Secure agentic AI for your Frontier Transformation
2026-03-10T20:52:20Z•7e0203ddaa6974b75bde715ab99a3ab63ab2e2642045b016170d6e8834f25da1
AI threatsAiTM phishingC2 operationsLLM data exfiltrationMicrosoft DefenderNorth Korea (threat actors)OAuth redirection abuseRCE-to-C2RMM backdoorsTycoon2FAagentic AIdeveloper supply chainmalicious Next.js reposmalicious browser extensionsphishing-as-a-servicesecurity operationssigned malwarestolen EV certificatethreat modeling
What happened
Microsoft Security Blog (Feb–Mar 2026) highlights multiple high-impact threats and guidance: threat actors are operationalizing AI to scale tradecraft (including activity by North Korean groups Jasper Sleet/Coral Sleet); malicious AI browser extensions harvested LLM chat histories and browsing data (≈900,000 installs, >20,000 enterprise tenants), exposing sensitive prompt/chat data; Tycoon2FA (AiTM phishing kit / PhaaS) operated at scale (campaigns reaching ~500,000 organizations) and was subject to disruption by Microsoft DCU and partners; signed malware using a stolen EV certificate deployed
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 7e0203ddaa6974b75bde715ab99a3ab63ab2e2642045b016170d6e8834f25da1
- Enrichment time
- 2026-03-10T20:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.