Minacce · 134 giorni fa
Il recovery di Microsoft Entra ID non è più una safety rail quando gli attacker possono trasformarlo in account takeover. In questa campagna, Storm-2949 usa self-service password reset e prompt di approvazione MFA per impossessarsi di account Microsoft 365 e Azure privilegiati, poi muoversi verso dati ad alto valore e cloud infrastructure.
1 fonte che coprono questa storia
Microsoft Self-Service Password Reset abused in Azure data theft attacks
A threat actor targeting Microsoft 365 and Azure production environments is stealing data in attacks that abuse legitimate applications and administration features.
Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-05-19