Sr. Content Developer at Microsoft, working remotely in PA, TechBash conference organizer, former Microsoft MVP, Husband, Dad and Geek.
161035 stories
·
33 followers

Microsoft 2.5: EVP Pavan Davuluri wants to remake Windows for both human and agent users

1 Share
Pavan Davuluri says Windows will keep serving human users while adding agentic workloads. (Microsoft Photo)

GeekWire is profiling over the next few weeks some of the people and teams that are shaping the evolution of Microsoft in what we’re calling its “Microsoft 2.5” era.

Just Don’t Call It an ‘Agentic OS.’ Given Microsoft’s one-pointed AI focus these days, it’s not surprising that the Windows organization is on the agentic train.

But Executive Vice President of Windows + Devices Pavan Davuluri has learned the hard way not to call Windows an agentic OS. He did so back in November 2025, via a tweet and blog post, and the customer backlash was quick and biting.

But Davuluri has not done a complete U-turn because of the criticism. Instead, he has changed how he talks about where Windows is going — which is still in an agentic direction.

“The user of Windows going forward will continue to be users … but it’s also going to add these agentic workloads,” the nearly 26-year Microsoft veteran Davuluri told GeekWire in a recent interview.

During his time at Microsoft, he’s held a variety of roles, from intern to General Manager of Surface, to Corporate Vice President of Windows Silicon & Systems Integration. He was appointed Executive Vice President of Windows + Devices in March 2026, reporting directly to CEO Satya Nadella.

Windows needs to evolve to support agentic workloads through new platform capabilities that the team is building under the covers, Davuluri said. These low-level capabilities, or “primitives,” affect how Windows handles security, identity, governance, observability, and performance when it comes to building and running agents natively.

These coming changes likely will affect the Windows file system, security model, PowerShell, and other foundational components.

Microsoft already is working on Windows identity and manageability to make them better able to service agents. Windows can assign agents a local ID, or a cloud-provisioned identity backed by Entra.

And it also has an early preview of technology known as Microsoft Execution Containers, meant to help secure agents by running untrusted code in sandboxes or virtual machines. It’s these system-level areas where the team is focusing first in preparation for a human+agent future, Davuluri said, rather than the UX/UI level.

Going Back to Basics. Windows has had a lot of very different leaders over the years, with very different management styles and priorities.

For his part, Davuluri said he plans to run the Windows and Surface teams with four principles in mind: Maintaining customer obsession; treating Windows as a complete end-to-end system (“full stack”); focusing on complete user experiences and workflows rather than individual features; and building Windows openly and transparently, with clearer communication about plans and priorities.

On the heels of his promotion to EVP, Davuluri committed publicly to the much-needed goals of improving Windows quality and reliability. In a blog post, he outlined some of the requested changes that his team would be making to Windows, ranging from fixing the way the Insider test program works, to more granular improvements like allowing users to reposition the Windows task bar.

And since then, the team largely has been delivering to the surprise and delight of many long-time Windows users.

Davuluri has also been working to shift the conversation from which new features are coming to a specific build to what are the outcomes Microsoft wants to enable for specific groups of Windows users.

“There is no one single sort of ring for a billion-plus users on the platform,” Davuluri said. Windows users encompass people who use the product in a variety of different ways, so “we need to get clarity in our minds on the things that we do that lift all boats that raise the entire platform — and things that we have to go do that are specific and unique to each of our sets of users based on how they primarily or typically use the device.”

Full-Stack Thinking. Is there still a role for Microsoft as a PC maker in the coming agentic future? Not surprisingly, given his heavily hardware-focused background, Davuluri insisted there is.

When Microsoft debuted its first Surface devices in 2012, officials said the company needed to build its own hardware to create reference designs and innovative form-factor examples for other Windows PC makers.

These days, most Surfaces that ship arguably are not better, spec- or design-wise, than other PCs. But Microsoft still needs to keep a hand in hardware design to understand the full stack, Davuluri claimed.

Surface plays a key role in how Microsoft develops platform abstractions, incubates support for technologies like pen, facial-recognition, and neural-processing units that later spread across Windows, and optimizes for silicon-to-cloud, he said.

While the company’s attempt to create a distinct category of “Copilot+” AI PCs fizzled, Microsoft continues to try to find AI-centric reasons to convince customers to choose Windows devices. Davuluri and others have referred to the idea of “unmetered intelligence” to attempt to make the case for running AI models locally on PCs.

