Tuesday , September 29 2026
Entra ID

Hackers Exploit Entra ID Accounts to Steal Microsoft 365, Azure Data

Hackers misuse Microsoft Entra ID accounts to steal data from Microsoft 365 and Azure. A very advanced cyberattack by a group called Storm-2949 is aiming at Microsoft Entra ID accounts to take sensitive data from Microsoft 365 and Azure.

Storm-2949 used real cloud management tools to get deep access to SaaS, PaaS, and IaaS environments instead of using harmful payloads.

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

The 5th Edition of InfoSecCon-2026, a premier cybersecurity-focused event, has been successfully completed with the participation of cybersecurity professionals, technology...
Read More
“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

The attack started with focused social tricks aimed at important users, like IT workers and top managers. The bad actor took advantage of Microsoft’s Self-Service Password Reset (SSPR) by deceiving users into agreeing to multifactor authentication (MFA) requests.

Attackers pretended to be IT support staff and got victims to approve MFA requests by saying they were checking accounts.

Microsoft says the attack shows a rising trend in cloud attacks, where hackers focus more on stealing identities than using usual malware.

Once they got approval, the attackers changed passwords, took away existing login methods, and set up their own MFA devices. This locked out real users while they kept access.

Hackers Exploit Entra ID

After getting in, Storm-2949 quickly started taking data from Microsoft 365 services, like OneDrive and SharePoint.

Storm-2949 attack diagram (Source : Microsoft).

The attackers aimed at important files like VPN setups and remote access steps, showing they were ready to move laterally.

Detection and Defense

Microsoft Defender was key in finding the attack by linking signals from identity, cloud, and endpoint areas. This shows how important integrated detection systems are for cloud security today.

This campaign shows a change to attacks focused on identity in cloud systems. By misusing real admin tools, attackers can work quietly with few signs of a breach.

Organizations are advised to:

Strengthen MFA steps and watch for strange approvals.
Limit RBAC permissions by using the least access needed.
Keep an eye on Microsoft Graph API activity for odd queries.
Secure Key Vault access and check how secrets are used.
Activate cross-domain detection with tools like Microsoft Defender XDR.

As more people use the cloud, protecting identity and access is very important to stop big data breaches.

Indicators of compromise (IOCs):

Indicator Type Description
176.123.4[.]44 IP address Attacker egressed from this address
91.208.197[.]87 IP address Attacker egressed from this address
185.241.208[.]243 IP address ScreenConnect instance used by Attacker

Check Also

Casbaneiro

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent …