What’s new in Microsoft Security: May 2026
2026-05-21T20:52:14Z•1bd3509bde8b1a8587554dd5d472ce194c3f237edf2af7f0c3eb97850282368a
1PasswordAI-securityCI/CDClarityFox TempestGitHub ActionsKazuarKubernetesMSaaSMini Shai-HuludRAMPARTRCESecret BlizzardStorm-2949agent-safetybotnetcloud-breachcredential-theftdata-exfiltrationidentity-theftmalware-signingmisconfigurationnation-statenpmsupply-chain
What happened
Microsoft Security May 2026 highlights multiple high-risk supply chain and cloud threats plus new AI‑security tooling and guidance. Key findings: (1) Mini Shai‑Hulud — malicious code injected into compromised @antv npm packages that executes during npm install on Linux CI/CD runners to harvest credentials across GitHub, AWS, Kubernetes, HashiCorp Vault, npm, and 1Password; (2) Fox Tempest — a malware‑signing‑as‑a‑service (MSaaS) enabling other criminals (e.g., Vanilla Tempest, Storm groups) to distribute signed malware and ransomware; (3) Storm‑2949 — identity compromise escalated to a cloud‑w
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 1bd3509bde8b1a8587554dd5d472ce194c3f237edf2af7f0c3eb97850282368a
- Enrichment time
- 2026-05-21T20:52:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.