Stolen Azure identities let automated attackers erase cloud assets
Daily Cyber News: Stolen Azure identities let automated attackers erase cloud assets
Attackers targeted cloud data and recovery controls after compromising two Azure service principals in the same tenant. One identity handled reconnaissance, while the other performed discovery, collected credentials, and carried out destructive operations. The destructive stage lasted seven minutes and targeted more than 100 storage accounts, along with a Key Vault, Function Apps, Virtual Machines, and App Services.
Key context: Because these were valid application identities, the destructive activity could resemble normal cloud administration.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, Stolen Azure, Stolen, Azure, identities, automated, attackers, erase.