# Microsoft Security Blog

Expert coverage of cybersecurity topics

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Protecting organizations from AI-assisted executive impersonation and invoice fraud

DevFeed: [Protecting organizations from AI-assisted executive impersonation and invoice fraud](<https://devfeed.tech/articles/protecting-organizations-from-ai-assisted-executive-impersonation-and-invoice-fraud-7645.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/>)

Author: Microsoft Security Research

Published: 2026-09-10T17:23:05Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [spoofing](<https://devfeed.tech/topics/spoofing.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [executive](<https://devfeed.tech/tags/executive.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [scam](<https://devfeed.tech/tags/scam.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

Microsoft examines an email-fraud campaign that used AI-assisted executive impersonation, fabricated invoices, and fake supporting conversations to prompt ACH payments.

### Source excerpt

Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud. The post Protecting organizations from AI-assisted executive impersonation and invoice fraud appeared first on Microsoft Security Blog.

## Detect and disrupt AI-themed attacks with Microsoft Defender

DevFeed: [Detect and disrupt AI-themed attacks with Microsoft Defender](<https://devfeed.tech/articles/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender-7644.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/10/detect-and-disrupt-ai-themed-attacks-with-microsoft-defender/>)

Author: Rob Lefferts

Published: 2026-09-10T16:00:00Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [spoofing](<https://devfeed.tech/topics/spoofing.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [adversary-in-the-middle-aitm](<https://devfeed.tech/tags/adversary-in-the-middle-aitm.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [claude](<https://devfeed.tech/tags/claude.md>), [copilot](<https://devfeed.tech/tags/copilot.md>), [credential-theft](<https://devfeed.tech/tags/credential-theft.md>), [deepseek](<https://devfeed.tech/tags/deepseek.md>), [defender](<https://devfeed.tech/tags/defender.md>), [github](<https://devfeed.tech/tags/github.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

Microsoft describes AI-themed phishing, malvertising, credential theft, and malware campaigns that impersonate popular AI services and tools. It argues that attackers are exploiting trust and urgency around AI brands rather than compromising the referenced services.

### Source excerpt

See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.

## Threat matrix: Mapping threats across cloud web applications

DevFeed: [Threat matrix: Mapping threats across cloud web applications](<https://devfeed.tech/articles/threat-matrix-mapping-threats-across-cloud-web-applications-7643.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/09/threat-matrix-mapping-threats-across-cloud-web-applications/>)

Author: Microsoft Security Research and Lior Leizerovich

Published: 2026-09-09T21:30:00Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [web applications](<https://devfeed.tech/topics/web-applications.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [framework](<https://devfeed.tech/tags/framework.md>), [mapping](<https://devfeed.tech/tags/mapping.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [security](<https://devfeed.tech/tags/security.md>), [serverless](<https://devfeed.tech/tags/serverless.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>)

### AI overview

Microsoft introduces a MITRE ATT&CK-aligned threat matrix for cloud-hosted web applications and serverless platforms. The framework maps attack techniques to help security teams identify visibility gaps, prioritize hardening, and investigate threats across application and cloud layers.

### Source excerpt

Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms. The post Threat matrix: Mapping threats across cloud web applications appeared first on Microsoft Security Blog.

## Passkey-themed social engineering leads to identity and cloud compromise

DevFeed: [Passkey-themed social engineering leads to identity and cloud compromise](<https://devfeed.tech/articles/passkey-themed-social-engineering-leads-to-identity-and-cloud-compromise-7642.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/>)

Author: Microsoft Security Research, Krithika Ramakrishnan, Bharat Vaghela, Vaibhav Deshmukh, Subhajit Ghosh, Anusha Chakraborty, Akash Chaudhuri, Victor Chingtham and Ivan Macalintal

Published: 2026-09-09T17:41:18Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [MFA](<https://devfeed.tech/topics/mfa.md>), [data-processing](<https://devfeed.tech/topics/data-processing.md>)

Tags: [adversary-in-the-middle-aitm](<https://devfeed.tech/tags/adversary-in-the-middle-aitm.md>), [apis](<https://devfeed.tech/tags/apis.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [data](<https://devfeed.tech/tags/data.md>), [identity](<https://devfeed.tech/tags/identity.md>), [mfa](<https://devfeed.tech/tags/mfa.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>)

### AI overview

Microsoft Security Research describes a passkey-themed social-engineering campaign that compromises cloud identities through AiTM phishing or device-code flows, establishes authentication persistence, and collects cloud data. It outlines investigation signals and recommends revoking sessions and removing unauthorized authentication methods after confirmed compromise.

### Source excerpt

Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance. The post Passkey-themed social engineering leads to identity and cloud compromise appeared first on Microsoft Security Blog.

## How to secure edge AI in customer-owned environments

DevFeed: [How to secure edge AI in customer-owned environments](<https://devfeed.tech/articles/how-to-secure-edge-ai-in-customer-owned-environments-7641.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/04/secure-edge-ai-customer-owned-environments/>)

Author: Shayak Lahiri

Published: 2026-09-04T19:10:10Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [AI Platforms/Deployment](<https://devfeed.tech/topics/ai-platforms-deployment.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>), [Inference](<https://devfeed.tech/topics/inference.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [customer](<https://devfeed.tech/tags/customer.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [edge](<https://devfeed.tech/tags/edge.md>), [frontier-ai-models](<https://devfeed.tech/tags/frontier-ai-models.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [inference](<https://devfeed.tech/tags/inference.md>), [models](<https://devfeed.tech/tags/models.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains how moving AI inference and assets into customer-owned edge environments changes the security trust model. It recommends attestation, provenance, action mediation, and releasing sensitive assets only to trusted environments.

