Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development
2026-05-21T01:24:15Z•0fd7e3b9cb3762cdad5b7ebcd994784f2e17176cfabe3872ad2acdf18bcdd651
BitLocker-bypassClarityDiscordEvilTokensFox-TempestMSaaSMicrosoft-Graph-APIMiniPlasmaRAMPARTTrapdoorWebwormYellowKeyactive-exploitationai-securityandroid-ad-fraudbackdoorgithub-actionsgithub-breachmalware-signingnpm-compromiseoauth-phishingpoCsupply-chainteamPCPvs-code-extension
What happened
A large cluster of high-impact security incidents and disclosures: Microsoft open-sourced AI-agent testing tools (RAMPART, Clarity) and disrupted a malware‑signing‑as‑a‑service operation (attributed to Fox Tempest); multiple supply‑chain compromises (Grafana/TanStack npm, compromised Nx Console VS Code extension, GitHub Actions tampering, Mini Shai‑Hulud npm infections) and widespread credential/CI theft campaigns; active intrusions including a GitHub insider/device compromise (TeamPCP), Webworm backdoors using Discord and Microsoft Graph API, and a major Android ad‑fraud campaign (Trapdoor).
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 0fd7e3b9cb3762cdad5b7ebcd994784f2e17176cfabe3872ad2acdf18bcdd651
- Enrichment time
- 2026-05-21T01:24:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.