Typosquatted npm packages used to steal cloud and CI/CD secrets 2026-05-29 True Microsoft Defender Security Research Team True The Gentlemen ransomware: Dissecting a self-propagating Go encryptor 2026-05-28 True Microsoft Threat Intelligence True From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities 2026-05-26 True Microsoft Defender Experts and Microsoft Defender Security Research Team True From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence 2026-05-22 True Microsoft Defender Security Research Team True Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft 2026-05-20 True Microsoft Defender Security Research Team True Exposing Fox Tempest: A malware-signing service operation 2026-05-19 True Microsoft Threat Intelligence True How Storm-2949 turned a compromised identity into a cloud-wide breach 2026-05-18 True Microsoft Defender Security Research Team True Kazuar: Anatomy of a nation-state botnet 2026-05-14 True Microsoft Threat Intelligence True When configuration becomes a vulnerability: Exploitable misconfigurations in AI apps 2026-05-14 True Microsoft Defender Security Research Team and Yossi Weizman True Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark 2026-05-12 True Taesoo Kim True Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise 2026-05-12 True Microsoft Incident Response True Active attack: Dirty Frag Linux vulnerability expands post-compromise risk 2026-05-08 True Microsoft Defender Security Research Team True When prompts become shells: RCE vulnerabilities in AI agent frameworks 2026-05-07 True Microsoft Defender Security Research Team, Uri Oren, Amit Eliahu and Dor Edry True ClickFix campaign uses fake macOS utilities lures to deliver infostealers 2026-05-06 True Microsoft Defender Security Research Team and Microsoft Defender Experts True Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise 2026-05-04 True Microsoft Defender Security Research Team and Microsoft Threat Intelligence True CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments 2026-05-02 True Microsoft Defender Security Research Team True Email threat landscape: Q1 2026 trends and insights 2026-04-30 True Microsoft Threat Intelligence and Microsoft Defender Security Research Team True Detection strategies across cloud and identities against infiltrating IT workers 2026-04-21 True Microsoft Defender Security Research Team and Microsoft Threat Intelligence True Cross‑tenant helpdesk impersonation to data exfiltration: A human-operated intrusion playbook 2026-04-18 True Microsoft Defender Security Research Team True Containing a domain compromise: How predictive shielding shut down lateral movement 2026-04-17 True Microsoft Defender Security Research Team True Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise 2026-04-16 True Microsoft Threat Intelligence and Microsoft Defender Security Research Team True Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees 2026-04-09 True Microsoft Incident Response True Intent redirection vulnerability in third-party SDK exposed millions of Android wallets to potential risk 2026-04-09 True Microsoft Defender Security Research Team True SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks 2026-04-07 True Microsoft Threat Intelligence True Inside an AI‑enabled device code phishing campaign 2026-04-06 True Microsoft Defender Security Research Team True Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations 2026-04-06 True Microsoft Threat Intelligence True Threat actor abuse of AI accelerates from tool to cyberattack surface 2026-04-02 True Sherrod DeGrippo True Cookie-controlled PHP webshells: A stealthy tradecraft in Linux hosting environments 2026-04-02 True Microsoft Defender Security Research Team True Mitigating the Axios npm supply chain compromise 2026-04-01 True Microsoft Threat Intelligence and Microsoft Defender Security Research Team True The threat to critical infrastructure has changed. Has your readiness? 2026-03-31 True Sherrod DeGrippo True WhatsApp malware campaign delivers VBScript and MSI backdoors 2026-03-31 True Microsoft Defender Security Research Team True How Microsoft Defender protects high-value assets in real-world attack scenarios 2026-03-27 True Microsoft Defender Security Research Team True Guidance for detecting, investigating, and defending against the Trivy supply chain compromise 2026-03-25 True Microsoft Defender Security Research Team True Case study: How predictive shielding in Defender stopped GPO-based ransomware before it started 2026-03-23 True Microsoft Defender Security Research Team True When tax season becomes cyberattack season: Phishing and malware campaigns using tax-related lures 2026-03-19 True Microsoft Threat Intelligence and Microsoft Defender Security Research Team True Help on the line: How a Microsoft Teams support call led to compromise 2026-03-16 True Microsoft Incident Response True Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft 2026-03-12 True Microsoft Threat Intelligence and Microsoft Defender Experts True Detecting and analyzing prompt abuse in AI tools 2026-03-12 True Microsoft Incident Response True Contagious Interview: Malware delivered through fake developer job interviews 2026-03-11 True Microsoft Defender Experts and Microsoft Defender Security Research Team True AI as tradecraft: How threat actors operationalize AI 2026-03-06 True Microsoft Threat Intelligence True Malicious AI Assistant Extensions Harvest LLM Chat Histories 2026-03-05 True Microsoft Defender Security Research Team True Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale 2026-03-04 True Microsoft Threat Intelligence and Microsoft Defender Security Research Team True Signed malware impersonating workplace apps deploys RMM backdoors 2026-03-03 True Microsoft Defender Security Research Team True OAuth redirection abuse enables phishing and malware delivery 2026-03-02 True Microsoft Defender Security Research Team True Developer-targeting campaign using malicious Next.js repositories 2026-02-24 True Microsoft Defender Experts and Microsoft Defender Security Research Team True Analysis of active exploitation of SolarWinds Web Help Desk 2026-02-07 True Microsoft Defender Security Research Team True New Clickfix variant ‘CrashFix’ deploying Python Remote Access Trojan 2026-02-05 True Microsoft Defender Security Research Team True Infostealers without borders: macOS, Python stealers, and platform abuse 2026-02-02 True Microsoft Defender Security Research Team True Case study: Securing AI application supply chains 2026-01-30 True Microsoft Defender Security Research Team True From runtime risk to real‑time defense: Securing AI agents 2026-01-23 True Microsoft Defender Security Research Team True