Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks

2026-07-21T08:52:23Z0ad704bad1d716467a1d2461211ccf6ccc317f8bfcd5b9aad2e3e6c434d5d113
ACR StealerAI agentsAsyncAPIBLUERABBITCI/CD compromiseClickFix lureEntra IDGigaWiperOAuth abuseSMS/voice authenticationShinyHunterscredential theftdestructive backdooridentity and accessimport-time payloadleast privilegemisconfigured guest accessnpm supply chainpasskeysransomware-likesupply-chain attacktoken thefttool binding`,`Defender Experts`,`Secure Future Initiative`,`SFIvishingwiper

What happened

Microsoft Security Blog (July 2026) highlights multiple high-impact threats and defensive guidance: Microsoft Defender Experts observed elevated ACR Stealer activity (late Apr–mid Jun 2026) using ClickFix lures to exfiltrate browser credentials, auth tokens, and sensitive documents via two intrusion chains. Threat actors compromised AsyncAPI npm packages and abused trusted CI/CD workflows to deliver import-time payloads (npm supply-chain compromise). ShinyHunters-linked activity abused OAuth (vishing, supply-chain compromises, misconfigured guest access) to target SaaS apps. GigaWiper (aka BLU

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
0ad704bad1d716467a1d2461211ccf6ccc317f8bfcd5b9aad2e3e6c434d5d113
Enrichment time
2026-07-21T08:52:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks · Baitaphish