[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fiXXjd8OtsbeS6Kvx9yWYWvE-dkD2L636PoyfsLU4l5E":3},{"article":4,"iocs":53,"watch_terms":54},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"5c87544b-f313-448e-a859-60db7ac7c584","Containing a domain compromise: How predictive shielding shut down lateral movement","containing-a-domain-compromise-how-predictive-shielding-shut-down-lateral-moveme-f66bbf","Domain compromise accelerates fast. Predictive shielding slowed it down. This real-world attack shows how exposure-based containment stopped credential abuse and broke the threat actor's momentum. The post Containing a domain compromise: How predictive shielding shut down lateral movement appeared first on Microsoft Security Blog.","Microsoft's Security Research Team documented a real-world domain compromise incident where predictive shielding technology successfully contained lateral movement and credential abuse. The post discusses exposure-based containment strategies that halted threat actor momentum during an attack. Additionally, the team uncovered a sophisticated macOS intrusion campaign by North Korean threat actor Sapphire Sleet that leverages social engineering and user-driven execution to bypass security controls and steal credentials and sensitive data.","Microsoft details domain compromise containment using predictive shielding against lateral movement.","April 16 25 min read Dissecting Sapphire Sleet’s macOS intrusion from lure to compromise The Microsoft Defender Security Research Team uncovered a sophisticated macOS intrusion campaign attributed to the North Korean threat actor Sapphire Sleet that abuses user driven execution and social engineering to bypass macOS security protections and steal credentials, cryptocurrency assets, and sensitive data.","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F04\u002F17\u002Fdomain-compromise-predictive-shielding-shut-down-lateral-movement\u002F","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002Fwp-content\u002Fuploads\u002F2026\u002F04\u002FMS_Actional-Insights_Access.png","2026-04-17T14:51:01+00:00","2026-04-17T16:00:24.461586+00:00",8,[18,21,24,27,30],{"name":19,"type":20},"Microsoft","vendor",{"name":22,"type":23},"Microsoft Defender","product",{"name":25,"type":26},"Sapphire Sleet","threat_actor",{"name":28,"type":29},"macOS","technology",{"name":31,"type":29},"Predictive Shielding","c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73",{"id":32,"icon":34,"name":35,"slug":36},null,"Incident Response","incident-response",[38,43,48],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":49},{"id":50,"icon":34,"name":51,"slug":52},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[],[19,22]]