Microsoft recognized as a Leader in The Forrester Wave™ for Workforce Identity Security Platforms
2026-05-24T02:52:16Z•ad6903ac9f34a9b04be93b616b4664553adb1e90eb7e81a833d6b553a2da9e17
1Password@antvAWSCI/CD secretsClarity (open-source) agent safety toolsConfluenceF5 BIG-IPFox TempestGitHubKerberos relayKubernetesLinux intrusionMini Shai-HuludRAMPARTStorm groupStorm-2949Vanilla TempestVaultcloud breachcredential theftidentity compromiselateral movementmalware-signing-as-a-servicenpm compromisesupply chain
What happened
This Microsoft Security Blog collection (May 18–22, 2026) highlights multiple high-impact security topics: a multi-stage Linux intrusion that began with an exposed F5 BIG‑IP appliance and pivoted to an internal Confluence server (including Kerberos‑relay attempts, credential theft, and lateral movement) that Microsoft Defender detected and disrupted; supply‑chain compromises of @antv npm packages delivering the ‘Mini Shai‑Hulud’ payload to steal CI/CD secrets from Linux automation environments (targeting GitHub, AWS, Kubernetes, Vault, npm, 1Password); the discovery of Fox Tempest, a malware‑签
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- ad6903ac9f34a9b04be93b616b4664553adb1e90eb7e81a833d6b553a2da9e17
- Enrichment time
- 2026-05-24T02:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.