Welcome to my personal corner of the internet. Here I share technical deep-dives and pieces of my life story.
Fresh from the blog

Eon launched Microsoft 365 data protection this week. IDrive added Entra ID backup last month. And Microsoft itself quietly took native Entra ID backup and recovery from preview to general availabilit...

On October 1, Dell published security advisory DSA-2026-324 for Dell System Update, the CLI tool admins use to push BIOS, firmware, and driver packages to PowerEdge servers. The tool whose job is to a...

Three days ago I wrote about the NetScaler zero-days that landed on a Sunday, and the point was simple: the upgrade is step two, not step one. Look for signs of compromise first, then patch. This post...

On October 10, setting EwsEnabled to $true in Exchange Online stops meaning what it used to mean. From that date, per Microsoft 365 Message Center post MC1485116, the switch alone no longer grants any...

Starting mid-October 2026, Microsoft will enforce a strict Content Security Policy on browser-based Entra ID sign-ins. Only scripts served from trusted Microsoft CDN domains will be allowed to run on ...

On Thursday, October 1, Fortinet published PSIRT advisory FG-IR-26-175 for CVE-2026-104286, a critical FortiMail flaw the vendor confirmed was already being exploited in the wild. The numbers are the ...

On Saturday, September 26, some network administrators got strange advice from their vendors and national security teams: take your NetScaler appliances offline. No one would say why. The advisory did...

Last night at 20:30 UTC, Microsoft's own maintenance broke its own cloud. An infrastructure OS servicing activity โ the kind of background patching every ops team does โ took down or degraded ExpressR...

On September 25, Microsoft Security Research published a detailed incident report about Storm-3168 โ the actor it links to JADEPUFFER, the "agentic ransomware" crew Sysdig documented in July. The head...