Monday 7/27
Autopilot and the Intune Connector
Microsoft Autopilot is a cloud-based solution that is used to provision new Windows devices and provides an alternative to the older imaging technology. When coupled with Intune, Autopilot enables vendors to drop-ship new machines directly to end users.
https://www.gothamtg.com/blog/autopilot-and-the-intune-connector
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID (Microsoft)
Microsoft Entra ID is updating its authentication experience by making passkeys the default phishing-resistant authentication method, helping customers reduce reliance on phishable methods such as SMS and voice.
https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/
When AI Agents Send Email: Securing Protected Information Before It Leaves (Proofpoint)
When an AI agent sends email as part of a business process, it may handle protected information. If that message is sent through an unmanaged application relay, SaaS platform, or third-party sender without consistent security controls, organizations can lose visibility and control at the moment the message leaves the organization.
https://www.proofpoint.com/us/blog/threat-protection/when-ai-agents-send-email-securing-protected-information-it-leaves
Tuesday 7/28
Safeguard 12.7: Require VPN and AAA Infrastructure for Remote Device Access
https://www.gothamtg.com/blog/safeguard-127-require-vpn-and-aaa-for-remote-device-access
Beyond Deepfake Detection: Operationalizing Identity Assurance (HYPR)
The barrier to creating convincing synthetic identities has fallen dramatically. The challenge for defenders is no longer simply recognizing that deepfakes exist, it’s building identity systems that know how to respond when they do.
https://www.hypr.com/blog/beyond-deepfake-detection-operationalizing-identity-assurance
Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report (Check Point)
The top five brand names cover more than half of all brand phishing activity this quarter. That concentration is worth sitting with. Scammers aren’t spreading their efforts across thousands of brands. They’re focused on a small set of names that nearly everyone recognizes and uses daily, since that recognition is what makes the con work in the first place.
https://blog.checkpoint.com/research/which-brands-are-impersonated-most-inside-the-q2-2026-brand-phishing-report/
Wednesday 7/29
Beyond the Model: Harnessing Frontier AI for Stronger Cyber Defense (CrowdStrike)
By late June 2026, the number of published CVEs this year had already reached nearly two-thirds of the total reported during all of 2025. Defenders aren't simply managing more vulnerabilities; they're managing an expanding attack surface that is growing faster every year.
https://www.crowdstrike.com/en-us/blog/harnessing-frontier-ai-for-stronger-defense/
Thursday 7/30
Why Seeing a Problem Is No Longer Enough (ControlUp)
For years, IT teams were told that visibility was the goal. Monitor everything, alert on thresholds, and let humans handle the rest. That model is broken and your employees feel it every single day.
https://www.controlup.com/blog/why-seeing-an-it-problem-is-no-longer-enough/
CosmosEscape: Taking Over Every Database in Azure Cosmos DB (Wiz)
Wiz Research uncovered CosmosEscape, a critical vulnerability in Azure’s flagship database service, Azure Cosmos DB, via its Gremlin API. The vulnerability could have been exploited to compromise every database in the service, including Microsoft's own internal databases - potentially enabling a cross-service attack.
https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db
Friday 7/31
Why Industrial OEMs Need to Rethink the Endpoint (IGEL)
For Industrial OEMs, the endpoint has become an increasingly important part of that equation. Organizations that treat it as a strategic component of the overall architecture, not just another customer-managed device, will be better positioned to differentiate their solutions and build long-term customer confidence.
https://www.igel.com/blog/industrial-oem-endpoint/
How to operationalize Citrix SecurAccess with Chrome Enterprise at scale (Citrix)
Work has moved to the browser. Employees, contractors, partners, and third parties now access SaaS and private applications from managed and unmanaged devices. Sensitive information moves through everyday browser actions, including AI prompts, uploads, downloads, and copy and paste. This has made the browser a critical control point for modern work.
https://www.citrix.com/blogs/2026/07/29/how-to-operationalize-citrix-securaccess-with-chrome-enterprise-at-scale/