Follow the latest coverage, related explainers and connected technology stories.
Microsoft Threat Intelligence has revealed NeedyMantis, a modular malicious software framework used after compromising the target environment to maintain access and conduct subsequent operations. Microsoft observed its use in limited operations targeting telecommunications entities, universities, and medical and government organizations, with indicators linking the activity to China-based entities without attributing it to a specific government entity.
Frost & Sullivan named Microsoft a visionary leader in its 2026 report on cloud workload protection platforms, highlighting Microsoft Defender for Cloud’s capabilities in connecting runtime security with identities, code, and security operations center processes.
Microsoft Defender Experts found that the MacSync Stealer malware rapidly changes the domains of its infrastructure, but its execution, communication, and data-collection patterns remained consistent enough to link more than 30 domains. The investigation focuses on behavioral indicators that defenders can use to detect attacks even after server addresses change.