Microsoft open-sources tools for designing and testing AI agents
2026-05-21T20:51:44Z•738d3f9bd8db9f7e4bfb285ca73b912d22d0f8be30a6abc85ee724dae369e869
CISA-KEVClarityNx ConsoleRAMPARTTanStackai-securityci-cd-compromisedata-exfiltrationdevsecopsfirst-vpngithub-breachgrafana-breachincident-responselaw-enforcementmalicious-vscode-extensionmicrosoft-defenderopen-sourceoperation-saffronred-teamingsecrets-theftsupply-chainvulnerability-exploitation
What happened
Multiple security developments: Microsoft open-sourced two AI-agent security tools (Clarity for structured design reviews and RAMPART for continuous red-team testing). Law enforcement led Operation Saffron dismantled First VPN—anonymity service used by ransomware operators—seizing servers and domains. A supply-chain compromise in the TanStack ecosystem via a malicious VS Code extension (Nx Console) enabled credential theft and movement through CI/CD, contributing to breaches at GitHub and Grafana Labs and exfiltration of thousands of private repositories. Microsoft confirmed active in-the-wild
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- 738d3f9bd8db9f7e4bfb285ca73b912d22d0f8be30a6abc85ee724dae369e869
- Enrichment time
- 2026-05-21T20:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.