What Happened
Recent evaluations of AI-driven code-patching agents exposed methodological and operational weaknesses that produce misleading headline results and hidden security risk. A reanalysis of a high-profile patching benchmark shows that restrictive protocols and skewed samples produced an exaggerated failure rate; when agents were allowed to run code and not instructed to apply wrong fixes,…
What Happened
Unit 42 published a practical detection pattern that maps cloud identity behavior by clustering audit-log activity and converting those behavioral patterns into standard SQL queries for continuous threat detection. The method uncovers anomalous or risky accounts by grouping identities by role-like behavior and operationalizing those groups as repeatable, queryable detections rather than one-off…
What Happened
Two recent security research streams illustrate converging AI-assisted and infrastructure-level threats. First, Microsoft observed a large-scale AI-assisted executive-impersonation campaign that sent over one million malicious emails impersonating CEOs/CFOs to induce ACH payments using fabricated invoices and third‑party mail services; artifacts pointed to template reuse and generative‑AI signatures in message content and HTML structure…
What Happened
Recent defensive research and incident investigations show three converging patterns attackers use to compromise cloud-hosted web and serverless applications: mapped technique sets targeting cloud web apps, identity‑first social engineering that enables broad Graph/mail/Drive collection, and commodity third‑party infrastructure abused to blend in and evade tracing.
Microsoft published a Cloud Web Applications…
What Happened
Research across the AI security community has converged on a concrete set of vulnerabilities that become critical when models and tooling run on customer‑owned edge infrastructure: prompt injection, poisoned retrievals, model tampering, malicious firmware and supply‑chain compromises, and expanded attack surface from agents and tool integrations. These findings emphasize a shifted trust model—customers…
What Happened
Recent security research and incident telemetry show three converging trends attackers are using to increase success and scale: obfuscation to bypass content defenses, AI-assisted data theft at scale, and social‑engineering that leverages legitimate collaboration tooling for hands‑on compromise.
Obfuscation adapted from prompt injection to phishing
A high‑volume phishing campaign used invisible Unicode Tag…
What Happened
Two recent investigations illustrate complementary modern threats: autonomous, agentic adversaries that rapidly discover and exploit network weaknesses, and sophisticated counterfeit-software delivery campaigns that gain persistent, privileged footholds.
Unit 42 documented an attack where autonomous AI agents accelerated network compromise, chaining reconnaissance, exploitation and lateral movement into an automated campaign that breached…
What Happened
Over the last three years independent security teams (Project Zero, Trail of Bits, Unit 42), specialist AI-security vendors (HiddenLayer, Lakera, Protect AI), and standards projects (OWASP AI, MITRE ATLAS) have published coordinated defensive research identifying recurring AI vulnerabilities and real-world exploit techniques. Their work documents attacks across the ML lifecycle: data poisoning and…
What Happened
Unit 42 documented a voice-phishing (vishing) campaign — dubbed "Spring Ring" — that abused Microsoft Teams calling features to impersonate trusted internal contacts, socially engineer employees, deliver malware, and escalate to domain controllers, enabling broad network compromise [1]. The campaign leveraged platform-native trust signals (caller identity, in-app presence) to bypass traditional email-centric defenses…
What Happened
Microsoft observed a multistage intrusion campaign (TerminalFix / ClickFix variant) that combined social engineering, signed‑binary abuse, steganography and a Python‑based reverse tunnel to enable silent pivoting and reconnaissance inside target networks [1].
Initial access: victims were lured to paste a malicious PowerShell command from a fake Cloudflare Turnstile CAPTCHA; that command…
What Happened
Unit 42 introduced a diagnostic called perturbation probing and used it to show that safety refusals in large language models are often concentrated in a thin, localized neural layer rather than distributed across the model. The practical takeaway is that internal model defenses (the model's own refusal behavior) can be highly brittle: small…
What Happened
Microsoft announced expanded security and governance controls aimed at organizations deploying AI agents and integrating third‑party telemetry. Key points include:
Extended managed detection and response: Microsoft Defender Experts MDR (P2) now ingests third‑party data through Microsoft Sentinel, enabling 24/7 MDR and threat hunting across non‑Microsoft sources such as Palo Alto Networks,…