Microsoft recognized as a Leader in The Forrester Wave™ for Workforce Identity Security Platforms
2026-05-24T20:52:19Z•4445f38dad69d7c42efd3676e577255e07cdfecd0bddc6debf8fe77644c561f0
ConfluenceF5 BIG-IPagent-securityai-safetyci/cdcloud-breachcredential-theftdetectionidentity-compromiseintrusionkerberos-relaylateral-movementmalware-signingmicrosoft-defendernpmopen-sourceransomwaresecurity-updatessupply-chainthreat-actor
What happened
This collection of Microsoft Security Blog posts highlights multiple high-risk incidents and defensive capabilities. Key incidents include a multi-stage Linux intrusion that began with an exposed F5 BIG‑IP appliance and pivoted to an internal Confluence server (Kerberos relay attempts, credential theft, lateral movement), supply‑chain compromise of @antv npm packages delivering the Mini Shai‑Hulud payload to steal CI/CD and cloud credentials, and Fox Tempest — a malware‑signing‑as‑a‑service used to distribute malicious code (including ransomware). Another report details Storm‑2949 turning a
m
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 4445f38dad69d7c42efd3676e577255e07cdfecd0bddc6debf8fe77644c561f0
- Enrichment time
- 2026-05-24T20:52:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.