Microsoft recognized as a Leader in The Forrester Wave™ for Workforce Identity Security Platforms

2026-05-24T20:52:19Z4445f38dad69d7c42efd3676e577255e07cdfecd0bddc6debf8fe77644c561f0
ConfluenceF5 BIG-IPagent-securityai-safetyci/cdcloud-breachcredential-theftdetectionidentity-compromiseintrusionkerberos-relaylateral-movementmalware-signingmicrosoft-defendernpmopen-sourceransomwaresecurity-updatessupply-chainthreat-actor

What happened

This collection of Microsoft Security Blog posts highlights multiple high-risk incidents and defensive capabilities. Key incidents include a multi-stage Linux intrusion that began with an exposed F5 BIG‑IP appliance and pivoted to an internal Confluence server (Kerberos relay attempts, credential theft, lateral movement), supply‑chain compromise of @antv npm packages delivering the Mini Shai‑Hulud payload to steal CI/CD and cloud credentials, and Fox Tempest — a malware‑signing‑as‑a‑service used to distribute malicious code (including ransomware). Another report details Storm‑2949 turning a 
m

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
4445f38dad69d7c42efd3676e577255e07cdfecd0bddc6debf8fe77644c561f0
Enrichment time
2026-05-24T20:52:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.