Turn specs into evals for any agent with ASSERT

2026-06-11T02:52:16Z293e7cf0bf3d2e0169f89ca9c98e84883b28d86330c48cd5e03be03102c8f6ce
ASSERTagentic-aiai-securityanthropicazure-aici/cdcopilotcredential-theftdependency-confusionforensicsgithub-actionsmitigationnpmopen-sourceprompt-injectionred-teamingsupply-chaintelemetrytyposquatting

What happened

This collection of Microsoft Security Blog posts covers emergent AI and supply-chain threats and defensive guidance. Key findings: ASSERT — an open-source framework to convert natural-language behavioral specs into executable evaluations for models and agents; a telemetry-driven playbook for reconstructing AI activity in Microsoft 365 Copilot and Azure AI to speed investigations and assess data exposure; threat actors exploiting AI branding as social-engineering lures; a prompt-injection vector in the Claude Code GitHub Action that could expose workflow secrets (responsible disclosure and Anth

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
293e7cf0bf3d2e0169f89ca9c98e84883b28d86330c48cd5e03be03102c8f6ce
Enrichment time
2026-06-11T02:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.