Real world incident response: Microsoft and AXA XL strengthen cyber resilience
2026-07-23T08:52:24Z•4a643509cda0500afb4483f1ab617b1a0cc366747bad883a97dd2003769f4387
ACR StealerAI agent least privilegeAXA XLAsyncAPIBLUERABBITCI/CD compromiseClickFixEntra IDGigaWiperMicrosoft Defender ExpertsOAuth abuseShinyHunterscredential theftcyber insurancedestructive malwareguest access misconfigurationimport-time payloadincident responsenpm supply chainpasskeystoken theftvishing
What happened
Collection of Microsoft Security Blog posts (July 2026) highlighting active threat activity, supply-chain abuses, and defensive/operational updates. Key operational threats include increased ACR Stealer campaigns (late Apr–mid Jun 2026) using ClickFix lures to exfiltrate browser credentials, auth tokens, and documents; an AsyncAPI npm supply-chain compromise that weaponized CI/CD and used import-time payload delivery; OAuth abuse campaigns with tradecraft linked to ShinyHunters (vishing, supply‑chain compromise, misconfigured guest access); and GigaWiper (aka BLUERABBIT), a destructive backdo
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 4a643509cda0500afb4483f1ab617b1a0cc366747bad883a97dd2003769f4387
- Enrichment time
- 2026-07-23T08:52:24Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.