Containing a domain compromise: How predictive shielding shut down lateral movement
2026-04-17T20:52:16Z•e07705370f566472e8ebc67ddf83695533d088a0b702d036c285cb679486e889
AI-enabled-phishingAI-securityAndroid-SDKDNS-hijackingMedusa-ransomwareNorth-KoreaSOHO-routerSapphire-SleetStorm-1175Storm-2755agentic-SOCcredential-theftcryptographic-inventorydevice-code-phishingdomain-compromiseincident-responseintent-redirectionlateral-movementmacOSman-in-the-middlepatching-mitigationpredictive-shieldingquantum-safesupply-chainwallet-theft
What happened
Collection of Microsoft Security Blog posts (Apr 2026) describing multiple active threats and defensive guidance: a rapid domain compromise where predictive shielding contained lateral movement and credential abuse; a severe intent‑redirection vulnerability in a widely deployed Android SDK exposing millions of wallets; a sophisticated macOS intrusion by North Korea‑linked Sapphire Sleet targeting credentials and crypto; SOHO router compromises enabling DNS hijacking and man‑in‑the‑middle attacks; an AI‑enabled device‑code phishing campaign that generates live authentication codes; financially‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- microsoft_security_blog
- Record identifier
- e07705370f566472e8ebc67ddf83695533d088a0b702d036c285cb679486e889
- Enrichment time
- 2026-04-17T20:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.