Microsoft Build 2026: Securing code, agents, and models across the development lifecycle

2026-06-02T20:52:19Z0c70bb7153ec67a9d8301d0520d0972a6891ca3569e41dd3b39c691afb089a45
ai chatbot abuseci/cdcloud secretsconfluencecredential theftcryptojackingdependency confusiondotnet utilitiesf5 big-ipgo malwaregpu miningkerberos relaylateral movementmdash (ai/dev security)microsoft defendermini shai-huludnpmransomwarescreenconnectself-propagationseo poisoningstorm-2697supply chainthe gentlementyposquatting

What happened

Microsoft Security Blog posts (May–Jun 2026) covering multiple high-risk developer and enterprise threats and new security capabilities announced at Build 2026. Key reports describe two npm supply-chain campaigns — a dependency‑confusion campaign using 33 malicious npm packages to profile developer/build environments, and the Mini Shai‑Hulud typosquatting campaign that steals cloud and CI/CD secrets — plus guidance for detection and mitigation. Additional intelligence details The Gentlemen ransomware (a self‑propagating Go encryptor deployed by Storm‑2697 affiliates), a cryptojacking campaign:

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
0c70bb7153ec67a9d8301d0520d0972a6891ca3569e41dd3b39c691afb089a45
Enrichment time
2026-06-02T20:52:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.