This fall, Microsoft (and other Windows PC makers) plan to roll out new PCs built on the Nvidia RTX Spark platform. The coming Surface Laptop Ultra, which will be optimized for RTX Spark, is aimed at creators, developers and AI builders, all of whom — Microsoft is hoping — will be fueling the growth of its next target user category: Agents.

Read the whole story
alvinashcraft
18 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

The Gemini app is now available for Windows

1 Share
We’re launching the Gemini app for Windows, the new desktop app built to work alongside your favorite tools and daily applications.
Read the whole story
alvinashcraft
19 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

Previews and Experiments in VS Code 1.137

1 Share
Microsoft's Sept. 9 release emphasizes scheduled agent work, spoken interaction and experimental GitHub and chat features.
Read the whole story
alvinashcraft
19 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

(Re)introducing Developer Story

1 Share
For the past few years, we’ve been looking at ways to bring a little more of the individual developer back to Stack.
Read the whole story
alvinashcraft
19 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

Protecting organizations from AI-assisted executive impersonation and invoice fraud

1 Share

Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive team members. While this technique is not new, the adoption of AI has enabled threat actors to improve their campaign templates and construct emails tailored to their recipients. Additionally, threat actors are incorporating multiple techniques within the same email to improve the overall narrative further.

In this blog, we will discuss a recent campaign observed using third-party email delivery infrastructure to send out over a million financial fraud scam emails that displayed multiple indicators consistent with the use of generative AI during email template creation. The threat actor impersonated CEOs of multiple target companies, attempting to convince accounts payable departments of the same companies to process an Automated Clearing House (ACH) payment of nearly $50,000. To add legitimacy, the actor included a forwarded email thread (and a fabricated invoice) between the impersonated CEO and ServiceNow (which was also being impersonated).

Attack chain overview

The campaign follows steps before and during the execution of the campaign: threat actors register impersonation domains, send executive-themed payment requests through trusted infrastructure, embed fabricated invoices and supporting conversations, and attempt to convince finance personnel to initiate ACH transfers.

Figure 1: Attack chain showing domain registration, executive impersonation, invoice fraud delivery, ACH payment execution, and financial theft.

Email Delivery

Between August 3 and 5, Microsoft detected a campaign consisting of more than a million emails targeting enterprise users. The attacker used multiple third-party email service accounts to send out the emails. A huge majority of these emails were sent to users in the United States (87.7% of the total campaign).

Figure 2. Campaign timeline.
Figure 3. Industry distribution of targeted enterprises of this campaign with ‘IT services & business advisory’ along with ‘Consumer goods’ and others.

Unlike traditional invoice scams that rely on a single social engineering lure, this campaign layered executive impersonation, vendor branding, fabricated invoices, and supporting email conversations into a unified narrative intended to reduce recipient skepticism.

The threat actor impersonated executive team members (such as a CEO, CFO, President) of multiple targeted companies, attempting to convince accounts payable departments of the same companies to process an ACH payment of nearly $50,000. More specifically, the CEOs were impersonated in multiple places in the email such as in the sender display name, reply-to display name, and in the email signature. Email bodies contained a simple and direct “approval” of the “invoice below” as well as urged users to request a PDF version if they need it. Additionally, as mentioned earlier, the email signature contained certain details about the spoofed CEO such as name and email address.

Figure 4. Spoofed message from executive team member.

Important note: Throughout this campaign, threat actors impersonated legitimate organizations using attacker-controlled infrastructure, fabricated communications, and lookalike domains. Microsoft found no evidence that the legitimate organizations referenced in the lures, including ServiceNow, were compromised or involved in the activity. Rather, the campaign relied on fraudulent domains and content designed to mimic trusted brands and individuals.

The threat actor did not stop there. To add further legitimacy, directly below the CEO signature, the actor included “forwarded” content , specifically a professional looking but fabricated “ServiceNow Platform — Annual Subscription” invoice. The extremely detailed invoice contains various ServiceNow branding and logos. It has basic invoice details such as invoice number, issue and due dates, currency, amount due, payment method, and itemized line items. The payment method instructed is a bank transfer to accounts controlled by the threat actor. Microsoft observed the use of multiple financial institutions across samples, indicating that payment destinations may vary between targets. Certain parts of the invoice are personalized to the recipient. Specifically, the “BILLED TO” section has the recipient company name and executive name.

The invoice shown below is a threat actor-created impersonation and was not issued by ServiceNow.

Figure 5. Spoofed ServiceNow invoice.

Finally, directly below the fake invoice, two more “forwarded” emails are included which are essentially a short conversation between the two spoofed executives (the targeted company executive, and ServiceNow President). The two executives are seen discussing the ServiceNow purchase, implementation and handling of the invoice.

Figure 6. “Forwarded” replies thread within the email lacking usual headers.

From a defender point of view there are several indicators within the email indicating that the email and the “forwarded” thread are not genuine.

  • “From” headers from the spoofed thread lack any data headers like actual forwarded emails.
  • Suspicious language used in the spoofed thread such as “no need to copy me”.
  • Suspicious language in headers i.e display name not matching sender address, subjects using financial lure keywords like ‘due bill’, ‘ACH Parment’ etc.
  • Despite the sophistication of the generated content, several inconsistencies remained visible to defenders
  • In real email threads, the previous threads are normally tabbed or otherwise visually grouped, while the previous threads in this example were left aligned.
  • An additional inconsistency was observed where the targeted company’s CEO requested the recipient to send the invoice directly to victims and not CC the sender. However, in the most recent thread, the CEO stated that the invoice is approved and the invoice is sent from his address.

Domain registration

Before initiating the campaign, the threat actor registered several domains. A ‘ServiceNow’ lookalike domain service-nowinc[.]com was registered on July 31, shortly before the campaign activity was observed. This domain was used for the spoofed email address of ServiceNow President. It was also used in several places in the fabricated invoice such as in the contact email in case of any questions. The actor also registered another domain on the same day. The domain domainlify[.]net was used in the Reply-To email.

Figure 7. Account information linked with email of impersonated domain.

Generative AI usage

Microsoft observed several indicators consistent with AI-assisted template development. These included extensive HTML comments, structured section labeling, and highly uniform template construction. While these indicators suggest generative AI involvement, they do not independently establish the extent to which AI generated campaign content.

Examples:

Figure 8. Code snippet showing a verbose HTML comment describing a section (a characteristic commonly observed in AI-generated code).
Figure 9. Another code snippet showing extensive comments on HTML style elements and sections.

Additionally, the use of ‘em dash’ (“—”) and banner ‘===========’ have also become other indicators associated with AI usage.

Figure 10. Another code example indicating AI usage. This example shows a verbose capitalized section header and yet more style elements excessively commented.

One possible indication of template-based generation is that invoice identifiers and narrative structure remained largely consistent across samples while organization-specific details changed between targets.

Mitigation and protection guidance

Microsoft provides layered protection against this type of executive-impersonation and invoice-fraud campaign. Properly configured email authentication, spoof protection, mail-flow connectors, and Microsoft Defender for Office 365 help identify and block suspicious messages before delivery; messages later determined to be malicious can be quarantined or removed through post-delivery remediation, including Zero-hour Auto Purge. Security teams can then use Microsoft Defender XDR and Security Copilot to investigate related alerts, affected users, and campaign indicators, coordinate response, and take remediation actions.

Together, these capabilities help reduce the likelihood that fraudulent payment requests reach finance personnel and support faster containment if a message is delivered.

To defend against social engineering campaigns involving executive impersonation, invoice fraud, and potentially AI-assisted content development, Microsoft recommends the following mitigations:

Configure automatic attack disruption in Microsoft Defender XDR. Automatic attack disruption is designed to contain attacks in progress, limit the impact on an organization’s assets, and provide more time for security teams to remediate the attack fully.

Enable Zero-hour auto purge (ZAP) in Office 365 to quarantine sent mail in response to newly acquired threat intelligence and retroactively neutralize malicious phishing, spam, or malware messages that have already been delivered to mailboxes.

Invest in advanced anti-phishing solutions that monitor and scan incoming emails and visited websites. For example, organizations can leverage web browsers like Microsoft Edge that automatically identify and block malicious websites, including those used in this phishing campaign, and solutions that detect and block malicious emails, links, and files.

These links provide information on how to properly configure mail flow with connectors:

These links provide information on configuring SPF, DKIM, and DMARC:

Microsoft Defender detections

Microsoft Defender customers can refer to the list of applicable detections below. Microsoft Defender coordinates detection, prevention, investigation, and response across endpoints, identities, email, and apps to provide integrated protection against attacks like the threat discussed in this blog.

Tactic Observed activity Microsoft Defender coverage
Financial TheftScam emailsMicrosoft Defender for Office 365
– Invoice scams delivered detected as Spam and malicious categories.
– Email messages marked malicious removed after delivery and spam moved to quarantine
– Email messages removed after delivery
– Messages retroactively removed through Zero-hour Auto Purge (ZAP).

Microsoft Security Copilot

Security Copilot customers can use the standalone experience to create their own prompts or run the following prebuilt promptbooks to automate incident response or investigation tasks related to this threat:

  • Incident investigation
  • Microsoft User analysis
  • Threat actor profile
  • Threat Intelligence 360 report based on MDTI article
  • Vulnerability impact assessment

Note that some promptbooks require access to plugins for Microsoft products such as Microsoft Defender XDR or Microsoft Sentinel.

Threat intelligence reports

Microsoft Defender XDR customers can use Threat Analytics reports in the Defender portal (requires license for at least one Defender XDR product) to get the most up-to-date information about the malicious activity and techniques discussed in this blog. These reports provide the intelligence, protection information, and recommended actions to prevent, mitigate, or respond to associated threats found in customer environments.

MITRE ATT&CK Techniques observed

This threat has exhibited use of the following attack techniques. For standard industry documentation about these techniques, refer to the MITRE ATT&CK framework.

Reconnaissance

T1591 – Gather Victim Organization Information
Threat actors collect publicly available information about target organizations, executives, finance personnel, vendors, and business relationships to build convincing invoice-fraud narratives.

T1598 – Phishing for Information
Information gathered from victims and public sources is used to craft highly targeted business email compromise (BEC) lures.

Resource Development

T1583.001 – Acquire Infrastructure: Domains
Threat actors register domains that impersonate trusted organizations, vendors, or business partners.

T1585.002 – Establish Accounts: Email Accounts
Attacker-controlled email accounts are created to support impersonation and fraudulent communications.

T1583 – Acquire Infrastructure
Third-party email delivery infrastructure and supporting services are leveraged to distribute campaigns.

Initial Access

T1566 – Phishing
Targeted phishing emails are delivered to finance personnel using executive and vendor impersonation themes.

T1566.001 – Spearphishing Attachment
Fraudulent invoices or supporting documents are attached to phishing emails.

T1566.003 – Spearphishing via Service
Third-party email services are used to distribute phishing messages and improve legitimacy.

Defense evasion

T1036 – Masquerading
Attackers disguise emails, domains, invoices, and business correspondence as legitimate communications.

T1656 – Impersonation
Executives, vendors, and trusted business entities are impersonated to establish credibility and influence payment decisions.

Impact

T1657 – Financial Theft
Victims are deceived into transferring funds to attacker-controlled financial accounts through fraudulent invoice payment requests.

Indicators of compromise (IOC)

IndicatorTypeDescription
service-nowinc[.]com Domain Domain impersonating ServiceNow
gomez@service-nowinc[.]comEmail address Email address associated with bank account
notifications@uinsure[.]co[.]uk info@tivityhealth[.]com no-reply@lumalisboa[.]com noreply@mctci[.]com info@nuf[.]co[.]jp info@lohnsteuerhilfe-aktuell-verein[.]de info@tovimbatista[.]pt contact@eemusicclass[.]co[.]uk info@lifeones[.]comEmail addressSender email address used to send out emails
domainlify[.]netDomainNewly registered domain used in Reply-to address

Learn More

For the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.

To get notified about new publications and to join discussions on social media, follow us on LinkedIn, X (formerly Twitter), and Bluesky.

To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat Intelligence podcast.

Review our documentation to learn more about our real-time protection capabilities and see how to enable them within your organization.  

The post Protecting organizations from AI-assisted executive impersonation and invoice fraud appeared first on Microsoft Security Blog.

Read the whole story
alvinashcraft
20 minutes ago
reply
Pennsylvania, USA
Share this story
Delete

When Content Is Free, Trust Is the Product

1 Share

There is more technical content available today than any human being could read in a thousand lifetimes. Every topic has a dozen YouTube videos, three Substack posts, a GitHub repo, and a Reddit thread, most created in the last six months and, in many cases, technically accurate. And yet most of the professionals I talk to say they don’t know what to trust. They can’t tell what’s important to read first, or which of 10 plausible answers is the one that holds up. That was true before AI, and AI has made it more true.

For most of the history of technical publishing, editing and verification were the same process, and that process was slow and expensive. Getting a book out took years. We found an author, vetted them, had them work with an editor, and checked their claims with technical reviewers. A lot of that time went into separating what was correct and useful from what was confusing or only sounded right. It was laborious, but it meant a reader could depend on the claims on the page. The credibility of the book, and of the publisher behind it, mattered as much as the information itself.

