MFA and Password Reset Become the Attack Path

Il recovery di Microsoft Entra ID non è più una safety rail quando gli attacker possono trasformarlo in account takeover. In questa campagna, Storm-2949 usa self-service password reset e prompt di approvazione MFA per impossessarsi di account Microsoft 365 e Azure privilegiati, poi muoversi verso dati ad alto valore e cloud infrastructure.

Part of the PlainSec briefing for 2026-05-19

Editions

Sources