Security News & Updates

Latest news and updates about Security.

AllMicrosoft 365IntunePower PlatformEntra IDSecurityAzureSharePoint
Security

Red Hat npm Miasma Attack Hits CI/CD Supply Chains

Microsoft Threat Intelligence uncovered a large-scale npm supply chain attack involving trojanized packages under the @redhat-cloud-services scope. The campaign abused a compromised CI/CD publishing workflow to deliver credential-stealing malware targeting GitHub, npm, AWS, Azure, GCP, Kubernetes, and developer systems, making it especially relevant for security teams and DevOps administrators.

3 min read · Jun 3, 2026
Security

Microsoft Build 2026 Security: Code, Agents, Models

At Microsoft Build 2026, Microsoft announced new security capabilities to protect code, AI agents, and models across the development lifecycle. Highlights include the expanded preview of MDASH for exploitability-focused vulnerability discovery and general availability of Microsoft Defender integration with GitHub Code Security to help teams prioritize and remediate real risks faster.

3 min read · Jun 2, 2026
Security

npm Dependency Confusion Attack Targets Developer Environments

Microsoft Threat Intelligence uncovered 33 malicious npm packages that abused dependency confusion to impersonate internal corporate packages and silently profile developer systems during installation. The campaign matters because it targets developer workstations and CI/CD environments, creating a foothold for potential follow-on supply chain attacks.

3 min read · May 30, 2026
Security

Typosquatted npm Packages Steal Cloud and CI/CD Secrets

Microsoft has uncovered an active npm supply chain attack in which 14 typosquatted packages stole AWS credentials, HashiCorp Vault tokens, GitHub Actions data, and npm publish tokens during installation. The campaign matters because it targets developer and build environments, creating risk of cloud lateral movement, CI/CD compromise, and downstream software supply chain attacks.

3 min read · May 29, 2026
Security

The Gentlemen Ransomware: Self-Propagating Go Threat

Microsoft Threat Intelligence has published a deep technical analysis of The Gentlemen ransomware, a Go-based ransomware-as-a-service threat that combines strong file encryption with aggressive self-propagation. The research matters for defenders because the malware can rapidly spread across local systems and network shares, increasing the blast radius of a single compromise.

3 min read · May 29, 2026
Security

Cryptojacking Campaign Abuses ScreenConnect and .NET

Microsoft has detailed an active cryptojacking campaign that uses poisoned search results and AI chatbot recommendations to lure users to fake software download sites. The attack abuses DLL sideloading, ScreenConnect, and Microsoft .NET utilities to gain persistent access and mine cryptocurrency on high-GPU systems, raising the risk of follow-on activity such as data theft or ransomware.

3 min read · May 29, 2026
Security

F5 and Confluence Attack Chain Hits Hybrid Identity

Microsoft detailed a multi-stage intrusion where attackers compromised an internet-facing F5 BIG-IP appliance, pivoted to an internal Linux host, then exploited Confluence to steal credentials and target Active Directory. The incident highlights how edge devices, Linux systems, and SaaS apps can become linked attack paths in hybrid environments, making broader monitoring and patching essential.

3 min read · May 29, 2026
Security

Microsoft Security May 2026: Purview and Entra Updates

Microsoft Security’s May 2026 updates focus on improving visibility and control across data, identities, and AI-driven environments. Highlights include the general availability of the new Purview Data Security Posture Management experience, deeper investigations with OCR and custom examinations, Entra ID Account recovery, and expanded preview for Windows 365 for Agents.

3 min read · May 29, 2026
Security

@antv npm Attack Hits CI/CD Secrets and Tokens

Microsoft has disclosed an active supply chain attack involving compromised @antv npm packages that used malicious preinstall scripts to steal credentials from GitHub Actions and other CI/CD environments. The campaign matters because it spread through popular downstream dependencies, putting developer pipelines, cloud secrets, and software supply chains at risk.

3 min read · May 20, 2026