Microsoft details how Azure AD SSPR abuse led to Kubernetes credential theft
Microsoft reported in September 2026 that a threat actor known as Storm-3068 compromised a single Azure AD account. The attacker achieved this by abusing the self-service password reset feature after obtaining account recovery details. Using the compromised identity, they then moved through Azure DevOps pipelines to steal credentials for Kubernetes clusters. This allowed access to over 50 downstream resources without exploiting a software vulnerability. The incident highlights risks from overly broad permissions and the abuse of legitimate system features.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in