Microsoft open-source packages were compromised with a self-replicating credential stealer that activates inside AI coding agents, marking the second supply-chain attack on the company’s repositories in recent weeks. The campaign exploited legitimate OIDC tokens and SLSA provenance to bypass detection and target cloud identities.

This marks the second supply-chain attack on a Microsoft repository in as many months.
https://x.com/arstechnica/status/2064054101806297189
Instead, it exploits the underlying trust model of the modern engineering ecosystem.
The repeated compromise of Microsoft maintainer credentials shows that even cryptographically verified supply chains remain vulnerable when identity hygiene fails.
Tap a lens to see what this story means for you.
Liked this? The Brief brings you the whole day in tech, verified, every morning.
Two minutes, free forever. What's in The Brief →
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Microsoft Dataverse is affected by critical vulnerability CVE-2026-88131, which allows remote code execution. The flaw scores 9.8 on CVSS; Microsoft says it has already fully mitigated it and customers have nothing to patch.
The first laptops built on Nvidia's RTX Spark chip, from Microsoft, Asus, Dell, HP, Lenovo and MSI, start at $2,599 and climb to $6,999.99 for a maxed-out Asus ProArt P16 with 128GB of unified memory, The Verge reports. The first models ship as early as October 16.
Meta and Microsoft are cutting employee use of Anthropic’s Claude AI and directing staff toward their own coding tools, The Information reported. The changes reflect tighter internal AI budgets while customer access to Claude through Microsoft platforms continues to expand.
Microsoft has introduced a local edition of MAI-Code-1.1-Flash that runs on Windows PCs without server access. The model requires substantial memory and is coming to GitHub Copilot in experimental preview by the end of October, starting with Nvidia RTX Spark PCs.
At its Windows and Surface event, Microsoft opened preorders for the $2,599 Surface Laptop Ultra and the $5,999 Surface RTX Spark Dev Box, and said Copilot will be able to use files and act across Windows in the coming months.