Recent Advisories

Severity ID Title Vendor Product Date Type
NONE MSSECURE:6D00E9...

Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft_MSSECURE:6D00E966D9372364C645950D0C2319E5

Microsoft has identified an active supply chain attack targeting the _@antv_ node package manager (npm) package ecosystem. A threat actor compromis...

N/A N/A MSSECURE
NONE MSSECURE:1D54D2...

Securing the gaming culture of cultures_MSSECURE:1D54D209A555D383D4633CE25EFF8D6A

__The Deputy CISO blog series is where Microsoft _Deputy Chief Information Security Officers_ (CISOs) share their thoughts on what is most importa...

N/A N/A MSSECURE
NONE MSSECURE:8C75FD...

Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow_MSSECURE:8C75FDCEB1F13D9A2E245E0943069417

In this article 1. Why we are investing in this 2. RAMPART: Continuous safety testing for agentic AI 3. Clarity: Helping check software engi...

N/A N/A MSSECURE
NONE MSSECURE:6BDC62...

Exposing Fox Tempest: A malware-signing service operation_MSSECURE:6BDC62484139BBC1A9BA13B799482AA1

In this article 1. Fox Tempest’s role and impact 2. Fox Tempest’s malware signing as a service infrastructure 3. Defending against Fox Tempe...

N/A N/A MSSECURE
NONE MSSECURE:241FF1...

Exposing Fox Tempest: A malware-signing service operation_MSSECURE:241FF15BA37FA03AFCBD210CE8014308

In this article 1. Fox Tempest’s role and impact 2. Fox Tempest’s malware signing as a service infrastructure 3. Defending against Fox Tempe...

N/A N/A MSSECURE
NONE MSSECURE:5AD7A8...

How Storm-2949 turned a compromised identity into a cloud-wide breach_MSSECURE:5AD7A84325AFB86E0C1059E1736E3D0E

In this article 1. Attack chain overview 1. Cloud compromise: Microsoft Entra ID and Microsoft 365 2. Initial access and persistence t...

N/A N/A MSSECURE
NONE MSSECURE:E5598F...

How to better protect your growing business in an AI-powered world_MSSECURE:E5598FF641557BA6C7DA58B40E66D892

AI is rapidly reshaping how work gets done in companies and organizations. In celebrating National Small Business Month, we want to acknowledge the...

N/A N/A MSSECURE
NONE MSSECURE:EFB879...

Kazuar: Anatomy of a nation-state botnet_MSSECURE:EFB8794560583CDED3097080E38D8DB2

In this article 1. Delivery 2. Module types 3. Botnet operations 4. Who is Secret Blizzard? 5. Mitigation and protection guidance 6. M...

N/A N/A MSSECURE
NONE MSSECURE:5FF080...

Kazuar: Anatomy of a nation-state botnet_MSSECURE:5FF080091E3A5D8496F976B20054123D

In this article 1. Delivery 2. Module types 3. Botnet operations 4. Who is Secret Blizzard? 5. Mitigation and protection guidance 6. M...

N/A N/A MSSECURE
NONE MSSECURE:BBC2B9...

When configuration becomes a vulnerability: Exploitable misconfigurations in AI apps_MSSECURE:BBC2B9AF8AFED240AD1386E73E990660

In this article 1. Background 2. What is an exploitable misconfiguration? 3. Exploitable misconfigurations in popular AI applications 4. M...

N/A N/A MSSECURE