30 Followers
211 Following
291 Posts

Microsoft just announced official support to store device bound Passkeys for Entra ID in the Windows Hello container. No app, no external hardware key but built in support. Sadly no attestation while in preview.

https://mc.merill.net/message/MC1247893

#Passkey #EntraID

MC1247893 - Microsoft Entra passkeys on Windows now support phishing-resistant sign-in | Microsoft 365 Message Center Archive

Microsoft Entra passkeys on Windows enable phishing-resistant, passwordless sign-in using Windows Hello on Entra-protected resources, including unmanaged devices. Public preview starts mid-March 2026. Organizations must opt in and configure policies to enable this feature; no impact occurs without activation.

2026, the year of the AI-driven attacker that could do back flips, they said.

Meanwhile, there's a magic number that allows Auth Bypass against Ivanti EPM (CVE-2026-1603)

something about a pledge 🙄

My CSS might look a bit like this...

The Hitchhiker’s Guide was famously written by correspondents like Ford Prefect. It wasn’t an #AI that made shit up based on some random sub-ether drivel. As a result, it was useful.

God, #DouglasAdams would have fucking hated #ElonMusk.

Curiously enough, an edition of The Guide that fell through a time warp from a thousand years in the future defined the executive board of X as “a bunch of mindless jerks who were the first against the wall when the revolution came”.

Today at 15:00 CET #YellowHat will start. It's a free live streamed conference around Microsoft Security and we have amazing speakers and topics lined up for you.

Register now to reserve your free spot.

https://yellowhat.live

#XDR #EDR #Defender #Microsoft #Security

Yellowhat

Yellowhat is a cutting-edge cybersecurity event dedicated to Microsoft Security Technology, offering advanced deep-dive sessions (level 400+) for seasoned professionals. It brings together experts and innovators to explore the latest tools, techniques, and strategies in securing digital environments. At Yellowhat, you’ll gain actionable insights, connect with industry leaders, and elevate your cybersecurity expertise to new heights.

Yellowhat

Everything You Need to Know About Email Encryption in 2026

If you think about emails as if they're anything but the digital equivalent of a postcard--that is to say, they provide zero confidentiality--then someone lied to you and I'm sorry you had to find out from a furry blog that sometimes talks about applied cryptography. CMYKat At the end of 2025, at the 39th Chaos Communications Congress in Hamburg, Germany, a team of security researchers posted some devastating…

http://soatok.blog/2026/01/04/everything-you-need-to-know-about-email-encryption-in-2026/

Everything You Need to Know About Email Encryption in 2026 - Dhole Moments

If you think about emails as if they’re anything but the digital equivalent of a postcard–that is to say, postcards provide zero confidentiality–then someone lied to you and I&#82…

Dhole Moments

Sometimes I just get an idea and it won't go away

Edited to add, since this is now doing Numbers:

Fuck the Tories, fuck the Labour party, fuck the TERFs, free Palestine

I made a thing: https://chrisphan.com/posts/2025-11-19_pwn_checker.html

It's a #TUI app queries the #API for @troyhunt 's Pwned Passwords service.

I wrote it in #python using @willmcgugan 's wonderful #Textual package.

Available on @codeberg, under an MIT license: https://codeberg.org/christopherphan/pwn_checker