Find notable cyber news and cases, enriched with sources, timelines, and signals.

Tenfold expands identity event auditing with Windows and Active Directory monitoring, plus upcoming Entra ID support

Security Tool/Service
First reported
Last updated
Happening score
H score 11
1 unique sources, 1 articles

Summary

Hide ▲

tenfold has expanded its event auditing capability with real-time identity telemetry for Windows and Active Directory, giving defenders faster visibility into suspicious identity activity. The platform also says Entra ID support and automated alerting are coming in upcoming releases, extending the security monitoring scope.

Related Happenings

Anthropic Claude misuse analysis of multi-agent reconnaissance, exploitation, and exfiltration

Technical Analysis
H score59 First: 11.09.2026 17:29 Last: 11.09.2026 17:29 Sources 1

About this happening: Anthropic says Claude AI was abused by multiple threat groups, including ShinyHunters, Midnight Blizzard, and GTG-10007, for credential harvesting, recon...

Microsoft Entra ID actively exploited deserialization RCE (CVE-2026-69836)

Vulnerability
H score49 First: 21.08.2026 09:06 Last: 21.08.2026 09:06 Sources 1

About this happening: Microsoft Entra ID is facing CVE-2026-69836, a CVSS 10.0 remote-code-execution flaw that was exploited in the wild. The bug affects Microsoft’s cloud identity an...

HollowGraph Windows malware uses Microsoft 365 calendars for covert C2

Malware Activity
H score15 First: 20.07.2026 15:30 Last: 20.07.2026 15:30 Sources 1

About this happening: HollowGraph is a Windows malware activity that abuses a compromised Microsoft 365 calendar and Microsoft Graph API as covert C2, hiding tasking in far-future *...

Microsoft Entra ID makes passkeys the default authentication method and retires SMS/voice MFA

Security Tool/Service
H score26 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: Microsoft Entra ID will make passkeys the default authentication method starting September 2026, reducing reliance on phishable second factors across enterprise accoun...

CISA urges Intune hardening for U.S. organizations

Public Sector Action
H score80 First: 19.03.2026 13:02 Last: 19.03.2026 13:02 Sources 1

About this happening: CISA urged U.S. organizations to harden Microsoft Intune and related endpoint management controls after the Stryker attack showed how those systems could be abused...

Timeline

  1. 29.09.2026 17:01 2 articles · 1h ago

    tenfold adds real-time identity event auditing for Windows and Active Directory

    Initial Disclosure

    tenfold added real-time identity event auditing that ingests Windows and Active Directory logs, enriches events with session and user context, and lets defenders search, save, and share queries for suspicious identity activity. The feature is included in all tenfold editions at no added cost, while Entra ID support and automated alerting are planned for upcoming releases.

    Show sources