Microsoft Threat Intelligence

@threatintel.microsoft.com

We are Microsoft's global network of security experts. Follow for security research and threat intelligence. https://aka.ms/threatintelblog

A single intrusion exposed parallel activity from two unrelated threat actors operating at the same time, blending tactics, obscuring signals, and enabling sustained access while masking the full scope of the compromise. msft.it/63326vqXMs

One intrusion, two cyberattackers: Uncovering parallel threat activity | Microsoft Security Blog

Microsoft DART uncovers dual threat actors in a single intrusion, revealing how blended tactics conceal attacks and complicate detection. Learn more.

msft.it

Microsoft has observed a supply chain attack targeting the Leo Platform/RStreams npm ecosystem. On June 24, 2026, at 23:04:55 UTC, a compromised maintainer account ("czirker") to publish malicious versions of 20+ npm packages in a coordinated, fully automated operation completed in under 3 seconds.

Graphic showing chains

Microsoft has identified a supply chain attack on the Mastra-AI npm ecosystem, with 80+ packages compromised via npm account takeover. The attacker introduced a phantom dependency into the compromised packages. The malicious dependency was published by a single anonymous maintainer <24 hours ago.

Image of supply chain attack

Threat actors are increasingly exploiting the hype around AI as social engineering lure in phishing, malvertising, and search-driven attacks. By impersonating trusted tools and services, they capitalize on user curiosity and urgency to improve success rates. msft.it/6019v5k6N

AI brands as bait: How threat actors are using the AI hype in social engineering | Microsoft Security Blog

As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure.

msft.it