Feed aggregator

Improving email security outcomes with real-world Microsoft Defender insights

Microsoft Malware Protection Center - Thu, 09/17/2026 - 12:00pm
Every benchmark tells a story. The most valuable ones tell us where to improve next.

For five consecutive quarters Microsoft has published email security benchmarking reports to provide greater transparency into real-world protection outcomes. The results have shown strong Microsoft Defender performance across pre-delivery and post-delivery scenarios, while revealing where threats and defenses continue to evolve.

This quarter’s benchmark examines how continuous measurement informs protection across prevention, detection, and adaptation, and how those insights are helping improve customer outcomes.

Read the latest Microsoft benchmarking data for email security Key takeaways
  • Defender again missed the fewest high-severity threats among the solutions evaluated, about 55% fewer than the next-closest secure email gateway (SEG) vendor.
  • Layered security adds the most value in promotional and bulk filtering and works; gains for spam and malicious email remain comparatively modest.
Benchmarking results for SEG vendors

In the latest quarterly SEG comparison from May 2026 through July 2026, Defender missed 221 high-severity threats per 1,000 protected users, 55.4% fewer than the next-closest SEG vendor. The benchmark measures missed threats instead of the total number of malicious emails that were caught and filtered, because catch totals can reflect differences in threat volume and exposure across vendor environments. By normalizing missed threats per 1,000 users we are able to provide a more consistent side-by-side comparison.

Figure 1: High-severity email threats missed by SEG vendors (May 2026 through July 2026), measured as threats missed per 1,000 users protected. Data source: Microsoft Defender.

If you’ve read our previous blogs, you’ll see that missed threats have increased across multiple reporting periods, including for Microsoft. This aligns with broader trends we’re seeing as AI makes it easier for cyberattackers to gather public information, tailor messages, and create more convincing impersonation attempts. It reinforces the need for protection that continuously adapts.

Benchmarking results for ICES vendors

Effective email detection combines pre-delivery filtering with post-delivery detection and remediation. This benchmark helps customers evaluate where each layer contributes measurable value.

Similarly to previous quarters, integrated cloud email security (ICES) solutions continue adding the most value in promotional and bulk filtering. We saw an improvement in ICES vendor malicious catch at 0.30% versus 0.13% in the last quarter and spam catch going up to 0.52% versus 0.28% compared to last quarter.

Figure 2: ICES vendor catch contribution (May 2026 through July 2026). Data source: Microsoft Defender.

Defender caught 92% of post-delivery malicious messages on average during the benchmark period, highlighting how the combination of pre-delivery and post-delivery remediation delivers strong results for customers.

At the same time it’s key to understand that Defender doesn’t treat post-delivery remediation as a point-in-time action after the email was first delivered to the inbox. Even after a message reaches the inbox, new threat intelligence can reveal risks that were not apparent at the time of delivery. Defender continuously reevaluates delivered messages and remediates threats as new indicators, campaign intelligence, and threat signals emerge.

Figure 3: Post‑delivery malicious catch by Microsoft Defender (May 2026 through July 2026), shown across vendors and overall average. Data source: Microsoft Defender. How our benchmarking is helping shape product innovation

The value of benchmarking is what happens after measurement. Insights from customer feedback, threat telemetry, and benchmarking have informed recent Microsoft Defender investments:

  • More control over promotional mail: Across multiple benchmarking periods, we observed that ICES solutions often delivered the greatest incremental benefit in filtering promotional and bulk email. The new Promotions folder in Outlook builds on these insights by helping users reduce inbox clutter while keeping legitimate marketing and bulk messages accessible.
  • Redesigned machine learning and AI model stack: By analyzing and incorporating natural language processing signals, including message topic, alongside other AI detection signals, Defender can improve detection accuracy. During a consecutive four-week period, Microsoft research observed a roughly two-thirds reduction in false negatives and a nearly one-fifth reduction in false positives for Defender customers.
  • Protection for people and AI: We built prompt injection protection to detect and isolate malicious AI instructions in email before delivery—helping protect not only people, but also Copilot, agents, and other AI systems that read and act on inbox content. This innovation demonstrates how we continue evolving our defenses to address the latest cyberattack techniques and stay ahead of emerging threats.
Looking ahead

Since July 2025, our goal has been to bring greater transparency to email security effectiveness. Today, we are using benchmarking to help customers understand how cyberthreats evolve, where defenses add value, and how protection improves over time.

