chiprook
← Security
SecuritySeptember 30, 2026, 11:07

Storm-3068 hijacked account via SSPR and stole Kubernetes credentials

Microsoft Defender Experts detailed an attack by Storm-3068: a self-service password reset (SSPR) let the actor take over a user identity, register an attacker device in Intune and add their own MFA while removing the victim's. Via Azure DevOps they ran a pipeline authorized for 50+ resources, pulled 7 kubeconfig files and deployed the Atera agent and a Chisel tunnel.

Storm-3068 hijacked account via SSPR and stole Kubernetes credentials
#Microsoft#Azure#Kubernetes#Intune
Read next
Security

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Security

GhostCode attackers abuse device codes to take over Microsoft 365 accounts

Security

Arizona Supreme Court says hackers stole residents' personal data

Security

Bitget says attacker stole $388M via third-party security flaw