Tenfold expands identity event auditing with Windows and Active Directory monitoring, plus upcoming Entra ID support
Security Tool/Service
Summary
Hide ▲
Show ▼
tenfold has expanded its event auditing capability with real-time identity telemetry for Windows and Active Directory, giving defenders faster visibility into suspicious identity activity. The platform also says Entra ID support and automated alerting are coming in upcoming releases, extending the security monitoring scope.
Related Happenings
Anthropic Claude misuse analysis of multi-agent reconnaissance, exploitation, and exfiltration
Technical Analysis
H score59
First: 11.09.2026 17:29
Last: 11.09.2026 17:29
Sources 1
About this happening:
Anthropic says Claude AI was abused by multiple threat groups, including ShinyHunters, Midnight Blizzard, and GTG-10007, for credential harvesting, recon...
Anthropic Claude misuse analysis of multi-agent reconnaissance, exploitation, and exfiltration
Technical AnalysisAbout this happening: Anthropic says Claude AI was abused by multiple threat groups, including ShinyHunters, Midnight Blizzard, and GTG-10007, for credential harvesting, recon...
Microsoft Entra ID actively exploited deserialization RCE (CVE-2026-69836)
Vulnerability
H score49
First: 21.08.2026 09:06
Last: 21.08.2026 09:06
Sources 1
About this happening:
Microsoft Entra ID is facing CVE-2026-69836, a CVSS 10.0 remote-code-execution flaw that was exploited in the wild. The bug affects Microsoft’s cloud identity an...
Microsoft Entra ID actively exploited deserialization RCE (CVE-2026-69836)
VulnerabilityAbout this happening: Microsoft Entra ID is facing CVE-2026-69836, a CVSS 10.0 remote-code-execution flaw that was exploited in the wild. The bug affects Microsoft’s cloud identity an...
HollowGraph Windows malware uses Microsoft 365 calendars for covert C2
Malware Activity
H score15
First: 20.07.2026 15:30
Last: 20.07.2026 15:30
Sources 1
About this happening:
HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future *...
HollowGraph Windows malware uses Microsoft 365 calendars for covert C2
Malware ActivityAbout this happening: HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future *...
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/Service
H score26
First: 14.07.2026 15:49
Last: 14.07.2026 15:49
Sources 1
About this happening:
Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA
Security Tool/ServiceAbout this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...
CISA urges Intune hardening for U.S. organizations
Public Sector Action
H score80
First: 19.03.2026 13:02
Last: 19.03.2026 13:02
Sources 1
About this happening:
CISA urged U.S. organizations to harden Microsoft Intune and related endpoint management controls after the Stryker attack showed how those systems could be abused...
CISA urges Intune hardening for U.S. organizations
Public Sector ActionAbout this happening: CISA urged U.S. organizations to harden Microsoft Intune and related endpoint management controls after the Stryker attack showed how those systems could be abused...
Timeline
-
29.09.2026 17:01 2 articles · 1h ago
tenfold adds real-time identity event auditing for Windows and Active Directory
Initial Disclosuretenfold added real-time identity event auditing that ingests Windows and Active Directory logs, enriches events with session and user context, and lets defenders search, save, and share queries for suspicious identity activity. The feature is included in all tenfold editions at no added cost, while Entra ID support and automated alerting are planned for upcoming releases.
Show sources
- Catch threats before they escalate with real-time Identity Telemetry — www.bleepingcomputer.com — 29.09.2026 17:01
- Catch threats before they escalate with real-time Identity Telemetry — www.bleepingcomputer.com — 29.09.2026 17:01