extensions can hit every domain-joined Windows host. Here is how to confirm the April patch actually deployed.

Device code phishing hits record levels — hundreds of M365 accounts compromised daily

April 16, 2026

Microsoft reports 10-15 campaigns per day. How to block the attack in Conditional Access.

Critical SharePoint Zero-Day Actively Exploited — Patch Now

April 16, 2026

CVE-2026-32201 is actively exploited against SharePoint Server. Here is how to protect your environment.

Ransomware hit two Swedish municipalities — is your business ready?

April 16, 2026

Two Swedish municipalities forced back to paper and pen. How to avoid the same fate.

SharePoint vulnerability CVE-2026-32201 — patch now, attackers are active

April 15, 2026

Microsoft released an emergency fix for SharePoint Server on April 14. CISA added it to the KEV catalog the same day. If you run SharePoint on-prem you need to act this week.

April 2026 Patch Tuesday — do not sleepwalk into the June 26 Secure Boot deadline

April 14, 2026

Microsoft shipped today's Patch Tuesday with 80-100+ CVEs. The bigger story is the June 26 Secure Boot certificate expiry — you have two Patch Tuesdays left.

BlueHammer — unpatched Windows zero-day grants SYSTEM via Defender updates

April 11, 2026

A published zero-day in Windows Defender signature updates gives attackers SYSTEM privileges. No patch exists. Here is how to protect your endpoints.

AI-powered phishing hits M365 — hundreds of orgs compromised daily

April 10, 2026

Storm-2755 uses AI to craft phishing emails that trick M365 users into giving up their tokens. Here is how to protect yourself.

Russian hackers steal M365 logins via your router — what to do now

April 10, 2026

APT28 compromised 18,000 routers to steal Microsoft 365 tokens. Here is how to check if your customers are affected.

EvilTokens hijacks M365 accounts — how to block it

April 4, 2026

New phishing-as-a-service kit bypasses MFA entirely through Microsoft 365 device code flow. Here is how to block it.

EvilTokens — new phishing attack bypasses MFA entirely via device code flow

April 3, 2026

New PhaaS platform steals M365 tokens by tricking users into authenticating on Microsofts own login page.

Kerberos RC4 hardening goes live in April — check your service accounts

April 3, 2026

April Windows updates enforce AES-only Kerberos for service accounts. Legacy RC4 dependencies will break.

Region Värmland hacked for four months — how to protect your M365 environment

April 2, 2026

Attackers had access to Region Värmland M365 email accounts for four months. CERT-SE warns of increasing BEC attacks against Swedish organizations.

Critical Chrome/Edge Zero-Day CVE-2026-5281 — Update Now

April 2, 2026

An actively exploited vulnerability in Chrome and Edge requires immediate patching. CISA added CVE-2026-5281 to its KEV catalog.

Kerberos RC4 enforcement April 2026 — what to do before patching

April 1, 2026

Microsoft April update enforces AES-only Kerberos. Service accounts still using RC4 will break. Here is how to prepare.

MFA does not protect against device code phishing — here is what does

April 1, 2026

Over 340 M365 organizations compromised via device code phishing. MFA is useless. Here is how to block it.

Device code phishing bypasses MFA — 340+ M365 organizations compromised

March 31, 2026

The EvilTokens platform steals M365 tokens that survive password resets. Here is how to block the attack in Conditional Access.

Excel vulnerability weaponizes Copilot — patch now

March 31, 2026

CVE-2026-26144 allows an attacker to use Copilot Agent in Excel to exfiltrate data without any user interaction.

Device code phishing hits 340 M365 orgs — block the flow now

March 29, 2026

Russian threat actors exploit Microsoft device code authentication to hijack M365 accounts. Conditional Access can stop it.

Outlook vulnerability runs malicious code without opening the email

March 29, 2026

CVE-2026-26113 and CVE-2026-26110 allow code execution just by viewing an email in the Preview Pane.

The Perfect Home Office: Monitor, Keyboard, and Headset

March 27, 2026

The right accessories make the difference between a home office that works and one that frustrates. Here is what you need.

Tablets in Business: From Warehouse to Boardroom

March 27, 2026

How to use tablets as productivity tools in your business — not just entertainment devices.

Managing Company Phones with Intune: iPhone and Android

March 27, 2026

How to secure, configure, and manage all company phones centrally — whether iPhone or Android.

Why Intune and Autopilot Transform IT Management for SMBs

March 27, 2026

Stop configuring laptops manually. With Intune and Autopilot, you set up a new device in 15 minutes instead of 3 hours.

How to Choose the Right Laptop for Microsoft 365 Business Premium

March 27, 2026

A guide for IT managers at Swedish SMBs who want to select the right hardware for Microsoft 365, Intune, and Defender.

