June 9, 2026

AI brands as bait: How threat actors are using the AI hype in social engineering

In this article ChatGPT-themed lure leads to phishing kit collecting credit card data Claude-themed phishing campaign collected credentials and access tokens “Awesome AI Windows Plugin” malvertising […]
June 3, 2026

Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign

In this article Attack chain overview Mitigation and protection guidance Learn more Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting 32 maliciously modified […]
May 23, 2026

From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence

In this article Attack chain overview Initial access: Exploiting edge appliances Discovery and reconnaissance Lateral movement and identity compromise Mitigation and protection guidance Microsoft Defender XDR […]
May 19, 2026

How Storm-2949 turned a compromised identity into a cloud-wide breach

In this article Attack chain overview Cloud compromise: Microsoft Entra ID and Microsoft 365 Initial access and persistence through targeted social engineering and SSPR abuse Directory […]
May 13, 2026

Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise

In this article Abuse of trusted relationships as an attack delivery mechanism Methods, tools, and access strategies Campaign conclusion Microsoft Defender detection and hunting guidance In […]
May 5, 2026

Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise

In this article Multi-step social engineering campaign leading to credential theft Mitigation and protection guidance Microsoft Defender detections Hunting queries Indicators of compromise Phishing campaigns continue […]
May 1, 2026

Email threat landscape: Q1 2026 trends and insights

In this article Tycoon2FA disruption impact QR code phishing attacks CAPTCHA tactics Malicious payloads Business email compromise Defending against email threats Microsoft Defender detections During the […]
April 18, 2026

Containing a domain compromise: How predictive shielding shut down lateral movement

In this article Predictive shielding overview Attack chain overview How predictive shielding changed the outcome MITRE ATT&CK® techniques observed Learn more In identity-based attack campaigns, any […]
April 17, 2026

Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise

In this article Sapphire Sleet’s campaign lifecycle Defending against Sapphire Sleet intrusion activity Microsoft Defender detection and hunting guidance Indicators of compromise Executive summary Microsoft Threat […]
March 20, 2026

When tax season becomes cyberattack season: Phishing and malware campaigns using tax-related lures

In this article A wide range of tax-themed campaigns How to protect users and organization against tax-themed campaigns Microsoft Defender detection and hunting guidance Indicators of […]
March 13, 2026

Storm-2561 uses SEO poisoning to distribute fake VPN clients for credential theft

In this article From search to stolen credentials: Storm-2561 attack chain Defending against credential theft campaigns Microsoft Defender detection and hunting guidance Indicators of compromise In […]