Microsoft Security Blog Expert coverage of cybersecurity topics
- Malicious npm packages abuse dependency confusion to profile developer environmentsby Microsoft Defender Security Research Team on May 30, 2026 at 12:06 am
A dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments. This report details the attack chain, observed tradecraft, and detection opportunities to help organizations identify and disrupt related activity. The post Malicious npm packages abuse dependency confusion to profile developer environments appeared first on Microsoft Security Blog.
- Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protectionby Rob Lefferts on May 29, 2026 at 4:00 pm
Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. The post Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection appeared first on Microsoft Security Blog.
- Typosquatted npm packages used to steal cloud and CI/CD secretsby Microsoft Defender Security Research Team on May 29, 2026 at 3:04 am
The Mini Shai-Hulud campaign used malicious npm packages to target cloud and CI/CD credentials across developer environments. This report details the attack chain, detection opportunities, and mitigation guidance to help organizations identify and disrupt related activity. The post Typosquatted npm packages used to steal cloud and CI/CD secrets appeared first on Microsoft Security Blog.
- The Gentlemen ransomware: Dissecting a self-propagating Go encryptorby Microsoft Threat Intelligence on May 28, 2026 at 3:00 pm
Microsoft Threat Intelligence presents a comprehensive analysis of The Gentlemen, a Go-based ransomware deployed by affiliates of Storm-2697 that combines per-file ephemeral key encryption with an aggressive self-propagation module to deploy itself across an entire network using series of simultaneous lateral movement techniques per target. The post The Gentlemen ransomware: Dissecting a self-propagating Go encryptor appeared first on Microsoft Security Blog.
- From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilitiesby Microsoft Defender Experts and Microsoft Defender Security Research Team on May 26, 2026 at 9:35 pm
Microsoft exposes a cryptojacking campaign using SEO poisoning and ScreenConnect to target high-performance PCs, with malicious sites also surfaced through AI chatbots. The post From poisoned search results to GPU mining: A cryptojacking campaign abusing ScreenConnect and Microsoft .NET utilities appeared first on Microsoft Security Blog.
- Microsoft recognized as a Leader in The Forrester Wave™ for Workforce Identity Security Platformsby Nadim Abdo on May 22, 2026 at 5:00 pm
Microsoft has been recognized as a Leader in The Forrester Wave™: Workforce Identity Security Platforms, Q2 2026, receiving the highest scores in both the current offering and strategy categories. The post Microsoft recognized as a Leader in The Forrester Wave™ for Workforce Identity Security Platforms appeared first on Microsoft Security Blog.
- From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluenceby Microsoft Defender Security Research Team on May 22, 2026 at 4:53 pm
A multi-stage attack on Linux devices began with an exposed F5 BIG-IP edge appliance and pivoted to an internal Confluence server for credential theft and identity compromise. Learn how the threat actor attempted Kerberos relay and lateral movement, and how Microsoft Defender detected, blocked, and unraveled the attack. The post From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence appeared first on Microsoft Security Blog.
- Microsoft Security success stories: How St. Luke’s and ManpowerGroup are securing AI foundationsby Steve Dispensa on May 22, 2026 at 4:00 pm
How Frontier firms secure AI at scale: read how Microsoft customers embed governance, identity, and cloud security to make protection an enabler of AI growth. The post Microsoft Security success stories: How St. Luke’s and ManpowerGroup are securing AI foundations appeared first on Microsoft Security Blog.
- What’s new in Microsoft Security: May 2026by Alym Rayani on May 21, 2026 at 4:00 pm
Microsoft Security’s latest updates extend visibility, control, and protection across expanding ecosystems as organizations accelerate AI adoption. The post What’s new in Microsoft Security: May 2026 appeared first on Microsoft Security Blog.
- Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theftby Microsoft Defender Security Research Team on May 20, 2026 at 5:48 pm
Compromised @antv npm packages deploy the Mini Shai-Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and targets credentials across GitHub, AWS, Kubernetes, Vault, npm, and 1Password platforms. The post Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft appeared first on Microsoft Security Blog.















