Turn specs into evals for any agent with ASSERT

2026-06-12T02:52:16Zf3817eeccd2af5f87d4db68033aa7491db80cb61bf26f253efe6bb2940672f8c
ASSERTAnthropicCI/CDClaude CodeMDASHMiasmaagentic AIcredential theftdependency confusioninvestigationsnpmprompt injectionred teamingsocial engineeringsupply chaintelemetrythreat intelligencetyposquattingworkflow secrets

What happened

A set of Microsoft Security Blog posts detailing multiple high-risk supply chain and agentic-AI threats and defensive guidance. Key items: a prompt-injection flaw in the Claude Code GitHub Action that could expose workflow secrets (responsible disclosure and Anthropic mitigations), the Miasma npm campaign that backdoored >90 @redhat-cloud-services package versions to steal credentials and propagate, dependency-confusion and typosquatting campaigns (33 malicious npm packages and Mini Shai‑Hulud) used to profile developer/build environments and exfiltrate cloud/CI/CD secrets, and broader AI/AGI‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
f3817eeccd2af5f87d4db68033aa7491db80cb61bf26f253efe6bb2940672f8c
Enrichment time
2026-06-12T02:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Turn specs into evals for any agent with ASSERT · Baitaphish