Turn specs into evals for any agent with ASSERT
2026-06-11T08:52:16Z•2c5481fd7d19b49d92a38baa51f6c26ecd5bf3ab7d387c282daa5d5ede060f5d
AI investigationsAI-branded phishingASSERTAnthropicAzure AICI/CD securityClaude CodeGitHub ActionsMDASHMiasmaMicrosoft 365 Copilotagentic AIcredential theftdependency confusionevaluation frameworkfailure modesnpmprompt injectionred teamingsocial engineeringsupply chaintelemetrytyposquatting
What happened
A set of Microsoft Security Blog posts covering AI-centric security risks and software supply chain attacks. Key topics include ASSERT — an open-source framework for turning natural-language specs into executable evaluations — and a telemetry-driven playbook for reconstructing AI activity in Microsoft 365 Copilot and Azure AI. Threat research highlights: social-engineering campaigns that weaponize AI branding, a prompt-injection pathway in the Claude Code GitHub Action that could expose workflow secrets (responsibly disclosed and mitigated by Anthropic), an expanded taxonomy of failure modes (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 2c5481fd7d19b49d92a38baa51f6c26ecd5bf3ab7d387c282daa5d5ede060f5d
- Enrichment time
- 2026-06-11T08:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.