Storm-2949 (May 2026): From a Fake IT Call to an Azure-Wide Breach
On May 18, 2026, Microsoft Threat Intelligence published details of Storm-2949, a threat actor that turned a single social-engineered identity into a breach...
On May 18, 2026, Microsoft Threat Intelligence published details of Storm-2949, a threat actor that turned a single social-engineered identity into a breach...
Storm-2949 moved from a social-engineered password reset to Azure-wide control using RBAC permissions and VM management features. Here is how to harden each...
From October 15, 2024, Microsoft began enforcing MFA for the Azure portal, Entra admin center and Intune admin center, and from 2025 for Azure CLI, PowerShell and infrastructure-as-code tools. Here is what it covers, what breaks, and how to migrate automation to workload identities.
A single Azure SAS token in a public GitHub repository exposed 38TB of Microsoft data, including 30,000+ Teams messages, for nearly three years. Here is the timeline, why SAS tokens are hard to govern, and how to remove the risk.
Storm-2949's attack produced signals across Entra ID, Azure Activity, Key Vault and endpoints. These detections connect them.
The short version: In May 2026, Microsoft described an attack group, Storm-2949, that started by tricking employees into approving fake login requests...
At Microsoft Ignite in November 2024, security announcements centered on resilience and exposure. Two stood out: the Windows Resiliency Initiative, a...
Not all vulnerabilities and misconfigurations matter equally. Attack path analysis shows which ones an attacker could chain to reach your critical assets....
Use this checklist to start an exposure management program with Microsoft Defender tools.
The short version: Security teams are drowning in alerts and vulnerability lists. In 2024, Microsoft and other vendors pushed a different approach:...
Microsoft's mandatory MFA for Azure breaks automation that signs in as a user with a password. Here is how to find and migrate those service accounts.
Use this checklist to confirm your organization is ready for Azure's mandatory MFA.
The short version: Since October 2024, Microsoft requires multi-factor authentication for anyone managing Azure through its web portals, and from 2025 also...
SAS tokens grant time-limited access to Azure Storage — but poorly scoped tokens can expose entire accounts for years. Here is how to govern them and remove...
Overly permissive or leaked SAS tokens provide direct access to Azure Storage. These detections help find token exposure and misuse.
The short version: In 2023, Microsoft's own AI researchers accidentally exposed 38 terabytes of internal data — including passwords and private messages —...
In October 2022, threat intelligence company SOCRadar reported a data leak it called BlueBleed: a misconfigured Microsoft-owned Azure Blob Storage container...
Azure Storage accounts can be exposed through anonymous blob access, overly permissive shared keys and SAS tokens, or public network endpoints. Here is how...
Public Azure Blob access is often discovered by outsiders scanning for open containers. Detecting both the configuration and anonymous access helps you find...
The short version: In 2022, researchers reported that a misconfigured Microsoft storage location exposed business documents involving Microsoft's customers....
At Microsoft Ignite in November 2021, Microsoft combined Azure Security Center and Azure Defender into a single product: Microsoft Defender for Cloud. It...
Defender for Cloud's secure score measures how many security recommendations you've implemented. Here is a 30-day plan to raise it meaningfully — focusing...
Defender for Cloud includes a free foundational tier and several paid plans. Use this checklist to decide which to enable and keep costs predictable.
The short version: In 2021, Microsoft combined its Azure security tools into Defender for Cloud, promising one dashboard for security across Azure, AWS and...