Storm-2949 (May 2026): From a Fake IT Call to an Azure-Wide Breach
On May 18, 2026, Microsoft Threat Intelligence published details of Storm-2949, a threat actor that turned a single social-engineered identity into a breach...
Service
Measure your Azure subscriptions against Microsoft's Cloud Adoption Framework and Cloud Security Benchmark.
Subscriptions built project by project accumulate broad Owner rights, public endpoints and storage accounts that allow shared keys. Identity-led attacks now use exactly those permissions to move from one compromised account to databases, secrets and virtual machines.
Organizations running production workloads in Azure without an enforced landing zone.
Yes. We include Azure Arc–connected servers and hybrid identity links in scope when relevant.
On May 18, 2026, Microsoft Threat Intelligence published details of Storm-2949, a threat actor that turned a single social-engineered identity into a breach...
Storm-2949 moved from a social-engineered password reset to Azure-wide control using RBAC permissions and VM management features. Here is how to harden each...
From October 15, 2024, Microsoft began enforcing MFA for the Azure portal, Entra admin center and Intune admin center, and from 2025 for Azure CLI, PowerShell and infrastructure-as-code tools. Here is what it covers, what breaks, and how to migrate automation to workload identities.