Containing a domain compromise: How predictive shielding shut down lateral movement

2026-04-18T08:52:23Z96f2ae514c94c22f78142f060d7951fa5d1d548935df5ad1d160fa4003d47986
AI‑enabled phishingAndroid SDK vulnerabilityDNS hijackingForest BlizzardMedusa ransomwareSOHO router compromiseSapphire SleetStorm-1175Storm-2755agentic SOCcredential theftcryptocurrency theftcryptographic posturedevice‑code phishingdomain compromiseincident responseintent redirectionlateral movementmacOS intrusionpayroll fraudpredictive shieldingquantum‑safe readinesssupply‑chain risk

What happened

Collection of Microsoft Security Blog posts (Apr 6–17, 2026) describing multiple high‑impact threats and defensive guidance: a domain compromise stopped by predictive shielding that blocked lateral movement and credential abuse; a severe intent‑redirection vulnerability in a widely used Android SDK exposing millions of wallets; a sophisticated macOS intrusion by North Korean actor Sapphire Sleet targeting credentials, crypto, and data; SOHO router compromises (Forest Blizzard) enabling DNS hijacking and adversary‑in‑the‑middle attacks; AI‑enabled device‑code phishing campaigns that generate on

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
96f2ae514c94c22f78142f060d7951fa5d1d548935df5ad1d160fa4003d47986
Enrichment time
2026-04-18T08:52:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.