The agentic SOC—Rethinking SecOps for the next decade
2026-04-12T08:52:26Z•b428e86c2a52987cd06d53185f255581131e3e529028c71c2d1acb25a8114504
AI-enabled phishingAndroidAxiosDNS hijackingForest BlizzardLinux hostingMFA bypassMITMMedusa ransomwareSOHO routerSapphire SleetSecOps modernizationStorm-1175Storm-2755agentic SOCcookie-gated webshellcritical infrastructuredevice-code-phishingintent-redirectionmobile-walletsnpmpayroll-fraudphp-webshellsupply-chainthird-party SDK
What happened
Collection of Microsoft Security Blog posts (Mar–Apr 2026) reporting multiple high-impact threats and tradecraft trends: a North Korean‑attributed npm supply‑chain compromise of Axios (Sapphire Sleet) that exposed many users; an Android intent‑redirection vulnerability in a widely deployed third‑party SDK impacting millions of apps and mobile wallets; SOHO router compromises and DNS hijacking by Forest Blizzard enabling adversary‑in‑the‑middle operations; financially motivated Storm‑2755 “payroll pirate” attacks diverting Canadian employee salaries; Storm‑1175 fast‑moving Medusa ransomware ops
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- b428e86c2a52987cd06d53185f255581131e3e529028c71c2d1acb25a8114504
- Enrichment time
- 2026-04-12T08:52:26Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.