惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Attack and Defense Labs
Attack and Defense Labs
T
The Blog of Author Tim Ferriss
V
Visual Studio Blog
GbyAI
GbyAI
B
Blog RSS Feed
H
Help Net Security
美团技术团队
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
The Cloudflare Blog
Security Latest
Security Latest
F
Fortinet All Blogs
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - Franky
P
Privacy & Cybersecurity Law Blog
J
Java Code Geeks
博客园 - 【当耐特】
Last Week in AI
Last Week in AI
Y
Y Combinator Blog
人人都是产品经理
人人都是产品经理
www.infosecurity-magazine.com
www.infosecurity-magazine.com
T
Threatpost
Schneier on Security
Schneier on Security
T
Tenable Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Latest news
Latest news
P
Proofpoint News Feed
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Know Your Adversary
Know Your Adversary
W
WeLiveSecurity
G
GRAHAM CLULEY
P
Palo Alto Networks Blog
The Hacker News
The Hacker News
Microsoft Security Blog
Microsoft Security Blog
罗磊的独立博客
Recent Commits to openclaw:main
Recent Commits to openclaw:main
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V2EX - 技术
V2EX - 技术
MongoDB | Blog
MongoDB | Blog
博客园_首页
D
Darknet – Hacking Tools, Hacker News & Cyber Security
T
Threat Research - Cisco Blogs
T
Tor Project blog
Google DeepMind News
Google DeepMind News
Blog — PlanetScale
Blog — PlanetScale
博客园 - 聂微东
Hacker News - Newest:
Hacker News - Newest: "LLM"
Google DeepMind News
Google DeepMind News
The GitHub Blog
The GitHub Blog
月光博客
月光博客

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security Elastic MCP Apps bring security and observability workflows into AI tools - Help Net Security Progress Software fixes sneaky WAF bypass vulnerability (CVE-2026-21876) - Help Net Security Tencent's QClaw AI agent app arrives on Windows and macOS - Help Net Security Phishing reclaims the top initial access spot, attackers experiment with AI tools - Help Net Security OneDrive updates focus on AI, access control, and compliance - Help Net Security PentAGI: Open-source autonomous AI penetration testing system - Help Net Security Apple Intelligence flaw kept stolen tokens reusable on another device - Help Net Security Shadow AI, deepfakes, and supply chain compromise are rewriting the financial sector threat playbook - Help Net Security Thunderbird 150 arrives with encrypted message search and OpenPGP improvements - Help Net Security VirtualBox 7.2.8 is out with Linux kernel 7.0 support and crash fixes - Help Net Security Ransomware negotiator admits role in attacks he was hired to resolve - Help Net Security Scattered Spider hacker pleads guilty to stealing $8 million in cryptocurrency Meta and PortSwigger drive offensive security further to find what others miss - Help Net Security EU pushes for stronger cloud sovereignty, awards €180 million to four providers - Help Net Security SmokedMeat: Open-source tool shows what attackers do inside CI/CD pipelines - Help Net Security How to spot a North Korean fake in a job interview - Help Net Security Product showcase: Syncthing for secure, private file synchronization - Help Net Security Week in review: Acrobat Reader flaw exploited, Claude Mythos offensive capabilities and limits Google wipes out 602 million scam ads with Gemini on duty Researcher drops two more Microsoft Defender zero-days, all three now exploited in the wild GitLab 18.11 brings agentic AI to security fixes, CI pipelines, and delivery analytics Liongard upgrades LiongardIQ with AI access, live asset data, and deeper discovery Mozilla challenges enterprise AI providers with Thunderbolt, open-source AI client under your control Codex can now operate between apps. Where are the boundaries? Android 17 Beta 4 arrives with post-quantum cryptography and new memory limits Apple AirTag tracking can be misled by replayed Bluetooth signals Social media bans might steer kids into riskier corners of the internet Workplace stress in 2026 is still worse than before the pandemic New infosec products of the week: April 17, 2026 - Help Net Security ImmuniWeb brings AI upgrades, post-quantum detection and more in Q1 2026 NIST admits defeat on NVD backlog, will enrich only highest-risk CVEs going forward Anthropic releases Claude Opus 4.7 with automated cybersecurity safeguards - Help Net Security Fortinet fixes critical FortiSandbox vulnerabilities (CVE-2026-39813, CVE-2026-39808) - Help Net Security Google Play is changing how Android apps access your contacts and location Tails 7.6.2 patches vulnerability that could expose saved files Cargo theft malware actor spent a month inside a decoy network before researchers pulled the plug OpenAI updates Agents SDK, adds sandbox for safer code execution Anthropic tests user trust with ID and selfie checks for Claude GitHub lays out copyright liability changes and upcoming DMCA review for developers EU cybersecurity standards are at risk if supplier ban passes Command integrity breaks in the LLM routing layer The fully free Linux OS Trisquel gets a major update with version 12.0 Ecne Week in review: Windows zero-day exploit leaked, Patch Tuesday forecast ClickFix campaign delivers Mac malware via fake Apple page Poisoned “Office 365” search results lead to stolen paychecks Gmail’s end-to-end encryption comes to mobile, no extra apps required To counter cookie theft, Chrome ships device-bound session credentials Product showcase: Session, a messenger without phone numbers or metadata Little Snitch for Linux shows what your apps are connecting to - Help Net Security Apiiro CLI turns AI coding assistants into full-stack security engineers - Help Net Security April 2026 Patch Tuesday forecast: Spring-cleaning of a preview - Help Net Security What vibe hunting gets right about AI threat hunting, and where it breaks down - Help Net Security Health insurance lead sites sell personal data within seconds of form submission - Help Net Security
The Exchange Online security controls organizations keep getting wrong
Mirko Zorz · 2026-04-29 · via Help Net Security

