DSE security knowledge hub

Security knowledge,
without the noise.

Verified security briefings, practical guides, and operational playbooks for video, access, IT, identity, networks, and cybersecurity.

DSE-authoredOfficial sourcesReviewed guidance
DSE post stream

Recently reviewed guidance

204 articles
DSE visual briefCyber defense

CVE-2026-70329 in Outlook: What the 8.8 RCE Means and How to Respond

Microsoft has fixed CVE-2026-70329, an Outlook integer-overflow vulnerability rated CVSS 8.8. Exploitation requires a user to open a malicious Office file. Review the exact affected editions, deploy the August 11 security release, and verify the installed build by servicing channel.

Published Reviewed 5 min readBy Gavin Stewart
Read the briefing
DSE visual briefIdentity & cloud

Microsoft Entra Retires Native SMS and Voice MFA in 2027—Prepare for Passkeys Now

Beginning September 1, 2026, Microsoft will start auto-enabling passkeys and registration nudges for SMS- and voice-enabled users in public-cloud Microsoft Entra ID tenants. On February 1, 2027, Microsoft-provided SMS and voice delivery ends; organizations must migrate affected users to a phishing-resistant method or configure a customer-managed telecom provider.

Published Reviewed 5 min readBy Gavin Stewart
Read the briefing
DSE visual briefContinuity & recovery
GuideImportantBusiness ContinuityIT

Place a failover-cluster witness outside the failure domain it must arbitrate

A quorum witness is a deciding vote, not a decorative cluster setting. Select cloud, disk, or file share from the topology; isolate its dependencies from the failures it must resolve; validate access from every node; and retest after cluster or site changes.

Published Reviewed 3 min readBy Gavin Stewart
Read the guide
DSE visual briefNetworks & infrastructure
ChecklistImportantITNetworks & Infrastructure

Govern Windows DNS scavenging as a deletion change, not routine cleanup

Windows DNS aging can identify stale dynamic records, and scavenging can delete them. Inventory timestamps and registration owners, align intervals with DHCP and client behavior, restrict scavenging servers, pilot one zone, and prove recovery before enabling automation.

Published Reviewed 3 min readBy Gavin Stewart
Read the checklist
DSE visual briefManaged IT operations

Govern every sensitive information exchange through its full lifecycle

Information remains exposed before, during, and after an exchange—regardless of whether it moves through an API, portal, file transfer, email, shared database, or manual process. Put protection duties and exit conditions in an owned agreement.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook