New tools and guidance: Announcing Zero Trust for AI

2026-03-20T02:52:17Z95cde3dfc606edf16b3bf9a53912e95d7dfa9a7850f6de3a1ce4c53ed7df1142
AI observabilityAI securityContagious InterviewFlexibleFerretIOCsMicrosoft DefenderMicrosoft PurviewOtterCookieSEO poisoningStorm-2561TrojanZero Trust for AIcredential theftemail security benchmarkgovernancephishingprompt injectionsocial engineeringthreat intelligencevoice phishing

What happened

Microsoft Security Blog (March 2026) published a collection of posts focused on AI security, threat activity, and detection/mitigation guidance. Highlights include the launch of “Zero Trust for AI” (new AI pillar, reference architecture, updated guidance, and an assessment tool), guidance on AI observability and prompt-injection detection, and Purview innovations for governance. Multiple threat reports describe active campaigns and TTPs: Storm-2561 using SEO poisoning to distribute fake VPN clients that install signed trojans and steal VPN credentials; Contagious Interview—fake developer job/​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
95cde3dfc606edf16b3bf9a53912e95d7dfa9a7850f6de3a1ce4c53ed7df1142
Enrichment time
2026-03-20T02:52:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New tools and guidance: Announcing Zero Trust for AI · Baitaphish