// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-wedgDTG 0600Z
ColdRecon / Breach Radar / Microsoft
Breach Record

Microsoft

DISCLOSED 2026-08-20 · UNKNOWN

Cisco Talos reports that Chinese-speaking cybercrime group UAT-10147 is using AI-generated playbooks and automation to compromise Windows and Linux web servers, turning them into a repeatable criminal operation. The group adds Microsoft Defender exclusions on compromised Windows IIS servers to evade detection. This highlights the use of AI in crafting attack playbooks and...

The record

What we know

Disclosed
2026-08-20
Sources

Cited reporting

This page is the permanent ColdRecon entry for the Microsoft disclosure. It updates if new public reporting emerges. All tracked breaches →

Microsoft just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →