❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Why federal cyber defense demands an offense-driven mindset

8 September 2026 at 14:30

Federal agencies are drowning in cybersecurity data. Every day, security operations centers absorb millions of logs, scanner alerts and inventory feeds. But raw, static data isn’t actionable intelligence. Ask a room of federal CISOs to name the three critical weaknesses an adversary could exploit today to compromise their missions, and you’ll likely be met with a mountain of compliance reports.

That disconnect reveals a critical velocity problem in government risk management.      Traditional vulnerability management treats every Common Vulnerabilities and Exposures (CVE) entry and high Common Vulnerability Scoring System (CVSS) score as an equal emergency, regardless of whether it’s actually exploitable. Security teams spend weeks chasing theoretical findings, while adversaries exploit overlooked attack paths in hours. CVSS scores are static abstractions: they cannot reveal whether a flaw is reachable today, chainable with other weaknesses or capable of causing immediate mission damage.

As AI collapses the window between vulnerability disclosure and exploit execution, CISA’s issuance of BOD 26-04 marks a long-overdue pivot. The directive codifies what frontline defenders already know: agencies cannot win 90-day patch races against adversaries moving at machine speed. Federal cyber defense must shift from reactive spreadsheet patching to real-time prioritization based on exploitability, active threats and mission risk.

Vulnerable does not mean exploitable

During 30 years in IT operations and military cyber environments, I lost count of how many times I had to tell an auditor: “That high-severity CVE is a false positive, the vulnerable module isn’t running, or we’ve mitigated it six different ways.”

That gap between vulnerable and exploitable is where federal security teams lose the clock. Vulnerability scanners produce thousand-page laundry lists. Teams work from the top down, spending finite engineering hours patching high-severity “purples.” They often exhaust their time and budget before reaching the medium- and low-severity findings.

Adversaries do not follow a 90-day patch cycle. Attackers rarely burn a valuable zero-day exploit when a misconfiguration, weak trust relationship or stolen credential provides a direct path to their objective. As my colleague Todd Beebe from Freeport LNG has noted, “Credentials are the everyday zero-day.” Attackers don’t hack in when they can simply log in.

Defenders spend months building fortresses around static “crown jewel” systems while adversaries maneuver around those controls by chaining low-severity weaknesses with compromised identities. CVEs are only part of the story: misconfigurations and the tactics, techniques and procedures that live between CVEs matter just as much. We’ve validated thousands of attack paths across thousands of organizations that led to critical impact without leveraging a single CVE, and the only way to understand those paths is through offense-driven defense. Closing a vulnerability ticket on schedule doesn’t mean you have stopped an attacker. Untested assumptions are what get organizations in the news.

The cyber version of the McNamara Fallacy

Federal leaders risk falling victim to a modern cyber version of the McNamara Fallacy. Named for Defense Secretary Robert McNamara’s reliance on quantifiable metrics during the Vietnam War, it describes managing by what is easiest to count (e.g., patches applied, tickets closed and average CVSS scores) while overlooking operational reality.

I learned this lesson firsthand while leading IT and cybersecurity operations for a specialized defense unit. Our team was compliant. We checked every DISA STIG box, passed every audit and maintained immaculate documentation. Then a red team assessed our environment. Across people, process and technology, our organization performed well, but the assessment still found things a threat actor could immediately take advantage of.

When I asked whether they could return in three months to verify our fixes, they laughed. “No way,” they said. “You don’t have the budget, and we don’t have the resources.”

That experience fundamentally shifted my mindset: it is much easier to be compliant than secure.

Human-led penetration testing remains valuable, but small-scoped, point-in-time assessments cannot match today’s threat velocity. A manual test conducted annually gives you 24 hours of confidence and 364 days of guesswork. In an AI-accelerated environment, the report may be stale before the ink dries.

Proving defenses work in real time

Across modern framework developments, from NIST SP 800-53 Rev. 5 and NIST CSF 2.0 to federal zero trust mandates, FedRAMP, and Continuous Threat Exposure Management (CTEM), the market is shifting from static attestation toward validation and verification:

  • Compliance asks if a control is present and documented.
  • Validation asks if that control stops realistic attacker behavior now.
  • Verification asks if remediation eliminated the attack path in production.

To outpace adversaries, agencies must augment human expertise with autonomous penetration testing capabilities. We know this works in high-assurance public-sector environments. Under the NSA’s Continuous Autonomous Penetration Testing (CAPT) program, autonomous testing has logged 223,833 hours of operations across 28,282 completed pentests, spanning more than 3.7 million endpoints across 822 Defense Industrial Base organizations.

More importantly, the program accelerated remediation, saving more than 340,000 labor hours and enabling lean security teams to verify and close 71% of critical findings within 30 days. That is the difference between an annual-audit mindset and real-time operational defense.

Three action steps for federal leaders

Federal leaders should take three steps to operate at the speed of the threat:

  1.   Define risk through exploitability and impact. Risk is the product of likelihood and impact. But legacy vulnerability management accepts theoretical guessing of likelihood and fails to account for the consequences of the exploitation. Remediation should prioritize validated attack paths posing immediate mission risk.
  1. Move to continuous verification. In the military, we said, “Trust but verify.” In modern cyber defense, it is simply “verify.” Agencies must safely and continuously test controls, architectures, and identity permissions in production from multiple perspectives, including outside-in, assumed-breach, identity-based, and cloud-native.
  2. Verify the fix, not the activity. A ticket should not close merely because someone deployed a patch or changed a configuration. It should close only after a targeted retest confirms the exploitable attack path is gone.

As Corey Brunkow, Horizon3’s Director of Federal Operations, puts it: “Compliance is the baseline, not the finish line. In the new era of AI-enabled attacks, government and supply chain partners cannot afford to mistake a documented security control for an effective one.” The only way to know whether defenses can withstand an adversary is to send an attacker at them. Federal leaders must turn the map around, view their networks through the eyes of the adversary and continuously validate their security posture before an opponent does.

Learn how Horizon3 can help organizations move from point-in-time compliance to continuous, autonomous penetration testing.

The post Why federal cyber defense demands an offense-driven mindset appeared first on CyberScoop.

What’s new in Microsoft Security: May 2026

21 May 2026 at 12:00

At Microsoft, security innovations are purpose-built to help every organization protect end-to-end with the speed and scale of AI. Our vision is simple: security should be ambient and autonomous, just like the AI it protects. As organizations accelerate AI adoption, security teams are navigating new blind spots created by the broad distribution of agents, data, and identities across different tools and platforms. Microsoft Security’s latest updates extend visibility, control, and protection across your expanding ecosystem, from third-party apps like Claude to your cloud environments and multi-cloud infrastructure. Together, these updates help your team secure what matters most—agents, data, and identities—without slowing your own innovation. Here’s what’s new:

Microsoft Purview visibility now extends to Anthropic’s Claude

Security and compliance teams can now detect and investigate Claude usage alongside other cloud applications in their broader AI ecosystem. The new Claude Compliance API for Microsoft Purview delivers centralized visibility and oversight for Claude Enterprise activity enabling Microsoft Purview to provide insights on Claude interactions and audit log signals. This integration will provide visibility across Claude Enterprise, extending the Microsoft Purview experience and helping your teams protect sensitive data across your AI estate.  

New data security posture management experience in Microsoft Purview

The new Microsoft Purview Data Security Posture Management (DSPM) experience is now generally available. This solution unifies and streamlines DSPM across scenarios, from discovery to protection, all the way to remediation, allowing teams to investigate risks and take actions on the same workflow. The new experience delivers goal-oriented flows, deeper remediation, expanded reporting, and third-party visibility. Your teams can efficiently discover sensitive data, assess risk, and take action at scale.

Microsoft Purview Data Security Investigations extends investigative depth with custom examinations

Microsoft Purview Data Security Investigations now includes optical character recognition (OCR) and custom examination capabilities to extend investigative depth. OCR extracts text from images, bringing previously inaccessible visual content into scope for AI-powered deep content analysis. In addition to existing examination types that identify credentials, risk, and personally identifiable data, and help inform mitigation, investigators can define their own analysis with custom examination, enabling more tailored and flexible investigations based on their unique needs. 

Now, Data Security Investigations can extract text from images, like the one above, adding visual content into scope for AI-powered investigations.

Microsoft Entra ID Account recovery securely restores account access

Microsoft Entra ID Account recovery is an advanced authentication recovery mechanism that enables users to regain access to their organizational accounts when they’ve lost access to all registered authentication methods. Unlike traditional password reset capabilities, Account recovery focuses on identity verification and trust re-establishment prior to replacement of authentication methods rather than simple credential recovery.

