Please turn JavaScript on
header-image

The Nine Lives Brief

Subscribe to Nine Lives, Zero Trust, and get security insights delivered to your inbox.

Here's what you'll get:

  • Zero Trust insights you can actually use

  • DevSecOps practices for building security into your pipeline

  • Threat intel worth knowing

  • Cloud security tips from the trenches

  • Secure coding and shift-left strategies

  • The occasional cat pun (we're paranoid about spam, not fun)

Whether you're building secure infrastructure, automating compliance, or navigating the multi-cloud maze, this newsletter has you covered.

Filter by topic to get precisely what you need. Unsubscribe anytime.

Stay curious. Stay secure. Land on your feet.

Message History

If you manage Azure infrastructure through CLI, PowerShell, Terraform, or any tool that hits the ARM control plane, MFA enforcement is coming for every write operation your user accounts make.

Starting October 1, 2025, Microsoft began gradually rolling out Phase 2 of mandatory MFA enforcement. Phase 1 (October 2024) locked down the portal. Phase 2 extends that to Azure...


Read full story

Containers are immutable until they aren’t. A compromised workload that downloads and executes a binary at runtime bypasses every image scan you ran at build time. Binary drift plus malware is the worst-case scenario for container security, and until now the detection story was mostly “find out later in logs.”

Microsoft changed that on February 20, 2026. Defender for C...


Read full story

February 2026 brought one of the meatier Sentinel drops in recent memory. Not a rebrand, not a portal shuffle. Real detection surface expansion. UEBA Essentials hit v3.0.5 with a refined workbook and 30 hunting queries (including multi-cloud detections shipped in earlier releases), the M365 Copilot data connector finally landed, nine connectors graduated to GA, and the co...


Read full story

Microsoft is shipping two Entra ID changes in March 2026 that will change how your users authenticate. Neither change requires administrator action to take effect, and that is precisely the risk. If you do not act before the deadlines, Microsoft applies its defaults, and the results may not align with your security posture.

Change 1: Passkey profiles a...


Read full story

The Ignite-through-early-2026 wave just delivered the most feature-dense Microsoft security drop in recent memory. We’re not talking incremental updates. This is a structural shift in how Defender XDR and Sentinel work.

What just shipped:

Four Security Copilot agents went live in Defender XDR (two GA, two in preview) that autonomo...

Read full story