Benchmarking is not simply about demonstrating effectiveness, it is about learning from real-world outcomes and translating those insights into stronger protection. As cyberattackers continue to innovate, we remain committed to sharing evidence, improving our technology, and helping customers stay ahead of emerging cyberthreats.

To explore the latest benchmarking data and learn more about how Defender and ICES partners work together, access the benchmarking site.

Read the latest Microsoft Defender benchmarking results Learn more

Learn more about Microsoft Defender.

To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.

The post Improving email security outcomes with real-world Microsoft Defender insights appeared first on Microsoft Security Blog.

Categories: Microsoft

OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

Security Week - Thu, 09/17/2026 - 11:45am

OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior.

The post OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training appeared first on SecurityWeek.

Categories: SecurityWeek

US Coast Guard and FBI board oil tanker to investigate cyber attack

Graham Cluely Security Blog - Thu, 09/17/2026 - 10:43am
An oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers. According to the US Coast Guard, the supertanker was boarded after indications that the network "may have been compromised by a foreign actor." Read more in my article on the Hot for Security blog.
Categories: Graham Cluely

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

Security Week - Thu, 09/17/2026 - 10:28am

The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.

The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek.

Categories: SecurityWeek

Revolut phishing texts appear days after data breach

Malware Bytes Security - Thu, 09/17/2026 - 10:07am

Only days after Revolut acknowledged that it disclosed sensitive customer records to an unauthorized party, affected customers are receiving phishing texts. However, we don’t know yet if the phishing texts are linked to the breach.

The company had accepted fraudulent information requests sent from an email address on a legitimate government agency domain.

Through this social engineering attack, rather than by gaining access to Revolut’s systems, the criminals obtained the following types of information about customers:

  • Identity and contact information such as dates of birth, postal addresses, email addresses, and phone numbers
  • Copies of IDs such as passports and driver’s licenses
  • Verification selfies
  • Account statements and transaction histories

Revolut has said only that a “limited” or “very limited” number of customers were affected, and that it contacted them directly.

One affected customer received a phishing text on Monday, September 14, two days after Revolut publicly acknowledged the data breach. The message appeared in the same conversation as other Revolut texts, making it look as though it had come from the bank.

Phishing text to a Revolut customer

According to VirusTotal, the phishing domain was first scanned that same day.

In a separate example, another customer said that opening the link took them to a web page that requested access to their device’s camera. If you tap Allow, the page reportedly imitates Revolut’s live-video “turn your head” identity check before prompting you to enter a password.

This makes the phishing page appear more authentic. It may also allow the scammers to collect a selfie or video that could be used for further social engineering, identity fraud, or to make subsequent scams more convincing.

A convincing fake liveness check followed by a password screen is a common way to lower suspicion and obtain the information attackers need to attempt a real login or account-recovery flow.

If the campaign is connected to the breach, the information obtained from Revolut, combined with login details entered by victims or their approval of a login request, could be enough to take over their accounts.

How to stay safe

We don’t yet know whether the phishing campaign is using data exposed in the breach or whether unrelated scammers are exploiting news of the incident to target Revolut customers more broadly.

Either way, treat unexpected messages about your account with caution:

  • Don’t follow links in unsolicited messages. If a message concerns your account, open the official Revolut app directly.
  • Check the actual domain in your browser’s address bar to see if it corresponds with what you expect.
  • Use an up-to-date, real-time anti-malware solution on your device, preferably with a web protection component.
  • Malwarebytes Scam Guard can help you determine whether a message is a scam and advise you on what to do next.

Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

Categories: Malware Bytes

Elliptic Curve Rank Leaderboard

Hacker News - Thu, 09/17/2026 - 9:58am

Article URL: https://elliptic-rank.icarm.cloud/

Comments URL: https://news.ycombinator.com/item?id=49740855

Points: 1

# Comments: 0

Categories: Hacker News

Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

Security Week - Thu, 09/17/2026 - 9:57am

Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months.

The post Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom appeared first on SecurityWeek.

Categories: SecurityWeek

Ask HN: How about small technological solutions to bring oil prices back down?

Hacker News - Thu, 09/17/2026 - 9:57am

The prices on diesel are approaching ludicrous. In my mind, this should be an opportunity for a new technological solution to be implemented.

