A malware family called TWINLOOT routes its command-and-control through Microsoft's own cloud — SharePoint, Teams, and the Graph API — so the domain blocklists and web filters built to catch an intrusion never see it, and it leaves no trace in your Microsoft 365 sign-in logs. Here's what that means for a professional-services firm, and the one question worth putting to your IT team.
Read more: When Your Own Microsoft 365 Becomes the Attacker's Channel

Blog • August 11, 2026
N-able's 2026 State of the SOC Report, built on data from the Adlumin SOC platform, lands on one finding every firm running endpoint protection should stop and consider: 50% of the attacks observed in 2025 bypassed endpoint controls entirely.
If your security strategy starts and ends with antivirus or EDR, that number means half of last year's attacks would have been invisible to you.
Key Insight
Half of 2025's attacks bypassed endpoint controls entirely — they moved through the network, perimeter, and identity layers that endpoint tools don't watch. — N-able 2026 State of the SOC Report
Here's why. Endpoint tools watch the endpoint — malware execution, suspicious processes, credential theft from memory. They're good at it. But a large share of modern attacks never runs anything on an endpoint until the very end. Network reconnaissance, lateral movement between systems, firewall and VPN exploitation, offline password cracking, identity attacks in the cloud — none of it generates an endpoint alert. By the time something does, the attacker has usually been inside for hours.
The Adlumin data puts numbers on it. Across 2025, the network and perimeter layers caught 137,187 threats that endpoint-only monitoring would have missed. Many weren't minor — they were the opening stages of attacks that would have become full breaches without visibility at those layers.
The same report explains why response speed matters as much as visibility. When a VPN login from an unusual location, internal SMB scanning, and a PowerShell execution show up separately, each looks ambiguous on its own. Correlated across layers, they read as an active compromise.
We watched a version of this play out in one of our own managed environments last Thanksgiving. A client traveled out of state for the holiday, logged in to get some work done, and was immediately flagged for signing in outside their normal area. SentinelOne on the laptop saw nothing wrong — because nothing on the laptop was wrong. The signal only existed in the layers around it. Adlumin correlated the sign-in with what our managed SonicWall appliance was seeing, and the SOAR weighed the context: a company laptop, a clean authentication, the VPN's two-factor prompt answered correctly. No aggravating circumstances, so it stopped at notifying me. Other cases have gone the other way — clients who left the country without telling us were automatically isolated from the network, applications, and resources until we confirmed it was really them. Same detection either way; the response matched the risk.
This is what the Capstone Threat Intelligence Center tracks: daily analysis of active threats — credential campaigns, perimeter exploits, the techniques showing up most often in professional services — and what each one means for the firms we manage.
Brian Sammons has managed IT environments for Ohio professional service firms since 2002. Capstone Technologies Group provides managed security services including firewall management, endpoint protection, backup, and 24/7 threat monitoring for medical practices, law firms, and accounting firms across the Dayton, Columbus, Cincinnati, and Springfield markets.
Questions about what your current tools can and can't see? Schedule 15 minutes and I'll walk you through it.
Announcement • June 01, 2026
Brian here. We've started publishing daily threat intelligence analysis at the Capstone Threat Intelligence Center.
The Threat Intelligence Center tracks active threats targeting the types of environments we manage — credential theft campaigns against Microsoft 365, malware delivery methods, phishing techniques, vulnerability disclosures, and the attack patterns that show up most often in professional services firms.
We monitor threat feeds throughout the day, score articles by relevance and severity, and publish analysis with context on what each threat means for managed environments. When a credential theft campaign targets Office 365 users — like the Storm-2755 attack we tracked last week that manipulates search results to redirect employee paychecks — the analysis publishes the same day.
Articles post to the Threat Intelligence Center daily and distribute across our social channels. The highest-priority threats get featured on LinkedIn each morning.
Starting this week, I'm also publishing a weekly summary on the blog — the two or three threats from the prior week that matter most for Ohio professional service firms, with context on what we're seeing and what it means for your environment. The first one is up now: SonicWall's 2026 Report Confirms What We See Every Week.
Windows 10 support ends October 14, 2025—just two weeks away. Microsoft recently announced extended security updates offering free and affordable options for the first time. With over 400 million Windows 10 PCs still in use and millions unable to upgrade due to strict hardware requirements, understanding your options is critical. Here's everything you need to know to protect your business systems and make informed decisions before the deadline.
Read more: Windows 10 End of Life: Your Free Security Bridge Explained
AI-enhanced Business Email Compromise (BEC) attacks are bypassing traditional security measures, posing immediate threats to organizations. Swift action is essential to prevent financial and reputational damage.
Read more: AI-Driven BEC Attacks: A New Cybersecurity Challenge
Page 1 of 3