Guarding AI memory

2026-06-23T02:52:17Zdfee2b96086140de501d97d65234c551810d794ed36e315f78187da7a06f6143
AI memoryAI securityAutoGen StudioAutoJackMCP WebSocketMDASH (agentic vulnerability detection)MastraRCESapphire SleetTorclipboard theftcrypto clipperlocalhost abusemissing authenticationnpmparallel threat activitypostinstall payloadransomwareremote code executionsupply chainsupply-chain compromiseunsafe parameter handlingwallet replacementwebsocketworm-like propagation

What happened

Collection of Microsoft Security Blog posts (June 2026) highlighting emerging AI and supply-chain risks and several active threats. Key items: AutoJack — a novel exploit chain where a single malicious webpage can achieve remote code execution on the host by abusing AI browsing agents’ access to localhost and AutoGen Studio’s MCP WebSocket (missing auth, unsafe parameter handling). Mastra npm supply-chain compromise (Sapphire Sleet) — poisoned packages with postinstall payloads that infected 140+ projects. Crypto Clipper campaign — clipboard theft, wallet replacement, Tor-based C2, worm-like L2

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
dfee2b96086140de501d97d65234c551810d794ed36e315f78187da7a06f6143
Enrichment time
2026-06-23T02:52:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.