Tech News

RSS CVE Feed

RSS Microsoft Security

  • Turn specs into evals for any agent with ASSERT June 10, 2026
    Adaptive Spec-driven Scoring for Evaluation and Regression Testing (ASSERT) is an open-source framework for converting natural language behavior requirements into executable evaluations of AI models and agents. The post Turn specs into evals for any agent with ASSERT appeared first on Microsoft Security Blog.
    Mehrnoosh Sameki, Sandeep Atluri, Minsoo Thigpen and Abby Palia
  • Reconstructing AI activity in investigations  June 9, 2026
    Learn how to investigate AI activity in Microsoft 365 Copilot and Azure AI services using a structured, telemetry-driven approach. This playbook helps security teams reconstruct events, assess data exposure, and detect potential threats faster. The post Reconstructing AI activity in investigations  appeared first on Microsoft Security Blog.
    Phillip Misner and Microsoft AI Red Team
  • AI brands as bait: How threat actors are using the AI hype in social engineering June 8, 2026
    As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure. The post AI brands as bait: How threat actors are using the AI hype in social engineering appeared first on Microsoft Security Blog.
    Microsoft Threat Intelligence and Microsoft Defender Security Research Team
  • Securing CI/CD in an agentic world: Claude Code Github action case June 5, 2026
    Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This research examines the attack chain, responsible disclosure process, Anthropic's mitigation, and guidance for securing AI-powered CI/CD workflows. The post Securing CI/CD in an agentic world: Claude Code Github action case appeared first […]
    Microsoft Defender Security Research Team, Dor Edry and Amit Eliahu
  • Updating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught us  June 4, 2026
    A surge in real-world attacks against agentic AI systems is reshaping how we think about risk. Based on 12 months of red teaming, this update introduces seven new failure modes, from supply chain compromise to goal hijacking, and the practical mitigations teams need now. The post Updating the taxonomy of failure modes in agentic AI […]
    Microsoft AI Red Team