Microsoft Build 2026: Securing code, agents, and models across the development lifecycle
2026-06-03T02:52:20Z•8d2d7a41eba93df733a5c4325d8da2289ef1ff6dab1893b8020d6b57c384414e
AI/model securityCI/CDConfluenceF5 BIG-IPGPU miningKerberos relayMDASHMicrosoft DefenderSEO poisoningScreenConnectThe Gentlemencloud credentialscryptojackingdependency confusiondetection and mitigationexfiltrationlateral movementnpmransomwareself-propagationsupply chaintyposquatting
What happened
Microsoft Security Blog posts (May–June 2026) detail multiple active threats, supply-chain abuses, and defensive advances. Key findings include a dependency‑confusion campaign that published 33 malicious npm packages to profile developer/build environments; a Mini Shai‑Hulud typosquatting campaign using malicious npm packages to exfiltrate cloud and CI/CD credentials; a Go‑based self‑propagating ransomware family (“The Gentlemen”) with aggressive lateral movement; and a cryptojacking campaign abusing SEO poisoning, ScreenConnect, and Microsoft .NET utilities to deploy GPU miners (also surfaced
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 8d2d7a41eba93df733a5c4325d8da2289ef1ff6dab1893b8020d6b57c384414e
- Enrichment time
- 2026-06-03T02:52:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.