Cyber Security News

Microsoft Threat Intelligence Briefing Agent Now Integrated With the Defender Portal

Microsoft unveiled significant enhancements to threat intelligence at Ignite 2025, bringing the Threat Intelligence Briefing Agent directly into the Defender portal.

This integration marks a pivotal shift in how security teams approach cyber defense, moving from reactive responses to proactive threat anticipation.

The Threat Intelligence Briefing Agent, initially launched in March 2025, is now fully integrated into the Microsoft Defender portal in Public Preview.

Enhanced Threat Analytics and Intelligence Access

This powerful tool delivers daily customized briefings that combine Microsoft’s global threat intelligence with organization-specific insights.

Saving analysts countless hours previously spent manually gathering information from multiple sources.

Security teams receive automated, up-to-date intelligence summaries within minutes, complete with risk assessments, clear recommendations, and direct links to vulnerable assets.

These briefings help analysts quickly prioritize actions

This streamlined approach enables organizations to identify and address exposures before they become incidents, fundamentally changing how defenders prioritize their actions.

Microsoft has expanded access to its comprehensive threat intelligence library through Threat Analytics, now available to both Defender XDR and Sentinel-only customers in Public Preview.

Previously exclusive content is now accessible at no additional cost, democratizing world-class threat intelligence across Microsoft’s security ecosystem. The upgraded Threat Analytics includes several critical enhancements.

Each threat report now features comprehensive Indicators of Compromise (IOCs), allowing customers to review relevant indicators and access detailed entity information directly within Defender.

MITRE ATT&CK framework mapping helps teams proactively identify and mitigate persistent attack techniques. At the same time, insights into targeted industries and the origins of threat actors enable better prioritization.

Link Cases to IOCs for Complete Threat Context

Reports are systematically organized and filterable by Actor, Tool, Technique, Vulnerability, Activity, or Core threat, making specific intelligence easier to locate.

Additional context includes related intelligence links and threat actor aliases, helping analysts understand how Microsoft’s findings align with broader industry developments.

A new feature allows security teams to link cases directly to relevant IOCs, ensuring investigations and response workflows remain connected.

This improvement enhances visibility and collaboration, enabling faster and more informed decisions during critical threat investigations.

These advancements represent Microsoft’s commitment to equipping organizations with powerful tools to anticipate and address emerging threats more effectively in an ever-evolving security landscape.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago