logo

Microsoft Security

ID: b951ba98-6659-5660-af1d-d9bce60a6749

STIX ID: identity--b951ba98-6659-5660-af1d-d9bce60a6749

Feed Type: rss

Earliest post: 2023-12-05

Latest post: 2026-08-27

Threat intelligence updates, defense strategies, vulnerability research, and insights from Microsoft’s security teams — covering cloud security, cybercrime trends, and best practices to protect enterprises and users.

01/01/2020
08/28/2026
Title Date Published Describes IncidentAuthorVisible
When AI infrastructure becomes the target: Securing gateways and control points2026-08-26TrueMicrosoft Security Research, Yash Gund and Sumith ManiathTrue
Hunting MacSync Stealer infrastructure through behavioral pivots2026-08-18TrueMicrosoft Defender Experts and Microsoft Security ResearchTrue
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure2026-08-10TrueMicrosoft Threat IntelligenceTrue
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide2026-08-05TrueMicrosoft Security Research and Srinivasan GovindarajanTrue
ChainDrop supply chain compromise: Anatomy of a self-propagating worm2026-08-04TrueMicrosoft Security Research, Ravikant Tiwari, Sagar Patil and Suriyaraj NatarajanTrue
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 2026-08-04TrueMicrosoft Security Research, David Shiran and Ayelet ArtziTrue
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft2026-07-31TrueMicrosoft Threat IntelligenceTrue
Email threat landscape: Q2 2026 trends and insights2026-07-23TrueMicrosoft Threat Intelligence and Microsoft Defender Security Research TeamTrue
ACR Stealer: Two observed intrusion chains amid increased threat activity2026-07-16TrueMicrosoft Security Research and Balaji Venkatesh STrue
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery2026-07-16TrueMicrosoft Security Research, Ravikant Tiwari, Sagar Patil, Suriyaraj Natarajan and Arvind GowdaTrue
Defending SaaS-based applications against ShinyHunters OAuth abuse2026-07-13TrueMicrosoft Security Research and Microsoft Defender Security Research TeamTrue
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware2026-07-09TrueMicrosoft Threat IntelligenceTrue
Securing AI agents: When AI tools move from reading to acting2026-06-30TrueMicrosoft Incident ResponseTrue
Chromium extension uses AI‑related branding to redirect browser search2026-06-29TrueMicrosoft Defender Security Research Team and Microsoft Defender ExpertsTrue
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access2026-06-25TrueMicrosoft Defender Security Research TeamTrue
StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them2026-06-24TrueMicrosoft Threat Intelligence, Microsoft Defender Security Research Team and Microsoft Digital Crimes UnitTrue
One intrusion, two cyberattackers: Uncovering parallel threat activity2026-06-22TrueMicrosoft Incident ResponseTrue
AutoJack: How a single page can RCE the host running your AI agent 2026-06-19TrueMicrosoft Defender Security Research TeamTrue
From package to postinstall payload: Inside the Mastra npm supply chain compromise2026-06-18TrueMicrosoft Defender Security Research TeamTrue
Crypto Clipper uses Tor and worm-like propagation for persistence and control2026-06-17TrueMicrosoft Defender Security Research Team and Microsoft Defender ExpertsTrue
Beyond the benchmark: Advancing security at AI speed 2026-06-17TrueTaesoo KimTrue
AI brands as bait: How threat actors are using the AI hype in social engineering2026-06-08TrueMicrosoft Threat Intelligence and Microsoft Defender Security Research TeamTrue
Securing CI/CD in an agentic world: Claude Code Github action case2026-06-05TrueMicrosoft Defender Security Research Team, Dor Edry and Amit EliahuTrue
Updating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught us 2026-06-04TrueMicrosoft AI Red TeamTrue
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign2026-06-03TrueMicrosoft Defender Security Research TeamTrue
Malicious npm packages abuse dependency confusion to profile developer environments2026-05-30TrueMicrosoft Defender Security Research TeamTrue
Typosquatted npm packages used to steal cloud and CI/CD secrets2026-05-29TrueMicrosoft Defender Security Research TeamTrue
The Gentlemen ransomware: Dissecting a self-propagating Go encryptor2026-05-28TrueMicrosoft Threat IntelligenceTrue
From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities2026-05-26TrueMicrosoft Defender Experts and Microsoft Defender Security Research TeamTrue
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence2026-05-22TrueMicrosoft Defender Security Research TeamTrue
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft2026-05-20TrueMicrosoft Defender Security Research TeamTrue
Exposing Fox Tempest: A malware-signing service operation2026-05-19TrueMicrosoft Threat IntelligenceTrue
How Storm-2949 turned a compromised identity into a cloud-wide breach2026-05-18TrueMicrosoft Defender Security Research TeamTrue
Kazuar: Anatomy of a nation-state botnet2026-05-14TrueMicrosoft Threat IntelligenceTrue
When configuration becomes a vulnerability: Exploitable misconfigurations in AI apps2026-05-14TrueMicrosoft Defender Security Research Team and Yossi WeizmanTrue
Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark2026-05-12TrueTaesoo KimTrue
Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise2026-05-12TrueMicrosoft Incident ResponseTrue
Active attack: Dirty Frag Linux vulnerability expands post-compromise risk2026-05-08TrueMicrosoft Defender Security Research TeamTrue
When prompts become shells: RCE vulnerabilities in AI agent frameworks2026-05-07TrueMicrosoft Defender Security Research Team, Uri Oren, Amit Eliahu and Dor EdryTrue
ClickFix campaign uses fake macOS utilities lures to deliver infostealers2026-05-06TrueMicrosoft Defender Security Research Team and Microsoft Defender ExpertsTrue
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise2026-05-04TrueMicrosoft Defender Security Research Team and Microsoft Threat IntelligenceTrue
CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments2026-05-02TrueMicrosoft Defender Security Research TeamTrue
Email threat landscape: Q1 2026 trends and insights2026-04-30TrueMicrosoft Threat Intelligence and Microsoft Defender Security Research TeamTrue
Detection strategies across cloud and identities against infiltrating IT workers2026-04-21TrueMicrosoft Defender Security Research Team and Microsoft Threat IntelligenceTrue
Cross‑tenant helpdesk impersonation to data exfiltration: A human-operated intrusion playbook2026-04-18TrueMicrosoft Defender Security Research TeamTrue
Containing a domain compromise: How predictive shielding shut down lateral movement2026-04-17TrueMicrosoft Defender Security Research TeamTrue
Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise2026-04-16TrueMicrosoft Threat Intelligence and Microsoft Defender Security Research TeamTrue
Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees2026-04-09TrueMicrosoft Incident ResponseTrue
Intent redirection vulnerability in third-party SDK exposed millions of Android wallets to potential risk2026-04-09TrueMicrosoft Defender Security Research TeamTrue
SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks2026-04-07TrueMicrosoft Threat IntelligenceTrue

1–50 of 141