Microsoft uses AI to link two malware operations in racketeering suit

2026-06-24T19:23:59Z8c475109147dc5883e08fe6de7c22ac3fa15884cabe06185b1d42f7e82814d49
A12-A13AI-assisted-investigationAUR-malicious-commitsAmadeyC2-serversCiscoFortinetKDDIPRC-linkedPeopleSoftSD-WANStealCactive-exploitationbootromcredential-leakdata-breachespionageiPhone-exploitmalwaresupply-chainzero-day

What happened

Roundup of multiple high-impact security incidents: Microsoft says it used AI to link two malware families (StealC and Amadey) in a racketeering suit and helped shut down 200+ C2 servers. Large credential exposure reported at a Japanese telco (14.2M managed-email credentials). Widespread active attacks and disclosed vulnerabilities include a massive password‑stealing campaign impacting ~75k Fortinet firewalls, three critical Fortinet sandbox bugs under attack, and a Cisco SD‑WAN 'make‑me‑root' flaw exploited as a 0‑day. Researchers also published a checkm8‑style BootROM exploit for A12/A13 iOS

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
8c475109147dc5883e08fe6de7c22ac3fa15884cabe06185b1d42f7e82814d49
Enrichment time
2026-06-24T19:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.