John Leyden
- Indexed articles, last 90 days
- 10
- Latest publication
- Sep 1, 2026
- Outlet visibility, for CSO Online
- Top 5M sites
- Earliest in this view
- Jul 9, 2026
Latest articles
Microsoft nudges enterprise security closer to its passwordless future. But ‘123456’ will survive. (opens the original)
Read excerpt
Today marks the beginning of the end of an era for enterprise Microsoft authentication. As of Sept. 1, passkeys are now the default authentication method for Entra ID, Microsoft’s cloud-based identity and access management (IAM) service. By Feb. 1, 2027, Microsoft-provided SMS and voice authentication will be a thing of the past. The move is seen as one aimed at pushing enterprises toward passwordless authentication — something security leaders are broadly on board with but often struggle to ful
5 key takeaways from Black Hat USA 2026 (opens the original)
Read excerpt
AI’s potential as a security tool and the danger of autonomous AI agents as a new attack surface were key themes of the presentations and product announcements at Black Hat and DEFCON in Las Vegas last week. Here are some key takeaways from this year’s hacker summer camp that CISOs should review while developing cybersecurity strategies. Microsoft’s David Weston delivered a keynote at Black Hat arguing that AI is making advanced vulnerability discovery and exploit development cheaper and faster,
Microsoft wants you to rethink your approach to cyber defense (opens the original)
Read excerpt
Cyber defenders need to shake off traditional best practices and switch from reactive patching to building inherently resilient systems in the face of AI-accelerated vulnerability discovery, according to a senior security manager at Microsoft. David Weston, group manager in the Windows team at Microsoft, told delegates at Black Hat USA that traditional approaches to vulnerability remediation fail to work in an era when AI tools are making vulnerability discovery and exploit development cheaper,
Evidence points to cybercriminals stepping up their AI game (opens the original)
Read excerpt
More evidence is emerging about how AI is becoming part of the day-to-day workflow for cybercriminals, from building and refining tools to managing infrastructure and accelerating vulnerability research. Drawing on recovered prompt logs, attack tooling, and threat actor conversations, research from Cisco Talos documents how AI is being used to develop malicious code, build fraud infrastructure, and accelerate vulnerability research and exploitation. The study, released during the Black Hat USA c
A Scattered Spider member was indicted. Microsoft’s GDID went to trial. (opens the original)
Read excerpt
A recently released criminal complaint against Peter Stokes, an alleged member of the Scattered Spider cybercrime group, reveals previously unpublicized details about Windows telemetry. Microsoft has never exactly had a reputation for being privacy-focused, however the complaint reveals the important part played by Microsoft’s Global Device Identifier (GDID), a persistent identifier tied to a Windows installation, in the case. GDID enabled investigators to correlate the suspect’s Windows install
Publishing over time
Last 90 days. Choose a month to open its work.
Recurring subjects
Named in the text we hold. One piece can cover several.
Audience
Top 5M sites
For CSO Online, the outlet · Measured Aug 1, 2026
Website popularity band, not a count of readers or article views.
About this data
Counts cover the work we have indexed. Tone needs enough text and a confident classification. Excerpts and episode notes are not full articles or transcripts.
Identity or attribution wrong? Suggest a correction.