threat-intel Crook hawks millions of records allegedly plundered from corporate Azure tenants A group of Russian threat actors are exploiting vulnerabilities in Microsoft's on-prem SharePoint to steal corporate data. The attackers are impersonating Signal support to carry out phishing attacks, leveraging a zero-day vulnerability to gain access to sensitive information stored within Azure tenant environments. The Register · Aug 17, 2026 High RUzero-dayphishingdata breach
threat-intel Fortune 500 Companies Hit in Azure Data Theft Campaign A threat actor, known as ‘TheHatman’, is selling massive amounts of stolen data allegedly extracted from Azure tenants belonging to several Fortune 500 companies, including McDonald’s, Vodafone, and Wyndham Hotels. The d… SecurityWeek · Aug 17, 2026 High azurecredential theftdata breach
vulnerability Multiples vulnérabilités dans Microsoft Azure (12 août 2026) Multiple vulnerabilities have been discovered within Microsoft Azure, potentially allowing an attacker to elevate privileges, compromise data confidentiality, and bypass security policies. These vulnerabilities affect va… CERT-FR · Aug 12, 2026 High CVE-2026-47299CVE-2026-57104CVE-2026-65806azurevulnerabilitysecurity
vulnerability Vulnérabilité dans Microsoft Azure (31 juillet 2026) A critical vulnerability has been identified in Microsoft Azure's Cosmos DB, allowing attackers to execute arbitrary code remotely. This could lead to significant data compromise and system control for malicious actors. CERT-FR · Jul 31, 2026 Critical CVE-2026-66803azureremote code executiondatabase
vulnerability Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database A vulnerability in Azure Cosmos DB, dubbed CosmosEscape by Wiz, allowed an attacker to bypass the service's query sandbox and gain platform-wide access to customer databases. The exploit chain began with a crafted Gremli… The Hacker News · Jul 30, 2026 High azurecosmos dbsecurity
vulnerability Default Azure Automation Setting Enables Cross-Tenant Identity Takeover A critical vulnerability in Microsoft's Azure Automation service, stemming from a default public configuration for automation account identities, could have allowed attackers to take over another tenant's identity and ac… Dark Reading · Jul 24, 2026 Critical CVE-2025-29827identitycloudautomation
threat-intel Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents A vulnerability in Microsoft Azure DevOps's MCP server allows attackers to hijack AI coding agents by inserting hidden HTML comments in pull requests. These comments can then instruct the agent to perform actions – like… The Hacker News · Jul 22, 2026 High prompt-injectionai-riskmicrosoft
threat-intel Massive Password Spray Campaign Targeting Azure CLI A massive password spray campaign targeting Microsoft 365 environments, specifically the Azure CLI, was observed by Huntress. The attacks, originating from AS32167 and linked to LSHIY LLC, resulted in the compromise of o… SecurityWeek · Jul 1, 2026 High CHHOUScredential spraymfaoauth ropc
threat-intel Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts A massive, automated password spray attack targeting Microsoft's Azure CLI compromised at least 78 Microsoft accounts across 64 organizations. The attack leveraged a deprecated OAuth flow (ROPC) to bypass Conditional Acc… The Hacker News · Jul 1, 2026 High USCNpassword sprayropcconditional access
supply-chain Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories A sophisticated supply chain attack, orchestrated by the Miasma worm (a variant of Shai-Hulud), targeted 73 Microsoft GitHub repositories, primarily within the Azure organization. The attack, initially discovered through… Dark Reading · Jun 9, 2026 High supply chaingithubazure
threat-intel China Uses Dual-Method Cyberattack on Czech Orgs This article details a dual-method cyberattack targeting organizations in the Czech Republic and Taiwan, orchestrated by Chinese nation-state threat actors. The campaign, dubbed "Operation Dragon Weave," utilizes a spear… Dark Reading · Jun 2, 2026 High CZCNTWspear-phishingrustazure
threat-intel China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic & Taiwan A new cyber espionage campaign, dubbed Operation Dragon Weave, is targeting government, research, and financial institutions in the Czech Republic and Taiwan using spear-phishing emails and a Rust-based loader to deploy… The Hacker News · Jun 1, 2026 High CZTWINspear-phishingc2azure
threat-intel Cybercrime service disrupted for abusing Microsoft platform to sign malware Microsoft disrupted a malware-as-a-service (MaaS) operation, dubbed Fox Tempest, that was abusing its Artifact Signing service to generate fraudulent code-signing certificates for ransomware gangs and other cybercriminal… BleepingComputer · May 19, 2026 High USCAmsaascode signingfraudulent certificates