Intelligence Feed
View all threat intelligence
Microsoft Security Blog
—
SEV 3/10
May 14 18 min read Kazuar: Anatomy of a nation-state botnet Kazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard, has been under constant development for years and continues to evolve in support of espionage-focused operations.
Microsoft Defender
Microsoft Security Blog
—
SEV 3/10
May 14 18 min read Kazuar: Anatomy of a nation-state botnet Kazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard, has been under constant development for years and continues to evolve in support of espionage-focused operations.
Defending against advanced tactics
Microsoft Security Blog
—
SEV 4/10
May 1 6 min read CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments A high-severity Linux vulnerability, “Copy Fail” (CVE-2026-31431), enables root privilege escalation across cloud environments and Kubernetes workloads.
Threat actors
Microsoft Security Blog
—
SEV 3/10
May 14 18 min read Kazuar: Anatomy of a nation-state botnet Kazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard, has been under constant development for years and continues to evolve in support of espionage-focused operations.
Supply chain attacks
Microsoft Security Blog
—
SEV 3/10
April 1 16 min read Mitigating the Axios npm supply chain compromise On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages for version updates to download from command and control (C2) that Microsoft Threat Intelligence has attributed to the North Korean state actor Sapphire Sleet.
Cyberattacker techniques, tools, and infrastructure
Microsoft Security Blog
—
SEV 3/10
May 14 18 min read Kazuar: Anatomy of a nation-state botnet Kazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard, has been under constant development for years and continues to evolve in support of espionage-focused operations.
Threat intelligence
Microsoft Security Blog
—
SEV 3/10
May 14 18 min read Kazuar: Anatomy of a nation-state botnet Kazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard, has been under constant development for years and continues to evolve in support of espionage-focused operations.