1. X
  2. Microsoft Threat Intelligence
Log inSign up
Microsoft Threat Intelligence
Microsoft Security
5,915 posts
Image
user avatar
Microsoft Threat Intelligence
Microsoft Security
@MsftSecIntel
We are Microsoft's global network of security experts. Follow for security research and threat intelligence.
Redmond, WA
aka.ms/threatintelblog
Joined November 2010
994
Following
196.2K
Followers
RepliesRepliesMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • user avatar
    Microsoft Threat Intelligence
    Microsoft Security
    @MsftSecIntel
    Jul 28
    Microsoft released security updates on July 14, 2026, to address CVE-2026-54121 (Certighost), an elevation-of-privilege vulnerability in Active Directory Certificate Services (AD CS). An authenticated, low-privileged attacker with network access could manipulate certificate
    Image
    25K
  • user avatar
    Microsoft Threat Intelligence
    Microsoft Security
    @MsftSecIntel
    Jul 23
    The continuing effects of Microsoft's disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques during Q2 of 2026 (April-June), including QR code phishing and CAPTCHA-gated phishing. msft.it/6017vA9QT At the same
    Image
    Email threat landscape: Q2 2026 trends and insights | Microsoft Security Blog
    From microsoft.com
    9.1K
  • user avatar
    Microsoft Threat Intelligence
    Microsoft Security
    @MsftSecIntel
    Jul 16
    Microsoft’s investigation into increased ACR Stealer activity surfaced two distinct intrusion paths that both begin with ClickFix, diverge in execution, but lead to the same outcome: the exfiltration of browser credentials, session tokens, and other sensitive data.
    Image
    ACR Stealer: Two observed intrusion chains amid increased threat activity | Microsoft Security Blog
    From microsoft.com
    18K
  • user avatar
    Microsoft Threat Intelligence
    Microsoft Security
    @MsftSecIntel
    Jul 16
    Microsoft has published an in-depth analysis of the AsyncAPI npm supply chain compromise, from CI/CD compromise to a multi-stage payload that executed at import time, bypassing common npm script-based defenses. Get technical info, along with detection & hunting guidance.
    Image
    Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery | Microsoft...
    From microsoft.com
    12K
  • user avatar
    Microsoft Threat Intelligence
    Microsoft Security
    @MsftSecIntel
    Jul 15
    “Developers are terraforming the battlefield that defenders have to fight on.” msft.it/6011vFIcv In this episode of the Microsoft Threat Intelligence Podcast, the authors of the new book “Threat-Driven Software Development: Defending Online Services from Modern Threat
    Image
    00:00
    13K
  • See @MsftSecIntel's full profile

    Sign up
    Log in
Advertisement
Advertisement