Guarding AI memory
2026-06-23T20:52:15Z•91a152f571dc238d25bd739464eeabf30d2bdffa8f9b44ef28b7c860769a03b7
AI agentsAI securityAutoGen StudioAutoJackMastraRCESapphire SleetTor C2backdoorcrypto clipperdetection and responselocalhost exploitationnpmparallel threat actorspersistencepostinstall payloadransomwaresupply chainthreat intelligenceworm-like propagation
What happened
Microsoft Security Blog roundup (Jun 15–22, 2026): multiple high‑risk findings and guidance. Key disclosures include AutoJack — a novel exploit chain where a single malicious webpage can escalate an AI browsing agent into host remote code execution by abusing trust in localhost, missing auth, and unsafe parameter handling (notably via AutoGen Studio’s MCP WebSocket); the Mastra npm supply‑chain compromise by threat actor “Sapphire Sleet,” a poisoned package that delivered a postinstall payload and infected 140+ projects; and a cryptocurrency clipper campaign that combines clipboard theft, Tor‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 91a152f571dc238d25bd739464eeabf30d2bdffa8f9b44ef28b7c860769a03b7
- Enrichment time
- 2026-06-23T20:52:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.