In this Help Net Security interview, Scott Schnoll, Microsoft MVP for Exchange, breaks down the Shared Responsibility Model, where Microsoft secures the cloud while organizations must protect their own data, identities, and configurations.

The discussion covers default settings worth changing tomorrow, including legacy protocols like SMTP AUTH that survive due to printer, scanner, and ERP dependencies. Schnoll highlights overlooked controls such as Conditional Access, PIM, and continuous monitoring, plus blind spots in audit logs around POP, IMAP, and client-side mailbox rules. He also weighs when third-party email gateways add value versus when they create duplicate spend for mid-sized teams.

Exchange Online security

When you walk into an organization for the first time and they tell you Exchange Online is “secure because it’s Microsoft’s problem now,” where does that conversation usually go in the next ten minutes?

This is a great first question because I’m having that conversation with a customer right now. I start by explaining what’s called the Shared Responsibility Model in Microsoft’s cloud. I always make sure that customers understand that attackers don’t attack Exchange Online per se; rather, they attack an Exchange Online tenant; they attack your identity, your configuration, and (for a lot of customers), your lack of monitoring, and your lack of user education.

As its name implies, in the Shared Responsibility Model, Microsoft and the organization each have responsibility for different aspects of the deployment. While Microsoft has a number of security and compliance controls, there are just as many that are made available to tenant admins for properly securing the tenant.

Of course in the cloud, Microsoft is providing datacenters, networking, servers, compute resources, identity and infrastructure, and some applications. Microsoft also provides a number of controls for the environment, such as physical and logical access controls, networking controls, monitoring, and more.
But for all Microsoft cloud deployments, the organization owns their data and identities. Thus, the organization is responsible for protecting the security of their data and identities, along with the cloud components they control through available configuration settings. So while Microsoft provides a variety security controls for Exchange Online, it remains the organization’s responsibility to manage access and to secure and protect their data, accounts, and endpoints.

Microsoft secures the cloud, and to help customers secure their Exchange Online tenant, Microsoft provides a number of controls for change management, anti-malware, antispam and protection against other malicious software, baseline threat protection, patch management, and data replication and redundancy, among other things.

Microsoft also provides admins with controls and tools for managing identity and access, certificates, email authentication, eDiscovery and search, and many security and compliance tools. And those provided controls don’t configure themselves. Instead, the organization configures them based on their business needs and risk tolerance. In fact, as I am going through this with a customer now, I can tell that there are more than 300 technical, operational, and documentation controls that can be implemented by customers based on their business needs. These controls span cloud settings, directory access, security, compliance, endpoint management, risk assessment, and more.

So, you’ve just moved your family and all your belongings to a new, rented house. The landlord provides you with doors, windows, a roof, etc. The landlord is interested in protecting the house, but responsibility for protecting the people, and property in the house is up to you. It’s your responsibility to harden the environment to meet your needs. You might decide you want better locks, cameras, an alarm system, etc. These are all things that you can do to improve security, and these things are not provided by the landlord, thereby making them your responsibility.

It’s the same principle in the cloud. It’s your data and your users. It’s up to you to protect them.

What’s the configuration default in Exchange Online that you wish Microsoft would change tomorrow, and why has it survived this long?

Oh, if only it were that easy. There’s a few things I’d like to see changed (or gone), including support for legacy protocols and authentication. For example, taking something like authenticated SMTP submissions aka SMTP AUTH. It’s used by POP3 and IMAP4 clients to submit messages, and by applications, servers, and devices that don’t use modern authentication methods.

The RFC that defines SMTP auth was created more than a decade ago, and today, all modern email clients that connect to Exchange Online (e.g., Outlook, Outlook Mobile, OWA, etc.) don’t use SMTP AUTH. For this reason, Microsoft strongly recommends disabling SMTP AUTH (either tenant-wide, or with some exceptions when needed).

Unfortunately, what keeps SMTP AUTH around is the lack of support for it by devices and applications used by customers. This includes things like printers and scanners, HVAC systems, ERP systems, legacy applications, and so forth. As long as customers continue to use clients that don’t support modern authentication (e.g., OAuth), it makes it a challenge for Microsoft to turn it off completely.

