Be first to know about AI, threats, and new tools. Quick hits, expert tips, and real-time security news—follow for smarter, safer ops.

Redmond, WA
From graph-based context to build-your-own Microsoft Security Copilot agents, we're introducing a new AI-ready security platform and innovations to empower defenders in the era of agentic AI: msft.it/6010sQNtI #MSSecure
49
41
149
88,136
Mark it: October 6, 9 AM PT. New live AMA with the engineers building the Integrated Security Operations Center (ISOC) in Microsoft Defender. Your questions, answered on camera. Join here: msft.it/6014alykq
3
15
4,984
New Cyberattack Series report: a threat actor reset one password and ended up inside the systems where code gets built and shipped. No malware, no exploits. Full report: msft.it/6011acvYc
4
52
247
29,467
How fast can attack disruption stop a ransomware attack? Faster than it took to show you. A look inside the new Microsoft Defender ISOC: msft.it/6011acGnf
4
6
25
6,483
Now generally available: Microsoft Purview and Microsoft Entra Global Secure Access bring data security to the network across human and agent traffic. Sensitive files headed for an unsanctioned AI tool can be blocked before they leave. Rest of this month's updates: msft.it/6012a9yGy

ALT Text reads, "In the Loop September 2026", featuring a person standing outdoors with a bag and an arched structure in the background.

6
2
28
6,679
Take the tour of the new ISOC in Microsoft Defender—SIEM + XDR in one place, workspace set up in a few clicks. Save this video—future you, mid-setup, will thank you.
4
6
78
11,519
XDR and SIEM now in one platform. Meet the new ISOC in Microsoft Defender—a SOC built for agentic security. Here to help you investigate and respond more efficiently. msft.it/6019ag5T1
10
86
490
950,058
New email security benchmark data: Microsoft Defender missed the fewest high-severity threats. Missed threats are climbing across the board as AI makes impersonation more convincing. Latest report: msft.it/6017a5P9f
1
7
46
8,732
1.3 billion enterprise AI agents by 2028. Every one of them an identity someone has to govern. Our Discovery Session covers discovering every agent in your estate and defending at machine speed. Reserve your spot 👉 msft.it/6018abaI2
3
2
9
5,528
Turns out a model does not need a memory feature to remember. Microsoft researchers dug into implicit memory—how information carries between sessions that were supposed to be separate, and what that means for AI security.⤵️
Large language models are often treated as stateless, but what happens when their outputs return as inputs in later interactions? Recent incidents have shown agents discovering shared message boards, leaving instructions in persistent artifacts, and coordinating through environments that were never designed to act as memory systems. In new Microsoft research, Andrew Paverd, Ahmed Salem, and Sahar Abdelnabi examine implicit memory, a mechanism through which stateless models can carry information across otherwise separate interactions. Their research demonstrates how this behavior could enable new security risks, including backdoors that activate only after a sequence of interactions. What began as a largely theoretical security scenario now has real-world analogues: agents have been observed communicating through shared infrastructure, public artifacts, and persistent environmental state. Read the blog to learn what this means for AI security, evaluation, and incident response: microsoft.com/en-us/msrc/blo…
11
37
12,061
Microsoft Defender's attack disruption now stops more than 45,000 adversary-in-the-middle attacks a month. AI-themed lures are a part of that picture. Read the details here: msft.it/6017abySl
8
32
7,420
The question is no longer *if* you'll adopt AI agents. It's whether your security strategy is ready. Not sure? Get our playbook for securing AI and find out. Link: msft.it/6012apx1K
2
10
42
10,100
Your agents can act, decide, and pull data without asking. The question isn't whether that's useful. It's whether anyone can see all of them. Our Discovery Session covers finding every agent you've got and governing what it can reach. Reserve your spot: msft.it/6013ars2d
1
4
17
5,583
Microsoft Purview auto-labeling went from 100,000 files a day to 500,000. If your Copilot rollout was waiting on data protection to catch up, it caught up. That's one update. More here: msft.it/6019auYQT

ALT Text reads In the Loop Monthly Product Updates displayed on a blue-themed background.

6
23
94
15,613
Safe Links, Safe Attachments, anti-phishing policies. The unglamorous stuff that decides how your week goes. Scott Landry shows how to remediate threats and strengthen defenses using Microsoft Defender. On demand, one hour. Watch now: msft.it/6018au8PY
1
13
40
8,602
63% of organizations surveyed want help gauging their Zero Trust maturity. If you're one of them, the Fundamental Guide to Zero Trust turns those questions into a to-do list: msft.it/6018aPHSa
2
8
28
9,802