Follow the latest coverage, related explainers and connected technology stories.
Microsoft Threat Intelligence has revealed NeedyMantis, a modular malicious software framework used after compromising the target environment to maintain access and conduct subsequent operations. Microsoft observed its use in limited operations targeting telecommunications entities, universities, and medical and government organizations, with indicators linking the activity to China-based entities without attributing it to a specific government entity.
Microsoft is investigating a defect in Defender for Office 365 Safe Links that caused some legitimate Google Search links to be classified as malicious and blocked from opening. IT administrators may receive incident-related alerts in Microsoft Defender and Microsoft Sentinel, with no impact scope or remediation timeline announced.
Microsoft has unveiled August 2026 updates to the Microsoft Security portfolio, including expanding the Defender Experts MDR service to cover data sources outside the Microsoft ecosystem and improving the management of identities, devices, and data. The company also added guidance for containing AI agents and increased Purview’s capacity for applying automatic classifications to 500,000 files per day.
Frost & Sullivan named Microsoft a visionary leader in its 2026 report on cloud workload protection platforms, highlighting Microsoft Defender for Cloud’s capabilities in connecting runtime security with identities, code, and security operations center processes.