Microsoft DCU Fox Tempest disruption
incident · incident:microsoft-dcu-disrupts-fox-tempest-malware-signing-as-a-servi
Microsoft DCU disrupts the Fox Tempest malware-signing-as-a-service: 1,000+ Artifact Signing certificates revoked under an SDNY court order; downstream users include Rhysida, INC, Qilin and Akira plus Vanilla Tempest and Storm-0501/2561/0249.
Coverage
0
first 2026-05-20 → last –
no data
Latest activity
–
no entry about it yet
Peak priority
·
no entry about it yet
Targets
·
no sector or region stated
Sources cited
0
0 hosts
Relationships explore in graph
Typed, source-stated connections from the entity registry; each edge cites the entry whose reporting establishes it.
related to
- Akiradownstream user of the disrupted signing service
- Fox TempestMicrosoft DCU disruption of Fox Tempest's signing service
- INC Ransomdownstream user of the disrupted signing service
- Qilindownstream user of the disrupted signing service
Story timeline
No published entries reference this entity yet.
Entries about Microsoft DCU Fox Tempest disruption
No published entry is about this entity yet · an entry attaches by registry key, by the entity's name or a public alias in its title or body, or (for CVE entities) by exact CVE id.