Observability for AI Systems: Strengthening visibility for proactive risk detection

2026-03-19T14:52:33Z5b002174ca7319d7c6ddaeefec3731fe443b5e0b604dbba1b41cd0ed8e6927f2
agentic-aiai-securitybackdoorcontagious-interviewcoral-sleetcredential-theftdeveloper-recruitmentfake-vpnflexibleferretidentity-led-intrusionjasper-sleetmicrosoft-defendermicrosoft-teamsobservabilityottercookieprompt-injectionpurviewseo-poisoningsigned-trojansocial-engineeringstorm-2561supply-chain-malicethreat-actorsvoice-phishingvpn-credentials

What happened

The feed highlights multiple active threat trends and Microsoft guidance: Storm-2561 is using SEO poisoning to distribute fake, signed VPN clients that install trojans and steal VPN credentials; the “Contagious Interview” campaign delivers backdoors (OtterCookie, FlexibleFerret) via fake developer interviews to steal API tokens, cloud credentials, wallets, and source code; Microsoft DART documents voice‑phishing via Microsoft Teams leading to identity‑led compromise. Several posts call out AI‑related risks—prompt injection, operationalization of AI by threat actors (e.g., Jasper Sleet, Coral S

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
5b002174ca7319d7c6ddaeefec3731fe443b5e0b604dbba1b41cd0ed8e6927f2
Enrichment time
2026-03-19T14:52:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Observability for AI Systems: Strengthening visibility for proactive risk detection · Baitaphish