# defender

Published articles for defender.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs

DevFeed: [September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs](<https://devfeed.tech/articles/september-2026-patch-tuesday-two-exploited-zero-days-and-113-critical-vulnerabilities-among-972-cves-8309.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-september-2026/>)

Author: Falcon Exposure Management Team

Published: 2026-09-12T11:17:51.295154Z

Content type: news

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [analysis](<https://devfeed.tech/tags/analysis.md>), [defender](<https://devfeed.tech/tags/defender.md>), [exposure-management](<https://devfeed.tech/tags/exposure-management.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [patch-tuesday](<https://devfeed.tech/tags/patch-tuesday.md>), [security](<https://devfeed.tech/tags/security.md>), [september-2026](<https://devfeed.tech/tags/september-2026.md>), [updates](<https://devfeed.tech/tags/updates.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Microsoft's September 2026 Patch Tuesday addresses 972 vulnerabilities, including two exploited zero-days and 113 critical issues. The article also notes a disclosed proof-of-concept zero-day exploit against Microsoft Defender.

### Source excerpt

Microsoft has released security updates for 972 vulnerabilities, including two exploited zero-days and 113 critical, in its September 2026 Patch Tuesday rollout.

## Detect and disrupt AI-themed attacks with Microsoft Defender

DevFeed: [Detect and disrupt AI-themed attacks with Microsoft Defender](<https://devfeed.tech/articles/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender-7644.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/10/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender/>)

Author: Rob Lefferts

Published: 2026-09-10T16:00:00Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [adversary-in-the-middle-aitm](<https://devfeed.tech/tags/adversary-in-the-middle-aitm.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [claude](<https://devfeed.tech/tags/claude.md>), [copilot](<https://devfeed.tech/tags/copilot.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [deepseek](<https://devfeed.tech/tags/deepseek.md>), [defender](<https://devfeed.tech/tags/defender.md>), [github](<https://devfeed.tech/tags/github.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

Microsoft describes AI-themed phishing, malvertising, credential theft, and malware campaigns that impersonate popular AI services and tools. It argues that attackers are exploiting trust and urgency around AI brands rather than compromising the referenced services.

### Source excerpt

See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.

## Serial Microsoft 0-day hunter drops yet another Defender exploit

DevFeed: [Serial Microsoft 0-day hunter drops yet another Defender exploit](<https://devfeed.tech/articles/serial-microsoft-0-day-hunter-drops-yet-another-defender-exploit-8560.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/09/serial-microsoft-0-day-hunter-drops-yet-another-defender-exploit/5295335>)

Author: Jessica Lyons

Published: 2026-09-09T17:23:00Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [defender](<https://devfeed.tech/tags/defender.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

The article reports another Microsoft Defender exploit, characterized as a bypass of prior bypasses.

### Source excerpt

A bypass of a bypass of a bypass

## Why Rider and ReSharper Were Slow to Start, and How Microsoft Helped Fix the Problem

DevFeed: [Why Rider and ReSharper Were Slow to Start, and How Microsoft Helped Fix the Problem](<https://devfeed.tech/articles/why-rider-and-resharper-were-slow-to-start-and-how-microsoft-helped-fix-the-problem-8801.md>)

Original publisher: [Read original article](<https://blog.jetbrains.com/dotnet/2026/09/09/why-rider-and-resharper-were-slow-to-start-and-how-microsoft-helped-fix-the-problem/>)

Author: Alexander Ulitin

Published: 2026-09-09T16:45:27Z

Content type: article

Language: en

Sources: [The JetBrains Blog](<https://devfeed.tech/sources/the-jetbrains-blog.md>)

Topics: [resharper](<https://devfeed.tech/topics/resharper.md>), [out-of-process](<https://devfeed.tech/topics/out-of-process.md>), [Latency](<https://devfeed.tech/topics/latency.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [defender](<https://devfeed.tech/tags/defender.md>), [logs](<https://devfeed.tech/tags/logs.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [net-tools](<https://devfeed.tech/tags/net-tools.md>), [oop](<https://devfeed.tech/tags/oop.md>), [out-of-process](<https://devfeed.tech/tags/out-of-process.md>), [performance](<https://devfeed.tech/tags/performance.md>), [resharper](<https://devfeed.tech/tags/resharper.md>), [resharper-oop](<https://devfeed.tech/tags/resharper-oop.md>), [rider](<https://devfeed.tech/tags/rider.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

The article investigates slow ReSharper startup after its out-of-process architecture was introduced. Profiling identified Microsoft Defender scanning as the source of substantial first-launch latency, and describes a repeatable investigation tool built with input from Microsoft.

### Source excerpt

When we launched ReSharper's out-of-process (OOP) architecture, users reported slower startup times for IDEs using ReSharper on Windows. After profiling, the cause surprised us: Microsoft Defender was scanning our process for longer than we expected. This post is about what we found, what we learned working with Microsoft, and a tool we built that allows [...]

