Women’s History Month: Encouraging women in cybersecurity at every career stage

2026-03-05T20:52:25Z1efee846e621386538219b0809b0795c6ba01b6c85a94312f5618653a4835171
AiTMLLM-data-exposureTycoon2FAai-assistantai-securityautonomous-defensecommand-and-controldeveloper-supply-chainev-certificatemalicious-browser-extensionsmalware-deliverynext.jsoauth-redirectionopenclawpersistent-accessphishingphishing-as-a-serviceremote-code-executionrmmruntime-isolationsecurity-exposure-managementself-hosted-agentssigned-malwarethreat-modeling

What happened

Microsoft Security Blog roundup covering multiple active threats and defensive guidance: malicious AI browser extensions harvested LLM chat histories and browsing data with ~900,000 installs and exposure across >20,000 enterprise tenants; Tycoon2FA AiTM phishing-as-a-service reached ~500,000 organizations monthly before disruption; signed malware using a stolen EV certificate deployed legitimate RMM tools to gain persistent enterprise access; OAuth redirection flows are being abused to deliver phishing and malware; developer-targeting supply-chain attacks used malicious Next.js repositories to

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
1efee846e621386538219b0809b0795c6ba01b6c85a94312f5618653a4835171
Enrichment time
2026-03-05T20:52:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.