What’s new in Microsoft Security: May 2026
2026-05-22T02:52:14Z•dcb8ae4433e4d90a8e3d7a205384b5af4980db13c9aabfe0d8332c03e1e1c673
1password@antvai-security','autonomous-agents','rampart','clarityawsbotnetci/cdcloud-breachcredential-theftdata-leakfox-tempestgithubidentity-compromisekazuarkubernetesmalware-signing-as-a-servicemicrosoft-security-blogmini-shai-huludmisconfigurationmsaasnation-statenpmrcestorm-2949supply-chainvault
What happened
Microsoft Security Blog (May 2026) roundup covering multiple high‑impact security topics: a supply‑chain compromise of @antv npm packages (“Mini Shai‑Hulud”) that steals CI/CD credentials from Linux automation environments (targets include GitHub, AWS, Kubernetes, Vault, npm, 1Password); a malware‑signing‑as‑a‑service operation (Fox Tempest) used to distribute malicious code and ransomware; Kazuar, an evolving P2P nation‑state botnet; Storm‑2949’s identity‑based cloud‑wide breach demonstrating how stolen credentials enable extensive data theft without malware; and exploitable misconfigurations
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- dcb8ae4433e4d90a8e3d7a205384b5af4980db13c9aabfe0d8332c03e1e1c673
- Enrichment time
- 2026-05-22T02:52:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.