Continue reading the full briefing.
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected environments, and practical guidance for detection, hunting, and remediation. The post ChainDrop supply chain compromise: Anatomy of a self-propagating worm appeared first on Microsoft Security Blog.
Why it matters: Microsoft Security Blog participates in the path from source code to production. A weakness can inherit runner permissions, build secrets, trusted artifacts, or deployment access.
What to verify: Trace untrusted input through pull requests and jobs, review token scope, isolate runners, pin trusted dependencies, and rebuild affected artifacts after remediation.
Operational focus: Check supported builds, update installation, restart state, and the current running version.
Open the original Microsoft Security Blog record
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
Microsoft expands its Zero Trust for AI strategy to enhance security for AI and DevSecOps environments with new tools and guidance. The post Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps appeared first on Microsoft Security Blog.
Why it matters: Microsoft Security Blog should be mapped to supported builds, deployed roles, restart requirements, and endpoint monitoring coverage.
What to verify: Start with asset ownership and exposure, compare the fixed release with the deployed build, and validate both security behavior and service health afterward.
Operational focus: Prioritize domain, federation, collaboration, and internet-facing servers before normal endpoint queues.
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft appeared first…
Why it matters: Microsoft Security Blog should be mapped to supported builds, deployed roles, restart requirements, and endpoint monitoring coverage.
What to verify: Separate confirmed applicability from broad advisory language, assign the remediation decision, and keep any exception visible with an expiry date.
Operational focus: Review privileged access and endpoint telemetry for signs of abuse before and after patching.
What’s new in Microsoft Security: July 2026
This month’s updates help security and IT teams secure their AI environments, use AI to defend, and strengthen the foundations that AI-powered operations depend on. The post What’s new in Microsoft Security: July 2026 appeared first on Microsoft Security Blog.
Why it matters: Microsoft Security Blog should be mapped to supported builds, deployed roles, restart requirements, and endpoint monitoring coverage.
What to verify: Confirm the affected version and reachable component, preserve useful telemetry, apply the publisher guidance, and record the evidence used to close the item.
Operational focus: Check supported builds, update installation, restart state, and the current running version.
Tame Dependabot: Group your updates, slow the cadence, keep security fast
Dependabot keeps your dependencies current, but its defaults can flood your repository with pull requests. Here's how grouping updates, slowing the cadence, and keeping security fixes fast cut the noise on a Microsoft open source project. The post Tame Dependabot: Group your updates, slow the cadence, keep security fast appeared first on The GitHub Blog.
Why it matters: GitHub Security Blog participates in the path from source code to production. A weakness can inherit runner permissions, build secrets, trusted artifacts, or deployment access.
What to verify: Trace untrusted input through pull requests and jobs, review token scope, isolate runners, pin trusted dependencies, and rebuild affected artifacts after remediation.
Operational focus: Prioritize domain, federation, collaboration, and internet-facing servers before normal endpoint queues.
Deployment plan
Connect each advisory to supported builds and deployed server roles. Identity and internet-facing systems should move before routine endpoint waves, with restart and EDR health verified afterward.
- Match Microsoft and CISA records to Windows builds and server products in inventory.
- Prioritize identity, SharePoint, Exchange, remote access, and domain-privileged systems.
- Test monthly updates, install promptly, and validate reboot or service restart completion.
- Review EDR health, tamper protection, authentication logs, and privileged group changes.
- Give every patch exception a business owner, mitigation, and expiry date.
Endpoint and server checks
Check build numbers, installed updates, restart state, privileged authentication, EDR coverage, and server-role health.
- Check supported builds, update installation, restart state, and the current running version.
- Prioritize domain, federation, collaboration, and internet-facing servers before normal endpoint queues.
- Review privileged access and endpoint telemetry for signs of abuse before and after patching.
Windows team takeaway
A successful Windows update cycle protects identity and public server roles first, proves the new build is active, and keeps every exception visible.
References used in this briefing
- GitHub Advisory Database: CVE-2026-70482: Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client
- NIST NVD and Microsoft: CVE-2026-57092: Windows VMSwitch use-after-free privilege escalation
- Microsoft Security Blog: 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
- Microsoft Security Blog: ChainDrop supply chain compromise: Anatomy of a self-propagating worm
- Microsoft Security Blog: Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
- Microsoft Security Blog: CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
- Microsoft Security Blog: What’s new in Microsoft Security: July 2026
- GitHub Security Blog: Tame Dependabot: Group your updates, slow the cadence, keep security fast
Need to add context to this briefing?
Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.

