Observability for AI Systems: Strengthening visibility for proactive risk detection
2026-03-19T14:52:33Z•5b002174ca7319d7c6ddaeefec3731fe443b5e0b604dbba1b41cd0ed8e6927f2
agentic-aiai-securitybackdoorcontagious-interviewcoral-sleetcredential-theftdeveloper-recruitmentfake-vpnflexibleferretidentity-led-intrusionjasper-sleetmicrosoft-defendermicrosoft-teamsobservabilityottercookieprompt-injectionpurviewseo-poisoningsigned-trojansocial-engineeringstorm-2561supply-chain-malicethreat-actorsvoice-phishingvpn-credentials
What happened
The feed highlights multiple active threat trends and Microsoft guidance: Storm-2561 is using SEO poisoning to distribute fake, signed VPN clients that install trojans and steal VPN credentials; the “Contagious Interview” campaign delivers backdoors (OtterCookie, FlexibleFerret) via fake developer interviews to steal API tokens, cloud credentials, wallets, and source code; Microsoft DART documents voice‑phishing via Microsoft Teams leading to identity‑led compromise. Several posts call out AI‑related risks—prompt injection, operationalization of AI by threat actors (e.g., Jasper Sleet, Coral S
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 5b002174ca7319d7c6ddaeefec3731fe443b5e0b604dbba1b41cd0ed8e6927f2
- Enrichment time
- 2026-03-19T14:52:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.