Windows 365 for Agents delivers a secure AI agent execution environment

Windows 365 for Agents, now expanding in public preview, and Microsoft Agent 365 work together to provide a consistent, secure environment to run and govern agents. Agent 365 determines the work an agent is authorized to do, using shared organizational policies and identity to govern agent behavior and access. Windows 365 for Agents defines where an agent executes the work, providing Cloud PCs that enable agents to operate their own desktops and applications within a fully managed and auditable environment. Read our blog for more details.

Stay In the Loop

Microsoft Security continually ships meaningful innovations across our portfolio and research-driven insights and reports for the security community. In the Loop posts are your reliable source of what’s new across Microsoft Security and what it means for your security strategy. Check back for the next drop and connect with us at Microsoft Build, June 2-3, 2026, in San Francisco, to hear directly from Microsoft Security experts and learn more about today’s releases.


To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

The post What’s new in Microsoft Security: May 2026 appeared first on Microsoft Security Blog.

What’s new in Microsoft Security: May 2026

21 May 2026 at 12:00

At Microsoft, security innovations are purpose-built to help every organization protect end-to-end with the speed and scale of AI. Our vision is simple: security should be ambient and autonomous, just like the AI it protects. As organizations accelerate AI adoption, security teams are navigating new blind spots created by the broad distribution of agents, data, and identities across different tools and platforms. Microsoft Security’s latest updates extend visibility, control, and protection across your expanding ecosystem, from third-party apps like Claude to your cloud environments and multi-cloud infrastructure. Together, these updates help your team secure what matters most—agents, data, and identities—without slowing your own innovation. Here’s what’s new:

Microsoft Purview visibility now extends to Anthropic’s Claude

Security and compliance teams can now detect and investigate Claude usage alongside other cloud applications in their broader AI ecosystem. The new Claude Compliance API for Microsoft Purview delivers centralized visibility and oversight for Claude Enterprise activity enabling Microsoft Purview to provide insights on Claude interactions and audit log signals. This integration will provide visibility across Claude Enterprise, extending the Microsoft Purview experience and helping your teams protect sensitive data across your AI estate.  

New data security posture management experience in Microsoft Purview

The new Microsoft Purview Data Security Posture Management (DSPM) experience is now generally available. This solution unifies and streamlines DSPM across scenarios, from discovery to protection, all the way to remediation, allowing teams to investigate risks and take actions on the same workflow. The new experience delivers goal-oriented flows, deeper remediation, expanded reporting, and third-party visibility. Your teams can efficiently discover sensitive data, assess risk, and take action at scale.

Microsoft Purview Data Security Investigations extends investigative depth with custom examinations

Microsoft Purview Data Security Investigations now includes optical character recognition (OCR) and custom examination capabilities to extend investigative depth. OCR extracts text from images, bringing previously inaccessible visual content into scope for AI-powered deep content analysis. In addition to existing examination types that identify credentials, risk, and personally identifiable data, and help inform mitigation, investigators can define their own analysis with custom examination, enabling more tailored and flexible investigations based on their unique needs. 

Now, Data Security Investigations can extract text from images, like the one above, adding visual content into scope for AI-powered investigations.

Microsoft Entra ID Account recovery securely restores account access

Microsoft Entra ID Account recovery is an advanced authentication recovery mechanism that enables users to regain access to their organizational accounts when they’ve lost access to all registered authentication methods. Unlike traditional password reset capabilities, Account recovery focuses on identity verification and trust re-establishment prior to replacement of authentication methods rather than simple credential recovery.

Windows 365 for Agents delivers a secure AI agent execution environment

Windows 365 for Agents, now expanding in public preview, and Microsoft Agent 365 work together to provide a consistent, secure environment to run and govern agents. Agent 365 determines the work an agent is authorized to do, using shared organizational policies and identity to govern agent behavior and access. Windows 365 for Agents defines where an agent executes the work, providing Cloud PCs that enable agents to operate their own desktops and applications within a fully managed and auditable environment. Read our blog for more details.

Stay In the Loop

Microsoft Security continually ships meaningful innovations across our portfolio and research-driven insights and reports for the security community. In the Loop posts are your reliable source of what’s new across Microsoft Security and what it means for your security strategy. Check back for the next drop and connect with us at Microsoft Build, June 2-3, 2026, in San Francisco, to hear directly from Microsoft Security experts and learn more about today’s releases.


To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

The post What’s new in Microsoft Security: May 2026 appeared first on Microsoft Security Blog.

❌
❌