All updates
security: ACR Stealer: Two observed intrusion chains amid increased threat activity
Jul 16, 2026
Microsoft Defender Experts observed increased ACR Stealer activity from late April to mid-June 2026 across customer environments. The campaigns used ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments.
- Source: Microsoft Security Blog