Women’s History Month: Encouraging women in cybersecurity at every career stage

2026-03-06T02:52:24Za747f8c21060da18e1047d063877ffa2c0573659299980a4af7132a019d7485f
AiTMOpenClawPhaaSTycoon2FAaibackdoorbrowser-extensioncommand-and-controldata-exfiltrationdefense-in-depthdeveloper-targetingenterprise-impactev-certificatellmnext.jsoauthphishingrceredirect-abusermmsecurity-operationsself-hosted-agentssigned-malwaresupply-chainthreat-modeling

What happened

Microsoft Security Blog updates (Feb–Mar 2026) describe multiple high-impact adversary techniques and defensive guidance: malicious AI browser extensions (≈900k installs, affecting >20k enterprise tenants) exfiltrating LLM chat histories and browsing data; Tycoon2FA—an AiTM phishing-as-a-service—operating at scale against hundreds of thousands of organizations; signed malware using a stolen EV certificate to deploy legitimate RMM tools as persistent backdoors; OAuth redirection abuse used to weaponize trusted sign‑in flows for phishing/malware delivery; developer-targeting via malicious Next.j

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
a747f8c21060da18e1047d063877ffa2c0573659299980a4af7132a019d7485f
Enrichment time
2026-03-06T02:52:24Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Women’s History Month: Encouraging women in cybersecurity at every career stage · Baitaphish