Guarding AI memory
2026-06-24T08:52:16Z•c0336e7b3e49a792c67b90460ddb3c5c87dfe806f9df56824a98793f938c532e
AI memory/poisoningAI securityAutoGen Studio MCP WebSocketAutoJackSapphire SleetTor C2agentic vulnerability detection (MDASH)clipboard theftcrypto clipperdetection and evasionemail security benchmarkinglocalhost abusenpm/Mastraparallel threat actorsransomwareremote code executionsupply chain compromiseworm‑like propagation
What happened
Microsoft Security Blog posts (mid‑June 2026) highlight emerging AI‑era attack surfaces and notable incidents: AutoJack — a novel exploit chain where a single malicious webpage can achieve host remote code execution by abusing localhost access and an AutoGen Studio MCP WebSocket; a Mastra npm supply‑chain compromise (Sapphire Sleet) that poisoned packages and delivered postinstall payloads across 140+ projects; a crypto‑clipper campaign combining clipboard theft, wallet replacement, Tor C2, and worm‑like propagation to maintain persistence and enable follow‑on activity; and a ransomware case l
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- c0336e7b3e49a792c67b90460ddb3c5c87dfe806f9df56824a98793f938c532e
- Enrichment time
- 2026-06-24T08:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.