Secure agentic AI for your Frontier Transformation

2026-03-11T14:52:19Z9d25416aada764926b2f888e39af2b56665690b250098ccec30515d29a31d70d
AiTM phishingLLM data exfiltrationMicrosoft DefenderNext.jsNorth Korea (Jasper Sleet/Coral Sleet)OAuth redirection abuseRCE-to-C2RMM backdoorsTycoon2FAagentic AIautonomous defensedeveloper-targetingfrontier AImalicious browser extensionsphishing-as-a-servicesigned malwarestolen EV certificatesupply-chainthreat modeling

What happened

Microsoft Security Blog round-up (Feb–Mar 2026): multiple high-impact threat trends and defensive guidance. Key items include: securing agentic AI and frontier AI deployments; threat actors operationalizing AI (notably North Korean groups Jasper Sleet/Coral Sleet) to scale tradecraft; malicious browser extensions harvesting LLM chat histories and browsing data with ~900,000 installs impacting >20,000 enterprise tenants; Tycoon2FA AiTM phishing-as-a-service operating at scale (affecting hundreds of thousands of organizations) and subsequent disruption efforts; signed malware using a stolen EV (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
9d25416aada764926b2f888e39af2b56665690b250098ccec30515d29a31d70d
Enrichment time
2026-03-11T14:52:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.