Secure agentic AI for your Frontier Transformation

2026-03-10T20:52:20Z7e0203ddaa6974b75bde715ab99a3ab63ab2e2642045b016170d6e8834f25da1
AI threatsAiTM phishingC2 operationsLLM data exfiltrationMicrosoft DefenderNorth Korea (threat actors)OAuth redirection abuseRCE-to-C2RMM backdoorsTycoon2FAagentic AIdeveloper supply chainmalicious Next.js reposmalicious browser extensionsphishing-as-a-servicesecurity operationssigned malwarestolen EV certificatethreat modeling

What happened

Microsoft Security Blog (Feb–Mar 2026) highlights multiple high-impact threats and guidance: threat actors are operationalizing AI to scale tradecraft (including activity by North Korean groups Jasper Sleet/Coral Sleet); malicious AI browser extensions harvested LLM chat histories and browsing data (≈900,000 installs, >20,000 enterprise tenants), exposing sensitive prompt/chat data; Tycoon2FA (AiTM phishing kit / PhaaS) operated at scale (campaigns reaching ~500,000 organizations) and was subject to disruption by Microsoft DCU and partners; signed malware using a stolen EV certificate deployed

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
7e0203ddaa6974b75bde715ab99a3ab63ab2e2642045b016170d6e8834f25da1
Enrichment time
2026-03-10T20:52:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Secure agentic AI for your Frontier Transformation · Baitaphish