Real world incident response: Microsoft and AXA XL strengthen cyber resilience
2026-07-23T02:52:16Z•d3b0de0fe8a02cb797769801c63d64d78a75ae4fe3b575e266f32614f5bd74c8
ACR-StealerAI-agentsAsyncAPIBLUERABBITBlack-HatCI/CDClickFixDefender-ExpertsEntraIDGigaWiperOAuth-abuseShinyHuntersauthentication-tokenscredential-theftcyber-insurancedestructive-malwareimport-time-payloadsincident-responseleast-privilegenpmpasskeyssupply-chain-attackthreat-intelligence
What happened
This collection of Microsoft Security Blog posts highlights several active and high-impact threats plus strategic defensive moves. Key incidents: ACR Stealer campaigns (late Apr–mid Jun 2026) using ClickFix lures to steal browser credentials, authentication tokens, and documents; an AsyncAPI npm supply-chain compromise that weaponized trusted CI/CD workflows to deliver import-time payloads; and GigaWiper (aka BLUERABBIT), a destructive backdoor built by combining multiple malware families. Microsoft also documents OAuth abuse tied to activity consistent with ShinyHunters targeting SaaS apps,發布
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- d3b0de0fe8a02cb797769801c63d64d78a75ae4fe3b575e266f32614f5bd74c8
- Enrichment time
- 2026-07-23T02:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.