### Source excerpt

As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge AI in customer-owned environments appeared first on Microsoft Security Blog.

## ASCII smuggling crosses over from AI prompt injection to phishing evasion

DevFeed: [ASCII smuggling crosses over from AI prompt injection to phishing evasion](<https://devfeed.tech/articles/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion-7640.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/>)

Author: Microsoft Security Research, Noam Kochavi and Sarah Wolstencroft

Published: 2026-09-03T16:00:00Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [ASCII](<https://devfeed.tech/topics/ascii.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>), [Language models](<https://devfeed.tech/topics/language-models.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [ai-models](<https://devfeed.tech/tags/ai-models.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [ascii](<https://devfeed.tech/tags/ascii.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

Microsoft describes a phishing campaign that uses invisible Unicode tag characters to split lure words and evade email parsing. The technique, known as ASCII smuggling, was previously prominent in AI prompt-injection research because models can process hidden text that people cannot see.

### Source excerpt

Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog.

## Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

DevFeed: [Impersonating IT support: how threat actors turn a remote session into enterprise-wide access](<https://devfeed.tech/articles/impersonating-it-support-how-threat-actors-turn-a-remote-session-into-enterprise-wide-access-7639.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/>)

Author: Microsoft Security Research, Sagar Patil, Arlette Umuhire Sangwa, Jesse Birch and Ravikant Tiwari

Published: 2026-09-02T22:51:18Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>)

Tags: [c2](<https://devfeed.tech/tags/c2.md>), [identity](<https://devfeed.tech/tags/identity.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [microsoft-teams](<https://devfeed.tech/tags/microsoft-teams.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [security](<https://devfeed.tech/tags/security.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Microsoft analyzes an intrusion campaign in which attackers impersonate IT support through Microsoft Teams, obtain remote access, deploy a Node.js and JavaScript implant, and move laterally through enterprise systems. The article provides detection, mitigation, and hunting guidance.

### Source excerpt

Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity. The post Impersonating IT support: how threat actors turn a remote session into enterprise-wide access appeared first on Microsoft Security Blog.

## Counterfeit installers to system compromise: Tracking a deceptive software download campaign

DevFeed: [Counterfeit installers to system compromise: Tracking a deceptive software download campaign](<https://devfeed.tech/articles/counterfeit-installers-to-system-compromise-tracking-a-deceptive-software-download-campaign-7637.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/>)

Author: Microsoft Security Research, Microsoft Defender Experts and Parth Jomadkar

Published: 2026-09-01T22:48:28Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>)

Tags: [china](<https://devfeed.tech/tags/china.md>), [defender](<https://devfeed.tech/tags/defender.md>), [malware](<https://devfeed.tech/tags/malware.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

Microsoft documents an active malware campaign that uses counterfeit software-download pages and malicious installers to compromise systems. It outlines the attack chain, Defender XDR detection and disruption, and mitigations for blocking untrusted downloads and strengthening endpoint protections.

### Source excerpt

An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system compromise: Tracking a deceptive software download campaign appeared first on Microsoft Security Blog.

## Cybersecurity IR Workshop: The workshop you shouldn't miss

DevFeed: [Cybersecurity IR Workshop: The workshop you shouldn't miss](<https://devfeed.tech/articles/cybersecurity-ir-workshop-the-workshop-you-shouldn-t-miss-7638.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/09/01/cybersecurity-ir-workshop-you-shouldnt-miss/>)

Author: Microsoft Defender Experts Cybersecurity Incident Response

Published: 2026-09-01T18:55:35Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [Incident response](<https://devfeed.tech/topics/incident-response.md>), [incident](<https://devfeed.tech/topics/incident.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [dart](<https://devfeed.tech/tags/dart.md>), [defender](<https://devfeed.tech/tags/defender.md>), [identity](<https://devfeed.tech/tags/identity.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [logs](<https://devfeed.tech/tags/logs.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

Microsoft's DART describes a scenario-driven incident-response readiness workshop that lets teams test their plans against simulated security incidents. It covers detection, investigation, containment, communication, threat hunting, and the use of tools, logs, and telemetry under pressure.

### Source excerpt

Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR Workshop: The workshop you shouldn't miss appeared first on Microsoft Security Blog.

## TerminalFix campaign deploys a reverse tunnel through multistage intrusion

DevFeed: [TerminalFix campaign deploys a reverse tunnel through multistage intrusion](<https://devfeed.tech/articles/terminalfix-campaign-deploys-a-reverse-tunnel-through-multistage-intrusion-7636.md>)

Original publisher: [Read original article](<https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/>)

Author: Microsoft Security Research, Sagar Patil, Suriyaraj Natarajan and Parasharan Raghavan

Published: 2026-08-29T03:43:27Z

Content type: article

Language: en

Sources: [Microsoft Security Blog](<https://devfeed.tech/sources/microsoft-security-blog.md>)

Topics: [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [c2](<https://devfeed.tech/tags/c2.md>), [clickfix](<https://devfeed.tech/tags/clickfix.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [python](<https://devfeed.tech/tags/python.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [security](<https://devfeed.tech/tags/security.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Microsoft analyzes the TerminalFix ClickFix campaign, which uses a fake Cloudflare CAPTCHA to induce PowerShell execution and deploys a multi-stage intrusion chain. The chain includes DLL sideloading, steganographic payload delivery, Active Directory reconnaissance, persistence, and an encrypted reverse tunnel that can provide access into the compromised network.

### Source excerpt

Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft Security Blog.