Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks
2026-07-20T08:52:15Z•da553ded00356b7e3f60a584e317665cc7f794382f862d8537fd3108bbfe1366
acr-stealerai agentsasyncapiauthentication tokensblack hat 2026bluerabbitci/cdclickfix lurecredential theftdefender expertsdestructive malwareentra idgigawiperidentity and accessimport-time payloadleast-privilegenpmoauth abusepasskeyssaas securitysecure future initiativeshinyhunterssupply-chainvishing
What happened
Microsoft Security Blog (July 2026) highlights an uptick in supply‑chain and credential‑theft activity and defensive guidance. Key posts describe: active ACR Stealer campaigns (late Apr–mid Jun) using ClickFix lures to steal browser credentials, tokens, and documents; an AsyncAPI npm supply‑chain compromise that weaponized CI/CD and delivered import‑time payloads; OAuth abuse and vishing linked to ShinyHunters targeting SaaS guest access; and GigaWiper (BLUERABBIT), a destructive backdoor combining multiple wiping/ransomware capabilities. Microsoft also published defensive guidance: Entra ID’s
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- da553ded00356b7e3f60a584e317665cc7f794382f862d8537fd3108bbfe1366
- Enrichment time
- 2026-07-20T08:52:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.