Real world incident response: Microsoft and AXA XL strengthen cyber resilience

2026-07-23T08:52:24Z4a643509cda0500afb4483f1ab617b1a0cc366747bad883a97dd2003769f4387
ACR StealerAI agent least privilegeAXA XLAsyncAPIBLUERABBITCI/CD compromiseClickFixEntra IDGigaWiperMicrosoft Defender ExpertsOAuth abuseShinyHunterscredential theftcyber insurancedestructive malwareguest access misconfigurationimport-time payloadincident responsenpm supply chainpasskeystoken theftvishing

What happened

Collection of Microsoft Security Blog posts (July 2026) highlighting active threat activity, supply-chain abuses, and defensive/operational updates. Key operational threats include increased ACR Stealer campaigns (late Apr–mid Jun 2026) using ClickFix lures to exfiltrate browser credentials, auth tokens, and documents; an AsyncAPI npm supply-chain compromise that weaponized CI/CD and used import-time payload delivery; OAuth abuse campaigns with tradecraft linked to ShinyHunters (vishing, supply‑chain compromise, misconfigured guest access); and GigaWiper (aka BLUERABBIT), a destructive backdo­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
4a643509cda0500afb4483f1ab617b1a0cc366747bad883a97dd2003769f4387
Enrichment time
2026-07-23T08:52:24Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.