The agentic SOC—Rethinking SecOps for the next decade
2026-04-15T02:52:16Z•b002e1cd45cb6b540a14ccf2e94c07a0142c12b43e6e8d7ac035f2babbad986a
AI-enabled phishingAndroidAxiosDNS hijackingForest BlizzardLinux hostingMFA bypassMedusa ransomwareNorth KoreaRussian militarySOHO routerSapphire SleetStorm-1175Storm-2755agentic SOC','security operations','critical infrastructurecookie-gated PHP webshellsdevice code phishingintent redirectionman-in-the-middlemobile walletsnpmpayroll fraudransomwaresupply-chainthird-party SDK
What happened
This collection of Microsoft Security Blog posts (April 2026) highlights multiple high‑impact and evolving threats: a widely deployed npm supply‑chain compromise of Axios attributed to North Korean actor Sapphire Sleet that exposed potentially millions of users; a severe intent‑redirection vulnerability in a third‑party Android SDK that put millions of wallets at risk; SOHO router compromises by Forest Blizzard enabling DNS hijacking and adversary‑in‑the‑middle attacks; financially motivated groups Storm‑2755 conducting payroll diversion attacks against Canadian employees and Storm‑1175 using/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- b002e1cd45cb6b540a14ccf2e94c07a0142c12b43e6e8d7ac035f2babbad986a
- Enrichment time
- 2026-04-15T02:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.