## Daybreak for Frontline Defenders: $1B to protect essential services

DevFeed: [Daybreak for Frontline Defenders: $1B to protect essential services](<https://devfeed.tech/articles/daybreak-for-frontline-defenders-1b-to-protect-essential-services-6369.md>)

Original publisher: [Read original article](<https://openai.com/index/daybreak-for-frontline-defenders>)

Published: 2026-09-03T13:15:00Z

Content type: article

Language: en

Sources: [OpenAI News](<https://devfeed.tech/sources/openai-news.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security Attacks](<https://devfeed.tech/topics/security-attacks.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [defender](<https://devfeed.tech/tags/defender.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [frontier-ai](<https://devfeed.tech/tags/frontier-ai.md>), [openai](<https://devfeed.tech/tags/openai.md>), [security](<https://devfeed.tech/tags/security.md>), [training](<https://devfeed.tech/tags/training.md>)

### AI overview

OpenAI introduces Daybreak for Frontline Defenders, a $1 billion initiative providing subsidized cyber AI access, training, support, and partnerships to help defenders protect essential services.

### Source excerpt

OpenAI introduces Daybreak for Frontline Defenders. A $1 billion commitment expands access to frontier cyber AI, training, and support for essential services.

## Counterfeit installers to system compromise: Tracking a deceptive software download campaign

DevFeed: [Counterfeit installers to system compromise: Tracking a deceptive software download campaign](<https://devfeed.tech/articles/counterfeit-installers-to-system-compromise-tracking-a-deceptive-software-download-campaign-7637.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/>)

Author: Microsoft Security Research, Microsoft Defender Experts and Parth Jomadkar

Published: 2026-09-01T22:48:28Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [china](<https://devfeed.tech/tags/china.md>), [defender](<https://devfeed.tech/tags/defender.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

Microsoft documents an active malware campaign that uses counterfeit software-download pages and malicious installers to compromise systems. It outlines the attack chain, Defender XDR detection and disruption, and mitigations for blocking untrusted downloads and strengthening endpoint protections.

### Source excerpt

An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system compromise: Tracking a deceptive software download campaign appeared first on Microsoft Security Blog.

## Cybersecurity IR Workshop: The workshop you shouldn't miss

DevFeed: [Cybersecurity IR Workshop: The workshop you shouldn't miss](<https://devfeed.tech/articles/cybersecurity-ir-workshop-the-workshop-you-shouldn-t-miss-7638.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/01/cybersecurity-ir-workshop-you-shouldnt-miss/>)

Author: Microsoft Defender Experts Cybersecurity Incident Response

Published: 2026-09-01T18:55:35Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [Incident response](<https://devfeed.tech/topics/incident-response.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [dart](<https://devfeed.tech/tags/dart.md>), [defender](<https://devfeed.tech/tags/defender.md>), [identity](<https://devfeed.tech/tags/identity.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [logs](<https://devfeed.tech/tags/logs.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

Microsoft's DART describes a scenario-driven incident-response readiness workshop that lets teams test their plans against simulated security incidents. It covers detection, investigation, containment, communication, threat hunting, and the use of tools, logs, and telemetry under pressure.

### Source excerpt

Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR Workshop: The workshop you shouldn't miss appeared first on Microsoft Security Blog.

## Microsoft cumulative update fixes 206 vulnerabilities, including critical Windows flaws

DevFeed: [Microsoft cumulative update fixes 206 vulnerabilities, including critical Windows flaws](<https://devfeed.tech/articles/security-week-2625-microsoft-23077.md>)

Original publisher: [Read original article](<https://habr.com/ru/companies/kaspersky/articles/1047514/>)

Author: Kaspersky\_Lab ("Лаборатория Касперского")

Published: 2026-06-15T18:48:33Z

Content type: news

Language: ru

Sources: ["Лаборатория Касперского" RU](<https://devfeed.tech/sources/ru-2.md>)

Topics: [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [Security](<https://devfeed.tech/topics/security.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Windows 11](<https://devfeed.tech/topics/windows-11.md>), [DHCP](<https://devfeed.tech/topics/dhcp.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [bitlocker](<https://devfeed.tech/tags/bitlocker.md>), [cve](<https://devfeed.tech/tags/cve.md>), [defender](<https://devfeed.tech/tags/defender.md>), [dhcp](<https://devfeed.tech/tags/dhcp.md>), [github](<https://devfeed.tech/tags/github.md>), [http](<https://devfeed.tech/tags/http.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [microsoft-defender](<https://devfeed.tech/tags/microsoft-defender.md>), [patch-tuesday](<https://devfeed.tech/tags/patch-tuesday.md>), [security](<https://devfeed.tech/tags/security.md>), [tag-9fe8963de219](<https://devfeed.tech/tags/tag-9fe8963de219.md>), [windows](<https://devfeed.tech/tags/windows.md>), [windows-11](<https://devfeed.tech/tags/windows-11.md>)

### AI overview

Microsoft released a cumulative update that fixes 206 vulnerabilities, including 39 rated critical. The article covers high-severity Windows network-stack issues and patches for vulnerabilities previously disclosed by the person known as Nightmare Eclipse.