AFAICT, one significant part of the problem is something like:

Huge hulking expensive iron delivery vessels chugging through the water get blown up by inexpensive distant ordinance delivery.

Thus, a general solution could be something like:

Transition to small, cheap and highly numerous delivery vessels to nullify the effectiveness of distant ordinance delivery.

My layperson conceptual solution:

Create synthetic (e.g., plastic, PVC, etc.) eel-shaped self-navigating "vessels" that provide delivery in very high volume (millions of such "vessels") through dangerous waters to be recovered in safe waters.

These could be manufactured into large rolls, à la inflatable packing, and filled using mechanical power (either any simple motor powered by whatever or even human-powered via crank handle).

Drive can be provided by whatever works: time the release of the vessels to go out with a tide current; small sails; solar-powered propellers, etc. Speed does not matter as the quantity can be so high that once the vessels are being recovered the volume being delivered will be massive. (Conceptually similar to the old saw about "never underestimate the bandwidth of a 747 full of tape.")

I really only provide the above to hopefully inspire people who have the talent and means to create something yet better than what we currently have so that we do not arrive at a very real problem of products such as diesel fuel being not only high in price, but largely unavailable, as we may currently be on course to experience.

Comments URL: https://news.ycombinator.com/item?id=49740835

Points: 1

# Comments: 1

Categories: Hacker News

I Don't Like LLMs

Hacker News - Thu, 09/17/2026 - 9:57am
Categories: Hacker News

Show HN: Dnswer – browser-based DNS change approval and multi-provider sync

Hacker News - Thu, 09/17/2026 - 9:56am

Imagine you have to manage DNS for domains spread across multiple DNS providers. You want to apply consistent DNS settings across your zones but the only way is applying the same change manually zone by zone (using multiple control panels). Tedious and a mistake is bound to happen. You want to delegate permissions to other teams but many times the only way is handing out access to everything. If something breaks you have no idea who did it and what exactly was changed.

The existing solution is IaC. Tools like OctoDNS or DNSControl can help you with some of the problems described above. But they require the whole team to feel at home with setting up pipelines, command line tools and git.

With dnswer I want to provide the same level of structure, but in a browser:

- staging / preview before publishing DNS changes (edit and publish are separate roles)

- reusable blocks of records with per-zone variables (not a one-off template: update once, bulk-upgrade every zone that uses it)

- granular access control from full access down to write access on just a single record

- multi-provider sync with drift detection and resolution

- provision new zones at your provider(s), not only importing existing ones

- nameserver verification after changes (verifies that the change is live)

- for providers without an API, a shareable change request with on-demand re-verification (viewable without a dnswer account)

- modern record types (HTTPS/SVCB) and DANE/TLSA for mail, with cert-drift monitoring

- a zone logbook showing what changed, who did it, and why

There are a few ways you can learn more about it:

- Learn: https://dnswer.net/show/ (walkthroughs; annotated screenshots explaining how to use key features)

- Try it: https://app.demo.dnswer.net/ (sandbox with mock providers, free; sign up and verify your email to get in)

- Pricing: https://dnswer.net/pricing

If you want to try it with your own zones and API access to your DNS provider(s): I'm looking for up to ten teams (ideally managing 20+ domains across multiple providers) willing to manage real zones using dnswer. Not a big beta: I want to watch how it actually gets used and adapt things quickly. Free for the first 3 months, and early users keep their price for 2 years even after it goes up for new customers. If you're interested, reach out by emailing joost@dnswer.net.

A few things worth knowing before you do. dnswer is not in your resolution path: your records stay at your provider and your nameservers keep answering. If dnswer is down, DNS keeps resolving and you can still change records directly in your provider's control panel, you just lose the workflow on top until it is back. You can leave whenever you like: every zone exports as a BIND file with your record descriptions preserved as comments, so your documentation comes with you. Your provider credentials are encrypted at rest.

I've built it to solve the DNS problems I ran into in the last 20 years. I'd like to learn about other people's DNS problems as well.

Tech stack: Django/DRF, PostgreSQL, NATS, Lit web components, deployed with Ansible.

Comments URL: https://news.ycombinator.com/item?id=49740831

Points: 1

# Comments: 0

Categories: Hacker News

Pages