SecOps SignalMicrosoft Security Operations Intelligence
SecOps Signal

Microsoft Security Operations briefing

Source-backed Microsoft Sentinel, Defender, vulnerability and advisory changes for SOC review.

Last successful collection: 2 September 2026 at 6:01 pm IST - Next scheduled: 3 September 2026 at 12:01 am IST

Request coverage healthy25/25 source requests succeeded4 items analyzed0 published after classificationSource policy
Lead operational brief

Critical Langflow Vulnerability (CVE-2026-0768) Actively Exploited to Steal OpenAI and AWS Keys

Publication time
2 September 2026 at 6:01 pm IST
Priority
Critical
Product
Langflow open-source AI application framework
Source
Non-Microsoft reporting

Operational impact: Langflow patched two security flaws after active exploitation leading to credential theft related to major cloud services. These updates address remote code execution weaknesses allowing attackers unauthorized access to sensitive keys.

Read operational brief

Latest operational intelligence

18 source-backed updates in the active window
View feed
HighMicrosoft Defender portalMicrosoft primary sourceKey Updates on Microsoft Unified Security Operations and Microsoft Sentinel Transition

Impact: - New content types (analytics, automation rules, workbooks) generally available for cross-tenant distribution. - Microsoft Sentinel is now generally available in the Microsoft Defender portal; Azure portal support ends March 2027. - Microsoft Threat Intelligence alerts enhanced for Sentinel customers within the Defender portal. - Introduction of UEBA experiences in Defender portal for behavioral insights. - Incident workflows supported with tasks in Defender portal. - Unified RBAC viewing and multitenant content distribution profiles made generally available. - Ability to create/edit Sentinel workbooks directly in Defender portal. - Automatic onboarding and redirection for new Sentinel customers to the Defender portal starting July 2025.

HighMicrosoft SentinelMicrosoft primary sourceMicrosoft Sentinel August 2026 Update: Enhanced UEBA, SAP Integrations, and Automation Consistency

Impact: UEBA now includes Fortinet FortiGate behaviors and supports Check Point, Fortinet, Zscaler, AWS GuardDuty anomalies, with mappings to MITRE ATT&CK techniques. UEBA behaviors gain contextual anomaly insights. SAP agentless and BTP solutions have new versions with audit and detection improvements. Analytics alert Account Name is normalized to UPN prefix only, adding new UPN fields to the SecurityAlert table, impacting automation rules and Logic Apps data handling.

MediumMicrosoft Graph APIMicrosoft primary sourceMicrosoft Graph Permission and Resource Changes - Admin Consent Updates and Bicep Resource Additions

Impact: Changed admin consent requirements for several delegated permissions; added Bicep resource support for various Microsoft Graph resource types including user, application, servicePrincipal, federatedIdentityCredential, and group; deprecated SAS authentication for Azure Event Hubs in favor of RBAC.

MediumMicrosoft Secure ScoreMicrosoft primary sourceUpdates and Enhancements in Microsoft Secure Score (Aug 2023 - Feb 2024)

Impact: Between August 2023 and February 2024, Microsoft introduced new Secure Score improvement actions covering a broad set of Microsoft and third-party security controls. Notable changes include the addition of phishing-resistant MFA enforcement for administrators, custom banned password lists, limitations on administrative roles for certain APIs, expanded SharePoint and Microsoft Forms sharing restrictions, recommendations related to Active Directory Certificate Services, Defender for Cloud Apps multi-instance support, and integration of Secure Score with Microsoft 365 Lighthouse for MSPs. Additionally, Secure Score access is now managed via Microsoft Defender unified RBAC allowing finer permission granularity.

MediumMicrosoft Security Exposure ManagementMicrosoft primary sourceMicrosoft Security Exposure Management - Recent Feature Updates and Previews

Impact: August 2026 updates enable keyless authentication using managed identities instead of API keys for Foundry connections; cancel scan option added to Microsoft Defender portal. Azure DevOps connector preview for remote on-demand agentic scans introduced. July 2026 releases feature MAI-Augmented scan profiles with specialized cyber AI models for enhanced code vulnerability detection available via Defender portal and CLI. Microsoft Security Exposure Management supports operational technology (OT) data connectors for Armis, Dragos, and Forescout to integrate OT asset data. June 2026 included new critical asset and identity classification rules for executive-sponsored AI agents, widespread local admins, and multiple SaaS application classifications (such as Microsoft Entra ID, Azure, 365 services). An updated overview dashboard is also previewed to aggregate exposure risks into actionable views.

HighMicrosoft Defender for Endpoint (Linux)Microsoft primary sourceNew Microsoft Defender for Endpoint Features and Enhancements (June-September 2026)

Impact: Introduced preview and general availability features in Defender for Endpoint across Linux, macOS, Windows, and mobile platforms such as: WSL container protection, tamper protection audit mode on Linux, antivirus audit mode, offboarding API support for Linux, vulnerability assessment of Microsoft Store apps, enhanced AI agent runtime protection, local AI agent discovery expansion, enhanced deployment tools, and new risk scoring methodologies including internet exposure reduction recommendations.

HighMicrosoft Defender for Identity sensor (all editions)Microsoft primary sourceMicrosoft Defender for Identity Sensor v3.x GA and Key Security Updates

Impact: - GA release of Defender for Identity sensor v3.x with improved coverage and performance. - Transition of several alerts to unified Microsoft Defender alerting format. - Introduced identity-related security posture assessments like inactive service accounts and discoverable passwords. - Added near real-time Microsoft Entra ID risk level to Defender for Identity. - New Graph API preview for sensor actions and remediation. - Bug fixes and improved detection accuracy, including noise reduction. - Deprecation warning for sensor support on Windows Server 2008 R2 starting August 15, 2022.