The agentic SOC—Rethinking SecOps for the next decade
2026-04-14T20:52:19Z•980981c5271225c5e4e5e2aa0e200e9b960b26b351be3f2247711a2f8bfb432a
agentic-socai-enabled-phishingandroidaxioscookie-gated-webshellcritical-infrastructuredevice-code-phishingdns-hijackingforest-blizzardintent-redirectionmedusamfa-bypassmitmnpmphp-webshellransomwaresapphire-sleetsdk-vulnerabilitysecurity-operationssoho-routerstorm-1175storm-2755supply-chain
What happened
This collection of Microsoft Security Blog posts (April 2026) highlights multiple high‑impact threat trends and incidents: financially motivated and nation‑state actors (Storm‑2755 “payroll pirate”, Storm‑1175 Medusa ransomware, Forest Blizzard, and Sapphire Sleet) conducting account takeovers, ransomware, DNS‑hijacking/MITM via compromised SOHO routers, and an npm supply‑chain compromise of Axios. Microsoft researchers also disclosed a severe intent‑redirection vulnerability in a widely used Android SDK that exposed wallets, detailed cookie‑gated PHP webshell tradecraft in Linux hosting, and—
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- 980981c5271225c5e4e5e2aa0e200e9b960b26b351be3f2247711a2f8bfb432a
- Enrichment time
- 2026-04-14T20:52:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.