Women’s History Month: Encouraging women in cybersecurity at every career stage
2026-03-06T02:52:24Z•a747f8c21060da18e1047d063877ffa2c0573659299980a4af7132a019d7485f
AiTMOpenClawPhaaSTycoon2FAaibackdoorbrowser-extensioncommand-and-controldata-exfiltrationdefense-in-depthdeveloper-targetingenterprise-impactev-certificatellmnext.jsoauthphishingrceredirect-abusermmsecurity-operationsself-hosted-agentssigned-malwaresupply-chainthreat-modeling
What happened
Microsoft Security Blog updates (Feb–Mar 2026) describe multiple high-impact adversary techniques and defensive guidance: malicious AI browser extensions (≈900k installs, affecting >20k enterprise tenants) exfiltrating LLM chat histories and browsing data; Tycoon2FA—an AiTM phishing-as-a-service—operating at scale against hundreds of thousands of organizations; signed malware using a stolen EV certificate to deploy legitimate RMM tools as persistent backdoors; OAuth redirection abuse used to weaponize trusted sign‑in flows for phishing/malware delivery; developer-targeting via malicious Next.j
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- a747f8c21060da18e1047d063877ffa2c0573659299980a4af7132a019d7485f
- Enrichment time
- 2026-03-06T02:52:24Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.