Il recovery di Microsoft Entra ID non è più una safety rail quando gli attacker possono trasformarlo in account takeover. In questa campagna, Storm-2949 usa self-service password reset e prompt di approvazione MFA per impossessarsi di account Microsoft 365 e Azure privilegiati, poi muoversi verso dati ad alto valore e cloud infrastructure.
Part of the PlainSec briefing for 2026-05-19
Every edition of this story: MFA and Password Reset Become the Attack Path