About 214 results
Open links in new tab
  1. Nation-state threat actor Mint Sandstorm refines tradecraft to attack ...

    Apr 18, 2023 · A mature subgroup of Mint Sandstorm is weaponizing N-day vulnerabilities in apps & conducting phishing campaigns to access environments.

  2. Kazuar: Anatomy of a nation-state botnet - microsoft.com

    May 14, 2026 · Kazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard, has been under constant development for years and continues to evolve in support of …

  3. Midnight Blizzard: Guidance for responders on nation-state attack ...

    Jan 25, 2024 · Microsoft detected a nation-state attack on our corporate systems and immediately activated response process to disrupt and mitigate.

  4. Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise

    Apr 16, 2026 · Microsoft Threat Intelligence identified a campaign beginning in early 2026 by North Korean state actor Sapphire Sleet demonstrating new combinations of macOS-focused execution …

  5. Frozen in transit: Secret Blizzard’s AiTM campaign against diplomats ...

    Jul 31, 2025 · Microsoft Threat Intelligence has uncovered a cyberespionage campaign by the Russian state actor we track as Secret Blizzard that has been ongoing since at least 2024, targeting …

  6. What Is SIEM? | Microsoft Security

    Security information and event management (SIEM) is a security solution that collects data and analyzes activity to support threat protection for organizations.

  7. Code injection attacks using publicly disclosed ASP.NET machine keys

    Feb 6, 2025 · Microsoft Threat Intelligence observed limited activity by an unattributed threat actor using a publicly available, static ASP.NET machine key to inject malicious code and deliver the Godzilla …

  8. Microsoft Digital Defense Report shares new insights on nation-state ...

    Oct 25, 2021 · Learn about targets and methods used by today’s nation-state threat actors, and how your organization can create a more secure environment.

  9. Intelligence Reports | Security Insider - microsoft.com

    Explore threat intelligence reports on nation-state, cybercrime, and threat actors based on trillions of signals analyzed by Security Insider researchers.

  10. New Russia-affiliated actor Void Blizzard targets critical sectors for ...

    May 27, 2025 · Microsoft Threat Intelligence has discovered a cluster of worldwide cloud abuse activity conducted by a threat actor we track as Void Blizzard, who we assess with high confidence is Russia …