Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks

2026-07-19T14:52:16Zee47a4c874b0e6f96f8bb2e941a3e112eb110a61e6e08fc03cb0074c0e8f9261
ACR StealerAI agentsAsyncAPIBLUERABBITCI/CD compromiseClickFix lureDefender Experts (MDE)GigaWiperMicrosoft Entra IDOAuth abuseSFISMS/voice authenticationSaaS securitySecure Future InitiativeShinyHuntersauthentication tokenscredential theftdestructive malwareidentity and access managementimport-time payloadleast privilegenpmpasskeyssupply-chainvishing

What happened

This Microsoft Security Blog collection (July 2026) highlights a wave of high-impact supply chain and credential-theft activity, defensive guidance for AI-driven systems, and product/security program updates. Notable incident analyses: ACR Stealer campaigns (late Apr–mid Jun 2026) using ClickFix lures to exfiltrate browser credentials, tokens, and documents; an AsyncAPI npm supply-chain compromise that abused trusted CI/CD to deliver import-time payloads; and GigaWiper (aka BLUERABBIT), a destructive backdoor that integrates code from multiple malware families. Microsoft also describes OAuth/O

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
ee47a4c874b0e6f96f8bb2e941a3e112eb110a61e6e08fc03cb0074c0e8f9261
Enrichment time
2026-07-19T14:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks · Baitaphish