Microsoft recognized as a Leader in The Forrester Wave™ for Workforce Identity Security Platforms
2026-05-25T08:52:26Z•6669d3205e2d7cc0b142393a3230206dfe8c5348721fcc708638d9f12d06338a
@antvagent safetyai securityci/cd credential theftclaritycloud breachconfluencef5 big-ipfox tempestidentity compromisekerberos relaylateral movementmalware-signing-as-a-servicemicrosoft defendermini shai-huludnpm supply chainrampartsigned malwarestorm-2949workforce identity security
What happened
Microsoft Security Blog (May 18–22, 2026) aggregates multiple high‑risk security findings and product updates: a multi‑stage Linux intrusion originating from an exposed F5 BIG‑IP appliance that pivoted to an internal Confluence server with Kerberos‑relay and lateral‑movement attempts (detected and disrupted by Microsoft Defender); Mini Shai‑Hulud malware delivered via compromised @antv npm packages that steals CI/CD credentials across GitHub, AWS, Kubernetes, Vault, npm, and 1Password; and the exposure of Fox Tempest, a malware‑signing‑as‑a‑service operation used to distribute signed malicious
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 6669d3205e2d7cc0b142393a3230206dfe8c5348721fcc708638d9f12d06338a
- Enrichment time
- 2026-05-25T08:52:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.