We all agree that disrupting messaging services is a non-starter (not to mention politically dangerous). In fact, for some customers, breaking mail flow is worse than leaving some legacy protocol enabled. The fact is that security best practices have moved and are moving faster than Microsoft’s willingness to break mail flows (or other things). So, it can take years to remove insecure legacy protocols from Exchange Online. And as we’ve seen in this case (and with other significant cloud deprecations), even when Microsoft sets a deadline that deadline is often extended based on telemetry they have that shows legacy authentication still in use, and of course, based on escalations from customers who ask for more time.

Walk me through the controls you consider non-negotiable that most mid-sized organizations still get wrong. Where is the gap between Microsoft’s documentation and what teams operationalize?

This is an interesting question but I’m not sure it applies just to mid-sized organizations. There are organizations of all sizes who overlook things, or things just fall through the cracks. Microsoft’s documentation is not perfect, but it is fairly comprehensive and I can’t think of any security or other controls that are not well documented (although even in those cases, some additional polishing could help).

Since there are literally hundreds of controls for customers to manage, it’s easy to miss or misconfigure a control, and it’s easy to assume that implementing a control provides more protection than it actually does. For example, I’ve had customers who have enabled MFA thinking that alone solves the authentication gaps. These same customers have left POP, IMAP, and legacy authentication enabled, basically rendering the protections provided by MFA useless. I’ve also had customers create really solid policies, but then they open gaps by allowing for “temporary exceptions” that often become permanent.

For me, identity and access controls like Conditional Access, PIM, JIT elevation, and multi-admin approval are non-negotiable. So are controls that provide auditing, encryption, external forwarding, and data protections. The Security Defaults in Microsoft 365 are good, but only as a starting point. There are many more controls that need to be implemented and monitored to properly protect a tenant. And once the controls have been properly configured and implemented, then continuous monitoring needs to take place. The lack of continuous monitoring is often an organization’s biggest operational failure and something that unfortunately, a lot of organizations lack. An organization can implement all available controls, but without regular reviews of identity, permissions, control effectiveness, and system activity, the controls themselves are not enough.

When an account is compromised, what artifacts do incident responders consistently miss in Exchange logs? Where are the blind spots in the unified audit log that you would warn people about?

I’ll say from the start that I’m a little reluctant to answer this because I don’t want to expose any auditing gaps that can be exploited by anyone. The reality is that mailbox audit logs may show that mailbox items were accessed, but they cannot always reliably prove exactly which messages were read or whether data was exfiltrated.

For sure there are nuances to using the information in the audit logs. Incident responders often miss client-side mailbox access artifacts, delegated access activity, and non-Exchange workloads that attackers abuse but do not fully appear in the audit log. To use your language, the audit log also has “blind spots” around IMAP/POP access, token replay, legacy protocol abuse, and gaps in mailbox rule creation visibility, all of which can allow an attacker to go completely unnoticed even when auditing is enabled.

One of the tactics used by attackers is creating client-side mailbox rules that silently forward emails to external addresses or auto-delete specific messages. Creation and usage of these rules may not be fully captured in the audit logs. Similarly, accessing a mailbox using a legacy protocol like POP and IMAP generates minimal or sometimes no auditing events. You’ll see authentication activity captured in the sign-in logs, but after that mailbox access, message and folder binding, and other activity simply won’t appear in the logs (in this case because the session is treated as a protocol synchronization instead of an interactive mailbox action). POP itself specifically bypasses item level security, and its especially problematic given that it can trigger both download and deletion of messages in a mailbox.

Several years ago, Microsoft did add auditing for MailItemsAccessed, which details what messages and folders were accessed and whether synchronization occurred but it doesn’t capture this data from legacy clients (POP, IMAP, and even older version of Outlook). So, if legacy clients are used as part of an attack, from a forensic standpoint you’ll likely be able to tell that the mailbox was accessed, but you won’t always be able to tell exactly what the attacker read.

To account for these gaps, responders typically have to look at multiple sources of data, including Entra ID sign-in logs, message trace, Defender for Cloud Apps, Conditional Access logs, mailbox audit data, and endpoint telemetry from managed devices because Exchange Online auditing might not tell the complete story.

What’s your view on the value of third-party email security gateways sitting in front of or alongside Exchange Online? Where does the math work, and where is it duplicate spend?

This is one of those questions where it’s difficult to provide a specific answer around costs and duplicate spending. The short answer is that third‑party email security gateways can add value for very specific needs, such as when an organization needs legacy routing, specialized compliance tools, or advanced threat‑layer diversity. But for many Exchange Online customers, using them does create duplicate spend, and it can also reduce detection accuracy, not to mention introduce operational complexity.

For most customers, the math works only when they have requirements that Microsoft’s native stack cannot meet. For example, if a customer needs to use specialized routing or encryption, or Centralized Mail Transport (or even legacy hybrid mail flow) then using a third-party gateway could be their best solution. But, if the organization needs only spam or message hygiene capabilities, or wants to detect things like business email compromise, internal threats, and OAuth abuse, then using the native capabilities in Exchange Online is better than relying on a third-party gateway.

Scott Schnoll is a speaker at Span Cyber Security Arena 2026 taking place in May. Help Net Security will be on-site, get in touch to book a meeting.