DSE security knowledge hub

Security knowledge,
without the noise.

Page 6 of the DSE Security Knowledge Hub, with source-backed guidance, checklists, explainers, and playbooks.

DSE-authoredOfficial sourcesReviewed guidance
DSE post stream

Guidance and analysis from DSE

254 articles
DSE visual briefDSE engineering

Turn a DSE Update into an owned assessment, change, and verification record

A public update can start an investigation; it cannot prove local applicability or authorize a production change. Capture source and review context, identify affected assets, assess risk, approve and test the change, verify results, and retain evidence.

Published Reviewed 4 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefCyber defense

CVE-2026-70329 in Outlook: What the 8.8 RCE Means and How to Respond

Microsoft has fixed CVE-2026-70329, an Outlook integer-overflow vulnerability rated CVSS 8.8. Exploitation requires a user to open a malicious Office file. Review the exact affected editions, deploy the August 11 security release, and verify the installed build by servicing channel.

Published Reviewed 5 min readBy Gavin Stewart
Read the briefing
DSE visual briefIdentity & cloud

Microsoft Entra Retires Native SMS and Voice MFA in 2027—Prepare for Passkeys Now

Beginning September 1, 2026, Microsoft will start auto-enabling passkeys and registration nudges for SMS- and voice-enabled users in public-cloud Microsoft Entra ID tenants. On February 1, 2027, Microsoft-provided SMS and voice delivery ends; organizations must migrate affected users to a phishing-resistant method or configure a customer-managed telecom provider.

Published Reviewed 5 min readBy Gavin Stewart
Read the briefing
DSE visual briefContinuity & recovery
GuideImportantBusiness ContinuityIT

Place a failover-cluster witness outside the failure domain it must arbitrate

A quorum witness is a deciding vote, not a decorative cluster setting. Select cloud, disk, or file share from the topology; isolate its dependencies from the failures it must resolve; validate access from every node; and retest after cluster or site changes.

Published Reviewed 3 min readBy Gavin Stewart
Read the guide
DSE visual briefNetworks & infrastructure
ChecklistImportantITNetworks & Infrastructure

Govern Windows DNS scavenging as a deletion change, not routine cleanup

Windows DNS aging can identify stale dynamic records, and scavenging can delete them. Inventory timestamps and registration owners, align intervals with DHCP and client behavior, restrict scavenging servers, pilot one zone, and prove recovery before enabling automation.

Published Reviewed 3 min readBy Gavin Stewart
Read the checklist