Microsoft Security Blog discusses the implications when threat actors attempt to manipulate what AI systems remember and the emerging defenses against these attacks. Understanding these risks is crucial for securing AI-driven technologies.
Microsoft has attributed the recent Mastra AI supply chain attack, compromising over 140 npm packages, to the North Korean group Sapphire Sleet, aka BlueNoroff. This highlights ongoing state-sponsored supply chain risks affecting open source ecosystems.
Attackers compromised ShapedPlugin's build pipeline to inject backdoor code into Pro plugins via official update channels. This supply chain attack puts thousands of WordPress sites at risk of remote exploitation.