Microsoft to Ship Windows with NTLM Blocked by Default, Pressing Enterprises to Migrate to Kerberos (US)
Read Our Expert Analysis
Create an account or login for free to unlock our expert analysis and key takeaways for this development.
By continuing, you agree to receive marketing communications and our weekly newsletter. You can opt-out at any time.
Recommended for you
Mandiant Publishes Precomputed Tables That Slash NTLMv1 Crack Time to ~12 Hours
Cybersecurity firm Mandiant released precomputed hash tables that enable attackers to recover weak NTLMv1-derived credentials in roughly 12 hours. The release highlights persistent use of an obsolete protocol and is intended to spur organizations to disable Net-NTLMv1 and adopt modern authentication.

Microsoft releases MCP C# SDK 1.0 with enhanced auth discovery
Microsoft published MCP C# SDK 1.0 , implementing the 2025-11-25 MCP specification and adding improved authorization server discovery, icon metadata, and experimental durable tasks. The release arrives as hyperscalers and vendors—who already expose dozens of MCP servers and gateways—move MCP from experimentation toward supported production surfaces, amplifying the SDK's practical value for .NET teams.

Microsoft warns of 2026 Secure Boot certificate expiry that may affect older PCs
Microsoft is alerting users and IT teams that core Secure Boot certificates will expire in 2026, and systems without updated firmware or certificates may fail to validate modern signed operating systems. OEMs and Microsoft provide firmware updates and support routes, but machines built before recent model years may require manual BIOS updates or vendor assistance to avoid boot interruptions.

Microsoft pushes urgent Office patch for a newly exploited zero-day used in targeted intrusions
Microsoft released fixes for CVE-2026-21509 after detecting active exploitation that undermines Office protections; mitigations and patches cover major supported Office builds and CISA has flagged the flaw for immediate remediation. The vulnerability appears to be leveraged in focused operations requiring user interaction and complex exploit chains, elevating the priority for high-value targets to deploy updates quickly.

Microsoft Intune: CISA Orders Immediate Hardening After Stryker Breach
CISA directed organizations to tighten configurations for Microsoft Intune after a disruptive incident hit Stryker on March 11; the advisory elevates endpoint-management security to an immediate compliance and operational priority. Vendor telemetry points to harvested administrative credentials and management-plane misuse, while public claims of widescale destructive wiping and actor attribution remain contested.
Microsoft discloses Office defect that let Copilot access private emails
A flaw in Office allowed Microsoft’s Copilot assistant to read and summarize emails that had confidentiality labels applied, creating a multi-week exposure window beginning in January; Microsoft began a phased remediation in early February and administrators can follow progress via message center entry CW1226324. The disclosure arrived alongside other active Office vulnerabilities — notably CVE-2026-21509 and related CISA guidance — heightening the urgency for organizations to patch, audit AI-enabled endpoints and review access to built-in assistants.
Microsoft Azure outage halts VM deployments and identity tokens for over 10 hours
A misapplied storage policy in Microsoft-managed accounts prevented access to VM extension packages, crippling provisioning and developer pipelines; an attempted mitigation overloaded the managed identities platform and extended the outage. The incident exposed fragile control-plane dependencies and underlined the need for diversified resilience strategies for enterprise cloud operations.
Microsoft pricing reset forces higher 2026 EA renewal costs
Microsoft's collapse of volume discount tiers and scheduled SKU increases are driving renewed cost exposure for Enterprise Agreement renewals; organizations face tier resets of about 6% , 9% , and up to 12% with additional suite adjustments slated for July 1, 2026.