May 23, 2026

From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence

In this article Attack chain overview Initial access: Exploiting edge appliances Discovery and reconnaissance Lateral movement and identity compromise Mitigation and protection guidance Microsoft Defender XDR […]
May 21, 2026

Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft

Microsoft has identified an active supply chain attack targeting the @antv node package manager (npm) package ecosystem. A threat actor compromised an @antv maintainer account and […]
May 2, 2026

CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments

In this article Vulnerability details Mitigation and protection guidance Microsoft Defender XDR detections References Learn more Microsoft Defender is investigating a high-severity local privilege escalation vulnerability […]
April 3, 2026

Cookie-controlled PHP webshells: A stealthy tradecraft in Linux hosting environments

In this article Cookie-controlled execution behavior Observed variants of cookie-controlled PHP web shells Mitigation and protection guidance  Microsoft Defender XDR detections Microsoft Security Copilot prompts Microsoft Defender XDR […]