5 Things to Consider When Buying IT Hardware for Your Business

March 27, 2026

Avoid costly mistakes when upgrading your company IT. Here are the five most important questions to ask before you buy.

New Phishing Attack Bypasses MFA via Device Code — Block It Now

March 27, 2026

Active campaign steals M365 tokens via OAuth device code flow. 340+ organizations compromised. Here is how to block the attack.

Hackers Wiped 200K Devices via Intune — Protect Your Environment Now

March 27, 2026

Iran-linked Handala used Microsoft Intune to wipe 200,000+ devices at Stryker. Here is how to protect your organization.

Region Varmland hacked for four months — how to protect your business

March 26, 2026

A Swedish government region suffered a phishing attack that gave attackers access to email accounts for four months undetected. Here is how to avoid the same fate.

Critical Office RCE vulnerabilities — the Preview Pane is the attack surface

March 26, 2026

Two critical RCE vulnerabilities in Microsoft Office let attackers execute code just by previewing a document in Outlook. Patch now.

Tycoon2FA is back — MFA bypass against M365 works again

March 25, 2026

The Tycoon2FA phishing platform is back after Europol's takedown. AiTM attacks bypass standard MFA and steal M365 tokens.

Entra ID deadline March 31 — apps without service principal will break

March 25, 2026

Microsoft Entra ID stops supporting app auth without a service principal on March 31. Check your app registrations now.

AI-powered phishing campaign hits 340+ organizations — M365 tokens stolen

March 25, 2026

Active device code phishing campaign exploits Railway.com and AI-generated lures to steal M365 tokens. Password resets won't help.

Excel vulnerability lets Copilot silently leak your data

March 25, 2026

CVE-2026-26144 enables attackers to weaponize Copilot Agent for zero-click data exfiltration from Excel. Patch now.

Swedish Security Service warns — constant cyberattacks on Swedish organizations

March 24, 2026

Säkerhetspolisen annual report confirms: cyberattacks against Swedish organizations are constant. What SMBs should do now.

The DarkSword attack — your iPhones could give hackers access to company data

March 24, 2026

CISA warns of actively exploited iOS attack chain threatening anyone running Microsoft Authenticator, Outlook, or Teams on iPhone.

Handala Detection Pack v2: Sigma rules for Intune bulk wipe prevention

March 23, 2026

ThreatHunter.ai published Detection Pack v2 with five new Sigma rules and KQL queries for Microsoft Sentinel covering: MuddyWater pre-positioning IOCs, PIM Authentication Context gap detection, three-layer bulk wipe prevention for Intune, stale session detection, and Rclone exfiltration detection.

Copilot as attack vector — Excel flaw enables zero-click data exfiltration

March 23, 2026

CVE-2026-26144 in Excel can be exploited to make Microsoft Copilot exfiltrate sensitive data without any user interaction.

The Stryker Attack: CISA demands Intune hardening after 200,000 devices wiped

March 23, 2026

CISA urges all organizations to harden Microsoft Intune after Iran-linked Handala wiped 200,000 devices at medtech giant Stryker.

Excel vulnerability weaponizes Copilot for data theft — CVE-2026-26144

March 21, 2026

A critical Excel vulnerability combines XSS with prompt injection to turn Copilot Agent into a data exfiltration tool. Zero-click — no user interaction required.

Teams calls from fake IT support — how one call compromises an entire company

March 20, 2026

Microsoft DART reveals how attackers use Teams voice calls and Quick Assist to deploy backdoors. Here is how to protect your organization.

Critical SharePoint Zero-Day Under Active Exploitation — Patch Before Friday

March 19, 2026

CISA added CVE-2026-20963 to its Known Exploited Vulnerabilities catalog with a 3-day patch deadline. If you run SharePoint on-prem, act now.

Why Your Organization Should Invest in FIDO2 and Passkeys in Entra ID

March 9, 2026

Passwords are the weakest link in enterprise security. FIDO2 security keys and passkeys in Microsoft Entra ID offer a phishing-resistant alternative that eliminates credential theft entirely.

Microsoft 365 Tenant Consolidation After Mergers & Acquisitions

March 9, 2026

When two companies merge, their IT environments collide. Duplicate tenants, overlapping identities, and inconsistent security policies create cost, risk, and friction. Here is a structured approach to M365 tenant consolidation.

AI in 2025-2026: The Acceleration Is Real — And So Are the Security Risks

March 8, 2026

The last six months have seen an unprecedented acceleration in AI capabilities. From reasoning models to autonomous agents, the technology is advancing faster than most organizations can adapt.

Maximize the Security You Already Paid For: Microsoft 365 Business Premium

March 7, 2026

Most organizations running Microsoft 365 Business Premium are only using a fraction of the security features included in their license. Here is how to unlock the full value.