Microsoft Threat Intelligence
msft-ti · B · active
https://www.microsoft.com/en-us/security/blog/topic/threat-intelligence/
Microsoft Threat Intelligence Center reporting. 2026-05-08 audit: WebFetch returned 5 dated TI articles latest 2026-05-04 on AiTM phishing, Sapphire Sleet, Forest Blizzard. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch (listing) https://www.microsoft.com/en-us/security/blog/topic/threat-intelligence/ then webfetch per-article (URLs are /security/blog/YYYY/MM/DD/{slug}/).. AVOID: Nothing — WebFetch works cleanly on both listing and article. No bridge needed.. | 2026-07-05 admiralty audit: B — MSTIC original threat research from Microsoft telemetry. Reliability HIGH->B, status stays active. Distinct source from msrc-blog (PSIRT).
Cited in 84 entries
Citation cadence
Citation days per ISO week (13 weeks of coverage span, total 43).
- Two independently-operating Russian state clusters converged this week on the government user's mailbox and the government user's travel — and both leave persistence that a patch or a password reset does not remove2026-08-02
- CaptiveCrunch: an SVR-linked sub-cluster hijacks hotel and conference captive portals to serve fake update lures, a Go RAT and a token-stealing PowerShell module to travelling staff2026-08-01
- CVE-2026-42897 — Exchange OWA stored XSS weaponised by TA488/LAUNDRY BEAR as a probable zero-day, delivering the browser-resident OWAReaper implant2026-07-31
- 2026-W30 looking ahead — items already in motion: a nginx pre-auth RCE PoC on a ~21-day release clock, Oracle Fusion Middleware abuse assessed 'very likely', a public AD CS DCSync PoC, a Mitel CVE pending, and two EU compliance clocks tightening2026-07-26
- Microsoft Email Threat Landscape Q2 2026: phishing moves off email into Teams vishing, and attachment lures drift PDF → DOCX2026-07-25
- CVE-2026-54121 — Windows Server AD CS 'Certighost': low-priv domain user forges a DC certificate to DCSync, full PoC public (CVSS 8.8)2026-07-25
- Nearly every breach disclosed this week entered through someone else's infrastructure — a service provider, a data-centre host, an ITSM platform and a CI/CD pipeline, not the victim's own perimeter2026-07-19
- npm / developer-ecosystem supply-chain wave status: AsyncAPI was the week's marquee compromise, and DPRK's Contagious Interview broadened the developer-as-target vector from package poisoning to CI/CD pipelines and job-interview repos2026-07-19
- The week's identity intrusions all abused a trusted relationship rather than breaking authentication — OAuth consent and secret reuse, forged and unverified tokens, and helpdesk process abuse turned valid trust into valid-account access2026-07-19
- ClickFix was the week's universal crimeware delivery vector, and macOS gained a coercion playbook — five families this week converged on paste-into-terminal delivery, local password validation before theft, and decentralized dead-drop C22026-07-19
- Microsoft: two parallel ACR Stealer intrusion chains — WebDAV/rundll32/Python with blockchain dead-drop C2, and a fileless MSHTA/steganography chain — both rooted in ClickFix2026-07-17
- CVE-2026-58644 — SharePoint Server deserialization RCE moves from 'Exploitation More Likely' to confirmed exploited and CISA KEV-listed2026-07-17
- AsyncAPI npm compromise — the trojanized packages shipped valid npm/OIDC provenance attestations (Microsoft forensic timeline)2026-07-16
- July Patch Tuesday follow-through: a SharePoint pre-auth JWT bypass from a Pwn2Own chain (CVE-2026-55040) and a pre-auth Dynamics 365 RCE Microsoft expects to be exploited (CVE-2026-55944)2026-07-15
- Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers — none exploiting a Salesforce vulnerability2026-07-14
- Microsoft July 2026 Patch Tuesday ships two actively-exploited zero-days — AD FS local EoP (CVE-2026-56155) and unauthenticated SharePoint EoP (CVE-2026-56164)2026-07-14
- GigaWiper: a Golang backdoor that folds a disk wiper, fake-ransomware encryptor and secure-wipe module into one modular implant2026-07-11
- CVE-2026-47291 — Windows HTTP.sys pre-auth RCE (CVSS 9.8): ZDI publishes full exploitation mechanics and a detection signature2026-07-11
- CVE-2026-50656 — Microsoft Defender engine 'RoguePlanet' local privilege escalation now patched; NCSC-CH tracks the ongoing 'Nightmare Eclipse' zero-day series2026-07-09
- Vulnerability status roll-up — 2026-W27: what moved, what to patch on the exploited-flaw clock vs the monthly cycle2026-07-05
- CVE-2026-45659 — Microsoft SharePoint Server: authenticated deserialization RCE, now KEV-listed2026-07-02
- A malicious "Perplexity AI" Chrome extension intercepted every address-bar keystroke via a search-suggest override2026-06-30
