What’s new in Microsoft Security: June 2026
2026-06-30T20:52:18Z•16652a231cd4c36ef06b5483e4f5ef8a75b058f1b82d84a8163b591f18a1da8b
AI agentsAmadeyAutoJackCNAPPChromium extensionMCP WebSocketMV3 APIsNode.js implantPerplexity spoofingPhoto ZIPStealCbrowser malwarecloud risk management','endpoint management','Forresterfake shortcut filesguarding AI memoryhospitality sectorinfostealerlocalhost abuseparallel threat actorspersistenceransomwareremote code executionsearch redirecttakedowntool poisoning
What happened
June 2026 Microsoft Security Blog roundup highlighting multiple active threats and defensive guidance: focused research on AI-agent risks including MCP tool‑poisoning (agents manipulated into performing unauthorized actions) and AutoJack (a webpage-driven exploit chain that can achieve RCE on hosts by abusing localhost/MCP WebSocket access); guidance on guarding AI memory; a malicious Chromium extension spoofing Perplexity AI that redirects browser search via MV3 APIs and intermediary infrastructure; a Photo‑ZIP campaign targeting hospitality organizations that uses fake image shortcuts to dro
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 16652a231cd4c36ef06b5483e4f5ef8a75b058f1b82d84a8163b591f18a1da8b
- Enrichment time
- 2026-06-30T20:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.