Women’s History Month: Encouraging women in cybersecurity at every career stage
2026-03-06T14:52:22Z•8133c28156aca99beceab908ad5b14733c22058a64607ac2308e22ed2aa62d6e
AI privacyAiTMC2LLM data exfiltrationNext.jsOAuth redirection abuseOpenClawRMM backdoorsTycoon2FAbuild-time RCEdeveloper-targetingidentity and isolationmalicious browser extensionsmalicious repositoriespersistencephishingphishing-as-a-servicesigned malwarestolen EV certificatesupply chainthreat modeling
What happened
Microsoft Security Blog posts (Feb–Mar 2026) describe multiple active, high-impact threats and supply-chain/AI risks: malicious AI browser extensions harvested LLM chat histories and browsing data (≈900,000 installs, activity across >20,000 enterprise tenants) risking wide data exposure; Tycoon2FA, a large AiTM phishing-as-a-service platform, reached ~500,000 organizations monthly before disruption; signed malware using a stolen EV certificate deployed legitimate RMM tools to establish persistent backdoors; OAuth redirection flows are being abused to convert trusted authentication into phish/m
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 8133c28156aca99beceab908ad5b14733c22058a64607ac2308e22ed2aa62d6e
- Enrichment time
- 2026-03-06T14:52:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.