Microsoft recognized as a Leader in The Forrester Wave™ for Workforce Identity Security Platforms

2026-05-25T08:52:26Z6669d3205e2d7cc0b142393a3230206dfe8c5348721fcc708638d9f12d06338a
@antvagent safetyai securityci/cd credential theftclaritycloud breachconfluencef5 big-ipfox tempestidentity compromisekerberos relaylateral movementmalware-signing-as-a-servicemicrosoft defendermini shai-huludnpm supply chainrampartsigned malwarestorm-2949workforce identity security

What happened

Microsoft Security Blog (May 18–22, 2026) aggregates multiple high‑risk security findings and product updates: a multi‑stage Linux intrusion originating from an exposed F5 BIG‑IP appliance that pivoted to an internal Confluence server with Kerberos‑relay and lateral‑movement attempts (detected and disrupted by Microsoft Defender); Mini Shai‑Hulud malware delivered via compromised @antv npm packages that steals CI/CD credentials across GitHub, AWS, Kubernetes, Vault, npm, and 1Password; and the exposure of Fox Tempest, a malware‑signing‑as‑a‑service operation used to distribute signed malicious

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
6669d3205e2d7cc0b142393a3230206dfe8c5348721fcc708638d9f12d06338a
Enrichment time
2026-05-25T08:52:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.