TLDR IT 2026-04-08
Anthropic’s cyber play ⚔️, M365 targeted 🎯, AI ROI gets real 📊
Router hijacks hit Microsoft 365 logins (4 minute read)
Law enforcement and private-sector partners disrupted a campaign that hijacked DNS settings on compromised routers to steal Microsoft account credentials and OAuth tokens. It is important to patch edge devices, retire unsupported gear, and check DNS exposure on internet-facing infrastructure.
Microsoft Device Code Phishing Bypasses MFA Using Legitimate Login Flow (3 minute read)
A large-scale campaign is abusing Microsoft's device code authentication flow to trick users into granting access, allowing attackers to capture tokens and maintain persistent access without needing passwords. This attack targets the authorization layer, meaning MFA and even passwordless methods don't stop it once a user completes the flow on a legitimate login page.
Most AI infra bets still aren't paying off (3 minute read)
Enthusiasm around AI in infrastructure is still outrunning results. Even with broad executive pressure to deploy AI, the data suggests many projects are getting stuck before they produce durable operational value. The projects most likely to survive are the ones that reduce toil, shrink MTTR, improve ticket resolution, or cut infra spend in ways finance can actually verify.
AI pilots are meeting a much harsher bar (3 minute read)
Channel and enterprise buyers are increasingly rewarding vendors that turn AI into concrete operational outcomes, not just demos. AI in IT is still attracting spending, but projects that can't show clear business value are getting exposed faster.
Anthropic turns frontier AI into a cyber tool (4 minute read)
Anthropic launched Project Glasswing, giving a limited group of major organizations access to its unreleased Mythos Preview model for defensive cybersecurity. Anthropic says the model has already surfaced thousands of significant vulnerabilities, while partners include major cloud, platform, and security vendors like AWS, Microsoft, Google, Apple, CrowdStrike, and Palo Alto Networks.
Caylent buys Pronetx to push AI-first CX on AWS (3 minute read)
AWS partner Caylent acquired Amazon Connect specialist Pronetx to expand its AI-first services into customer experience, with a focus on designing, operating, and evolving CX systems on AWS. This is another sign that partners are trying to own the full stack: infra, managed ops, and customer-facing AI workflows, rather than selling point solutions.
Nutanix adds multi-tenant cloud capabilities (3 minute read)
Beyond a NetApp alliance, Nutanix also used .NEXT to roll out new multi-tenant cloud capabilities, Kubernetes-on-bare-metal support, and broader AI platform positioning aimed at customers reevaluating VMware. Vendors are clearly competing to become the landing zone for orgs rethinking virtualization, container platforms, and AI infrastructure at the same time.
How MassMutual and Mass General Brigham Turned AI Pilot Sprawl Into Production (5 minute read)
MassMutual and Mass General Brigham centralized AI governance, enforced clear success metrics for every use case, actively shut down low-value pilots, and built abstraction layers to avoid vendor lock-in. This resulted in AI programs being moved from scattered experimentation to a managed portfolio of production use cases tied to real business outcomes.
Curated news 🗞️ and trends 📈 in IT strategy 💻, information security 🔐, and cloud computing ☁️.
Join 587,000 readers for
one daily email