Microsoft Build 2026: Securing code, agents, and models across the development lifecycle

2026-06-03T02:52:20Z8d2d7a41eba93df733a5c4325d8da2289ef1ff6dab1893b8020d6b57c384414e
AI/model securityCI/CDConfluenceF5 BIG-IPGPU miningKerberos relayMDASHMicrosoft DefenderSEO poisoningScreenConnectThe Gentlemencloud credentialscryptojackingdependency confusiondetection and mitigationexfiltrationlateral movementnpmransomwareself-propagationsupply chaintyposquatting

What happened

Microsoft Security Blog posts (May–June 2026) detail multiple active threats, supply-chain abuses, and defensive advances. Key findings include a dependency‑confusion campaign that published 33 malicious npm packages to profile developer/build environments; a Mini Shai‑Hulud typosquatting campaign using malicious npm packages to exfiltrate cloud and CI/CD credentials; a Go‑based self‑propagating ransomware family (“The Gentlemen”) with aggressive lateral movement; and a cryptojacking campaign abusing SEO poisoning, ScreenConnect, and Microsoft .NET utilities to deploy GPU miners (also surfaced

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
8d2d7a41eba93df733a5c4325d8da2289ef1ff6dab1893b8020d6b57c384414e
Enrichment time
2026-06-03T02:52:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.