Guarding AI memory
2026-06-22T20:52:18Z•dd4ecba46d1c437f30b1640f821377c3c2154431a2e56851411e65aef771a155
agentic vulnerability detectionai memoryai securityautogen studioautojackbackdoorcrypto clipperdetection and huntinglocalhost trustmastramcp websocketmdashmicrosoft defender email benchmarkingnpmparallel threat actorspostinstall payloadransomwarerceremote code executionsapphire sleetsupply chain compromisethreat intelligencetorworm-like propagationxdr
What happened
A Microsoft Security Blog collection covering multiple high-risk developments: a detailed threat model for attacks against what AI ‘remembers’; AutoJack — an exploit chain that can convert a single malicious webpage into remote code execution on the host by abusing AI browsing agents’ access to localhost and AutoGen Studio’s MCP WebSocket; a Mastra npm supply-chain compromise (Sapphire Sleet) that poisoned 140+ projects via postinstall payloads; a cryptocurrency clipper campaign using Tor and worm-like propagation to persist and enable follow-on access; and an analysis of parallel threat actor
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- dd4ecba46d1c437f30b1640f821377c3c2154431a2e56851411e65aef771a155
- Enrichment time
- 2026-06-22T20:52:18Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.