### Source excerpt

На прошлой неделе компания Microsoft выпустила очередной кумулятивный набор патчей для своих продуктов. В соответствии с общей тенденцией на увеличение количества обнаруживаемых уязвимостей за единицу времени, данный релиз исправляет рекордные 206 уязвимостей, из них 39 имеют статус критических. Если делить заплатки по категориям, то 63 патча закрывают уязвимости, ведущие к повышению привилегий, 56 багов обеспечивают выполнение произвольного кода, еще 30 могут приводить к утечке информации. Наиболее опасная уязвимость имеет идентификатор CVE-2026-45657, близкий к максимальному рейтинг опасности 9,8 балла по шкале CVSS. Это ошибка в ядре Windows при обработке сетевых пакетов данных, результатом эксплуатации которой может быть удаленное выполнение произвольного кода, затрагивает она Windows 11, а также Windows Server 2022 и 2025. Такого же высокого рейтинга удостоились еще две проблемы -- CVE-2026-47291 и CVE-2026-44815, они также относятся к сетевому стеку в Windows, соответственно затрагивая драйвер HTTP.sys и встроенный клиент DHCP. Кроме того, была закрыта уязвимость, позволяющая обойти BitLocker, ранее раскрытая анонимом, известным как Nightmare Eclipse. Об этом многомесячном противостоянии стоит поговорить подробнее. Читать далее

## Chainguard Now Available on Microsoft Azure Marketplace; Scan Chainguard Container Images with Microsoft Defender for Cloud

DevFeed: [Chainguard Now Available on Microsoft Azure Marketplace; Scan Chainguard Container Images with Microsoft Defender for Cloud](<https://devfeed.tech/articles/chainguard-now-available-on-microsoft-azure-marketplace-scan-chainguard-container-images-with-microsoft-defender-for-cloud-12973.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-now-available-on-microsoft-azure-marketplace>)

Published: 2025-07-16T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [Azure](<https://devfeed.tech/topics/azure.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [container-security](<https://devfeed.tech/topics/container-security.md>), [vulnerability scanning](<https://devfeed.tech/topics/vulnerability-scanning.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [azure](<https://devfeed.tech/tags/azure.md>), [azure-marketplace](<https://devfeed.tech/tags/azure-marketplace.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [container-security](<https://devfeed.tech/tags/container-security.md>), [defender](<https://devfeed.tech/tags/defender.md>), [microsoft-defender](<https://devfeed.tech/tags/microsoft-defender.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-scanning](<https://devfeed.tech/tags/vulnerability-scanning.md>)

### AI overview

Chainguard Containers is now available through the Microsoft Azure Marketplace, enabling Azure customers to adopt it within existing procurement, billing, deployment, and CI/CD workflows. Microsoft Defender for Cloud can also scan Chainguard container images for vulnerabilities, improving visibility and security across container environments.

### Source excerpt

Chainguard is now listed on the Microsoft Azure Marketplace. In addition, Microsoft Defender for Cloud can now scan Chainguard container images.

## Proofpoint's TA410 Report Shows How Attack Details Can Inform Better Defenses

DevFeed: [Proofpoint's TA410 Report Shows How Attack Details Can Inform Better Defenses](<https://devfeed.tech/articles/threat-research-more-like-this-37056.md>)

Original publisher: [Read original article](<https://shostack.org/blog/threat-research-more-like-this/>)

Author: Adam

Published: 2020-06-14T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [proofpoint](<https://devfeed.tech/topics/proofpoint.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Actor](<https://devfeed.tech/topics/actor.md>), [Code](<https://devfeed.tech/topics/code.md>), [execution](<https://devfeed.tech/topics/execution.md>), [file](<https://devfeed.tech/topics/file.md>)

Tags: [actor](<https://devfeed.tech/tags/actor.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [code](<https://devfeed.tech/tags/code.md>), [commands](<https://devfeed.tech/tags/commands.md>), [defender](<https://devfeed.tech/tags/defender.md>), [delivery](<https://devfeed.tech/tags/delivery.md>), [execution](<https://devfeed.tech/tags/execution.md>), [file](<https://devfeed.tech/tags/file.md>), [malware](<https://devfeed.tech/tags/malware.md>), [proofpoint](<https://devfeed.tech/tags/proofpoint.md>), [report](<https://devfeed.tech/tags/report.md>), [research](<https://devfeed.tech/tags/research.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>)

### AI overview

The article praises Proofpoint's report on TA410 attacks against U.S. utilities for its factual analysis and detailed explanation of the attack chain. It argues that details such as malicious macros, file renaming, cmd use, certutil execution, and delivery infrastructure can help defenders design better protections.

### Source excerpt

I want to call out some impressive aspects of a report by Proofpoint.