When AI infrastructure becomes the target: Securing gateways and control points 2026-08-26 True Microsoft Security Research, Yash Gund and Sumith Maniath True Hunting MacSync Stealer infrastructure through behavioral pivots 2026-08-18 True Microsoft Defender Experts and Microsoft Security Research True DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure 2026-08-10 True Microsoft Threat Intelligence True From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide 2026-08-05 True Microsoft Security Research and Srinivasan Govindarajan True ChainDrop supply chain compromise: Anatomy of a self-propagating worm 2026-08-04 True Microsoft Security Research, Ravikant Tiwari, Sagar Patil and Suriyaraj Natarajan True 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET 2026-08-04 True Microsoft Security Research, David Shiran and Ayelet Artzi True CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft 2026-07-31 True Microsoft Threat Intelligence True Email threat landscape: Q2 2026 trends and insights 2026-07-23 True Microsoft Threat Intelligence and Microsoft Defender Security Research Team True ACR Stealer: Two observed intrusion chains amid increased threat activity 2026-07-16 True Microsoft Security Research and Balaji Venkatesh S True Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery 2026-07-16 True Microsoft Security Research, Ravikant Tiwari, Sagar Patil, Suriyaraj Natarajan and Arvind Gowda True Defending SaaS-based applications against ShinyHunters OAuth abuse 2026-07-13 True Microsoft Security Research and Microsoft Defender Security Research Team True GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware 2026-07-09 True Microsoft Threat Intelligence True Securing AI agents: When AI tools move from reading to acting 2026-06-30 True Microsoft Incident Response True Chromium extension uses AI‑related branding to redirect browser search 2026-06-29 True Microsoft Defender Security Research Team and Microsoft Defender Experts True Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access 2026-06-25 True Microsoft Defender Security Research Team True StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them 2026-06-24 True Microsoft Threat Intelligence, Microsoft Defender Security Research Team and Microsoft Digital Crimes Unit True One intrusion, two cyberattackers: Uncovering parallel threat activity 2026-06-22 True Microsoft Incident Response True AutoJack: How a single page can RCE the host running your AI agent 2026-06-19 True Microsoft Defender Security Research Team True From package to postinstall payload: Inside the Mastra npm supply chain compromise 2026-06-18 True Microsoft Defender Security Research Team True Crypto Clipper uses Tor and worm-like propagation for persistence and control 2026-06-17 True Microsoft Defender Security Research Team and Microsoft Defender Experts True Beyond the benchmark: Advancing security at AI speed 2026-06-17 True Taesoo Kim True AI brands as bait: How threat actors are using the AI hype in social engineering 2026-06-08 True Microsoft Threat Intelligence and Microsoft Defender Security Research Team True Securing CI/CD in an agentic world: Claude Code Github action case 2026-06-05 True Microsoft Defender Security Research Team, Dor Edry and Amit Eliahu True Updating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught us 2026-06-04 True Microsoft AI Red Team True Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign 2026-06-03 True Microsoft Defender Security Research Team True Malicious npm packages abuse dependency confusion to profile developer environments 2026-05-30 True Microsoft Defender Security Research Team True Typosquatted npm packages used to steal cloud and CI/CD secrets 2026-05-29 True Microsoft Defender Security Research Team True The Gentlemen ransomware: Dissecting a self-propagating Go encryptor 2026-05-28 True Microsoft Threat Intelligence True From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities 2026-05-26 True Microsoft Defender Experts and Microsoft Defender Security Research Team True From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence 2026-05-22 True Microsoft Defender Security Research Team True Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft 2026-05-20 True Microsoft Defender Security Research Team True Exposing Fox Tempest: A malware-signing service operation 2026-05-19 True Microsoft Threat Intelligence True How Storm-2949 turned a compromised identity into a cloud-wide breach 2026-05-18 True Microsoft Defender Security Research Team True Kazuar: Anatomy of a nation-state botnet 2026-05-14 True Microsoft Threat Intelligence True When configuration becomes a vulnerability: Exploitable misconfigurations in AI apps 2026-05-14 True Microsoft Defender Security Research Team and Yossi Weizman True Defense at AI speed: Microsoft’s new multi-model agentic security system tops leading industry benchmark 2026-05-12 True Taesoo Kim True Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise 2026-05-12 True Microsoft Incident Response True Active attack: Dirty Frag Linux vulnerability expands post-compromise risk 2026-05-08 True Microsoft Defender Security Research Team True When prompts become shells: RCE vulnerabilities in AI agent frameworks 2026-05-07 True Microsoft Defender Security Research Team, Uri Oren, Amit Eliahu and Dor Edry True ClickFix campaign uses fake macOS utilities lures to deliver infostealers 2026-05-06 True Microsoft Defender Security Research Team and Microsoft Defender Experts True Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise 2026-05-04 True Microsoft Defender Security Research Team and Microsoft Threat Intelligence True CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments 2026-05-02 True Microsoft Defender Security Research Team True Email threat landscape: Q1 2026 trends and insights 2026-04-30 True Microsoft Threat Intelligence and Microsoft Defender Security Research Team True Detection strategies across cloud and identities against infiltrating IT workers 2026-04-21 True Microsoft Defender Security Research Team and Microsoft Threat Intelligence True Cross‑tenant helpdesk impersonation to data exfiltration: A human-operated intrusion playbook 2026-04-18 True Microsoft Defender Security Research Team True Containing a domain compromise: How predictive shielding shut down lateral movement 2026-04-17 True Microsoft Defender Security Research Team True Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise 2026-04-16 True Microsoft Threat Intelligence and Microsoft Defender Security Research Team True Investigating Storm-2755: “Payroll pirate” attacks targeting Canadian employees 2026-04-09 True Microsoft Incident Response True Intent redirection vulnerability in third-party SDK exposed millions of Android wallets to potential risk 2026-04-09 True Microsoft Defender Security Research Team True SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks 2026-04-07 True Microsoft Threat Intelligence True