- Operation Endgame2026-06-29
- npm supply-chain worms — a sustained wave across the week2026-06-29
- Microsoft: "Photo ZIP" phishing laundered through Calendly drops Node.js TonRAT against European hospitality front desks2026-06-27
- Operation Endgame dismantles the Amadey and StealC malware-as-a-service backbone2026-06-25
- Threat actor: DPRK Sapphire Sleet escalates npm supply-chain attacks with the Mastra compromise2026-06-22
- Research: the AI agent and toolchain control plane became a concrete attack-surface class this week2026-06-22
- Looking ahead — 2026-W252026-06-22
- Chaotic Eclipse / Nightmare Eclipse zero-day wave — RoguePlanet (CVE-2026-50656) still unpatched, PoC works on June builds2026-06-22
- Mastra npm scope compromise attributed to North Korea, with the access vector our deep dive could not name2026-06-21
- AutoJack — Microsoft shows a single web page can drive host RCE through an AI agent's local MCP server2026-06-20
- Nightmare/Chaotic Eclipse zero-day wave — the Defender LPE now carries a CVE, a public PoC, and Microsoft's "Exploitation More Likely" rating, with no patch2026-06-19
- Microsoft details a USB-LNK worm with Tor hidden-service C2 driving a cryptocurrency clipboard hijacker2026-06-19
- Varonis "SearchLeak" (CVE-2026-42824): one-click M365 Copilot data exfiltration, now patched2026-06-16
- The Gentlemen ransomware: 478 claimed leak-site victims, self-propagating Go encryptor, operator publicly named2026-06-12
- June 2026 Patch Tuesday: four CVSS ≥ 9.1 criticals — Windows kernel TCP/IP RCE, Nuance PowerScribe, Azure Stack Edge, Exchange Online2026-06-12
- CVE-2026-25089 — Fortinet FortiSandbox: unauthenticated OS command injection in the web UI's VNC-launch handler (CVSS 9.8)2026-06-12
- CVE-2026-47344 et al. — TYPO3 core June release: 13 CVEs across every supported branch (10.4 ELTS → 14.3 LTS)2026-06-10
- CVE-2026-47291 — Microsoft June Patch Tuesday: HTTP.sys pre-auth RCE (CVSS 9.8) headlines the largest-ever release (198 CVEs)2026-06-10
- Microsoft Threat Intelligence: AI-brand impersonation drives Lumma Stealer and Vidar delivery via signed binaries2026-06-09
- Windows Netlogon CVE-2026-41089 moves from "patch-available" to actively exploited2026-06-02
- Two concurrent npm dependency-confusion campaigns target internal corporate namespaces2026-06-01
- CVE-2026-41089 — Windows Netlogon: pre-auth SYSTEM RCE on domain controllers, actively exploited2026-06-01
- Nightmare Eclipse / Chaotic Eclipse — Microsoft's Digital Crimes Unit threatens criminal action; GreenPlasma and MiniPlasma (cldflt.sys SYSTEM escalation) remain unpatched; researcher announces July 14 drop2026-05-30
- The Gentlemen ransomware — Microsoft publishes full technical dissection of the Storm-2697 Go-encryptor2026-05-29
- FortiClient EMS CVE-2026-35616 + EKZ Infostealer kill chain2026-05-29
- Microsoft Defender Experts — AI-chatbot search-poisoning extends SEO-poisoning lure; GPU-utility lookalikes drop ScreenConnect, then process-hollowed miners under signed Microsoft binary2026-05-28
- AI tooling as lure, attack surface and force-multiplier — the cross-day pattern no single daily framed whole2026-05-25
- Microsoft Defender CVE-2026-41091 + CVE-2026-45498 — both CVEs confirmed exploited, out-of-band engine update 4.18.26040.7 confirmed as fix2026-05-22
- Keycloak 26.6.2 — 16 CVEs including OIDC session fixation (CVE-2026-7507), WebAuthn execute-actions token replay (CVE-2026-37982), introspection audience bypass (CVE-2026-37979) and cross-realm IDOR in Authorization Services (CVE-2026-4630)2026-05-21
- CVE-2026-42822 — Microsoft Azure Local Disconnected Operations (ALDO): CVSS 10.0 unauthenticated network elevation-of-privilege, "Exploitation More Likely"2026-05-21
- vm2 Node.js sandbox — 12 critical CVEs (CVE-2026-43997 / 43999 / 44005 / 44006 / 44008 / 44009 et al.), sandbox escape to host RCE, upgrade to ≥ 3.11.42026-05-20
- Storm-2949 SSPR-to-Key-Vault Azure kill chain2026-05-20
- Microsoft DCU disrupts Fox Tempest malware-signing-as-a-service feeding Rhysida, INC, Qilin and Akira ransomware operations2026-05-20
- CVE-2026-45585 (YellowKey) — Microsoft formally assigns CVE and publishes WinRE mitigation2026-05-20
- CVE-2026-45584 — Microsoft Defender Engine heap-buffer-overflow RCE over network2026-05-20
- CVE-2026-41091 — Microsoft Defender Engine link-following EoP, actively exploited2026-05-20
- Windows "Chaotic Eclipse" zero-day proliferation — YellowKey, GreenPlasma, MiniPlasma2026-05-18
- Tycoon2FA after the March 2026 takedown — OAuth Device Authorization Grant abuse on Microsoft 3652026-05-18
- + 24 earlier entries