When the cost of production drops to zero, that credibility becomes worth more, not less. Content is easier to make than ever, but without a transparent process behind it, readers have no idea where the knowledge came from or whether it holds up. As Jasmine Sun puts it in “The Independent Writer’s Advantage in the Age of AI,” “Trust is not about information and its quality alone. It’s about the messenger. It’s about who says it and their track record and what they’ve told me before.” A practitioner has confidence in a source because someone she respects has put their reputation on the line for it. They believe what the author is saying because the publisher has a history of being right and of correcting itself when it isn’t, and because the work is attributed and verifiable.

The corpus matters, but it’s the assurances around it that are hard to replicate, and that comes not just from the people who produce the content but from the people whose judgment vouches for it. Sometimes a creator brings their own credibility with them. Other times, the publisher spots someone unknown and lends them its own. The art critic Dave Hickey said this about gallery owners in Air Guitar: They gain status from the famous artists they represent and share it with emerging talent who have something to offer but who haven’t had the chance to earn a reputation. This is what O’Reilly has done for nearly half a century, build a network of experts who vouch for what’s worth knowing.

Expertise is alive, and it compounds

Expertise is a living thing, continuously expanding. Content starts to decay the moment it’s published, because frameworks evolve, libraries deprecate, and yesterday’s best practice becomes today’s security incident. Keeping expertise alive requires a pipeline of people who stay current and an editorial layer that notices when something has gone stale, and either retires it or calls for a fix.

That pipeline isn’t something you switch on when an author has a book to ship. At O’Reilly, we’ve always prided ourselves on living at the bleeding edge, finding what Tim O’Reilly calls “the alpha geeks” and spreading what they know to everyone else. Content sits at the center of our platform, but we think about it in pace layers. Some advice is timeless, some moves but has a long shelf life (some of our books are still in print after nearly 50 years!), and some changes weekly. We work with experts at each pace layer, capturing what lasts while doing our best to keep pace with an industry that seems to have changed every time we wake up. We have relationships with hundreds of the best practitioners in the world, and our job is to keep them engaged continuously, with quick takes when something breaks, structured responses when major research drops, and live sessions on emerging topics while they’re still emerging.

An institution doesn’t stamp trust onto content. In a technical community, trust is conferred in both directions. A practitioner earns standing because people who already have standing engage with her work, cite it, argue with it, and build on it. That insight was the whole idea behind PageRank, Google’s first great innovation. A page mattered because other pages that mattered linked to it. Reputation works the same way.

The audience isn’t just consuming reputation signals; it’s generating them. When a senior engineer whose judgment others respect says out loud that something is worth reading, she spends a little of her own credibility; the author gains a little; and everyone watching recalibrates whom to trust next time. O’Reilly plugs into that existing economy of reputation. When we put our mark on someone’s work, we aren’t the sole source of its credibility. We’re amplifying a judgment the community is already making and adding our own track record to it. The reader who finds it reliable hands status back to the source.

When the readers are machines

Human practitioners aren’t the only ones who need trusted engineering knowledge. The AI systems now sitting in every workflow, the coding and debugging agents and architecture advisors, need it just as badly since most of them are built on scraped web data and documentation that was stale before it was ever indexed. They’re fluent, but they’re wrong often enough that you can’t just take their word for it.

The stakes grow with AI increasingly being used to generate not just provably correct types of content like code, which either works or it doesn’t, but persuasive documents in fuzzier areas like hiring, strategy, and so on. Like everyone else leaning on these tools, we at O’Reilly are reckoning with the consequences of the ability to talk to a model and get back something that looks smart at a glance. A few rounds in, the slop is still there. In the last few months, maybe 10 times as many documents have crossed our desks, from new product ideas to strategic plans and proposals. But the ease of generating the text hides the fact that either the model or the person prompting it doesn’t actually know what they’re talking about. Knowledge workers need ways to ground their work in insights from human experts, particularly when that work is AI-assisted. So we’re building tools that let agents draw on our repository of expertise to support their proposed decisions.

Credible sources are particularly important when thinking through and justifying important choices. Our CTO, Andrew Odewahn, describes the shift this way: “18 months ago, it was all about how to get engineers to be more productive, but now it’s about how to get organizations to make better decisions. The engineering tasks are moving away from coding output to planning.” For planning tasks like comparing implementation approaches, you need expert-over-your-shoulder guidance for contextual decision-making. You can’t just rely on an LLM’s best guess to solve your problem, which is why we see great opportunity for new products like O’Reilly’s Expert Intelligence offering that delivers grounded knowledge embedded in your AI tools and your workflows to help navigate what you do. Trust is foundational because the expertise behind it stays genuine, practical, and human.



Read the whole story
alvinashcraft
20 minutes ago
reply
Pennsylvania, USA
Share this story
Delete
Next Page of Stories