⤷ Title: How Storm-0501 is Pivoting to Cloud-Native Attacks
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 04:17:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Azure #cloud security #cybersecurity #Entra ID #hacking #Microsoft Threat Intelligence #ransomware #Storm_0501
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 04:17:45 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Azure #cloud security #cybersecurity #Entra ID #hacking #Microsoft Threat Intelligence #ransomware #Storm_0501
Penetration Testing Tools
How Storm-0501 is Pivoting to Cloud-Native Attacks
A new Microsoft report reveals that the Storm-0501 threat actor is pivoting to cloud-native ransomware, using cloud tools to exfiltrate and destroy data without malware.
⤷ Title: Malware-less Ransomware: How Storm-0501 is Pivoting to Cloud-Native Attacks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:24:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Azure #Cloud Security #cybersecurity #Entra ID #Hacking #Microsoft Threat Intelligence #ransomware #Storm_0501
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 29 Aug 2025 00:24:09 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Azure #Cloud Security #cybersecurity #Entra ID #Hacking #Microsoft Threat Intelligence #ransomware #Storm_0501
Daily CyberSecurity
Malware-less Ransomware: How Storm-0501 is Pivoting to Cloud-Native Attacks
A new Microsoft report reveals that the Storm-0501 threat actor is pivoting to cloud-native ransomware, using cloud tools to exfiltrate and destroy data without malware.
⤷ Title: Snowflake External OAuth: Authorization Code flow (+PKCE)
════════════════════════
𐀪 Author: Mike Mitrowski
════════════════════════
ⴵ Time: Sat, 13 Sep 2025 02:07:32 GMT
════════════════════════
⌗ Tags: #entra_id #cybersecurity #snowflake #oauth2 #authorization
════════════════════════
𐀪 Author: Mike Mitrowski
════════════════════════
ⴵ Time: Sat, 13 Sep 2025 02:07:32 GMT
════════════════════════
⌗ Tags: #entra_id #cybersecurity #snowflake #oauth2 #authorization
Medium
Snowflake External OAuth: Authorization Code flow (+PKCE)
Snowflake External OAuth: Authorization Code flow (+PKCE) Note: The example below creates an authorization URL, and retrieves a valid token from the token endpoint in Entra ID. Please reference …
⤷ Title: Microsoft Averts Mass Cloud Takeover Due to Azure Flaw
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 21 Sep 2025 09:37:23 +0000
════════════════════════
⌗ Tags: #Vulnerability #Azure #cloud security #CVE_2025_55241 #cybersecurity #Entra ID #Microsoft #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sun, 21 Sep 2025 09:37:23 +0000
════════════════════════
⌗ Tags: #Vulnerability #Azure #cloud security #CVE_2025_55241 #cybersecurity #Entra ID #Microsoft #vulnerability
Penetration Testing Tools
Microsoft Averts Mass Cloud Takeover Due to Azure Flaw
A researcher uncovered two flaws in Microsoft's Entra ID that, when combined, could have allowed attackers to take over any Azure tenant with global admin privileges.
⤷ Title: Microsoft Fixed Entra ID Vulnerability Allowing Global Admin Impersonation
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 23 Sep 2025 21:23:40 +0000
════════════════════════
⌗ Tags: #Security #Azure #Black Hat #Cybersecurity #def con #Entra ID #Microsoft #Vulnerability #Zero Trust
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 23 Sep 2025 21:23:40 +0000
════════════════════════
⌗ Tags: #Security #Azure #Black Hat #Cybersecurity #def con #Entra ID #Microsoft #Vulnerability #Zero Trust
Hackread
Microsoft Fixed Entra ID Vulnerability Allowing Global Admin Impersonation
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: Microsoft’s New Internet ‘Super-Shield’: Explaining Entra Global Secure Access in Simple Terms
════════════════════════
𐀪 Author: Janith Sandamal
════════════════════════
ⴵ Time: Sat, 27 Sep 2025 09:15:12 GMT
════════════════════════
⌗ Tags: #cybersecurity #microsoft #global_secure_access #entra_internet_access #entra_private_access
════════════════════════
𐀪 Author: Janith Sandamal
════════════════════════
ⴵ Time: Sat, 27 Sep 2025 09:15:12 GMT
════════════════════════
⌗ Tags: #cybersecurity #microsoft #global_secure_access #entra_internet_access #entra_private_access
Medium
Microsoft’s New Internet ‘Super-Shield’: Explaining Entra Global Secure Access in Simple Terms
Imagine your company is a highly secure, important castle.In the old days, everyone worked inside the castle walls.
⤷ Title: Tuesday Morning Threat Report: Sept 30, 2025
════════════════════════
𐀪 Author: Mark Maguire
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 00:14:36 GMT
════════════════════════
⌗ Tags: #entra_id #iam_roles #cybersecurity #agentic_ai #darkweb
════════════════════════
𐀪 Author: Mark Maguire
════════════════════════
ⴵ Time: Tue, 30 Sep 2025 00:14:36 GMT
════════════════════════
⌗ Tags: #entra_id #iam_roles #cybersecurity #agentic_ai #darkweb
Medium
Tuesday Morning Threat Report: Sept 30, 2025
The “most severe cloud identity vulnerability ever” found in Microsoft Entra and MI6 launches a dark web portal to recruit new spies
⤷ Title: Microsoft Warns: Threat Actors Turn Microsoft Teams into a Weapon for Ransomware, Espionage, and Social Engineering
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Oct 2025 00:11:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #Collaboration Security #Entra ID #Microsoft Teams #Microsoft Threat Intelligence #ransomware #reconnaissance #TeamsPhisher
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Oct 2025 00:11:53 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #Collaboration Security #Entra ID #Microsoft Teams #Microsoft Threat Intelligence #ransomware #reconnaissance #TeamsPhisher
Daily CyberSecurity
Microsoft Warns: Threat Actors Turn Microsoft Teams into a Weapon for Ransomware, Espionage, and Social Engineering
Microsoft Threat Intelligence details how APTs abuse Teams and Entra ID integration for recon, vishing, and C2. Attackers use RMM tools and spoofed accounts to breach enterprise environments.
⤷ Title: Microsoft Teams: New Report Exposes How APTs and Ransomware Groups Weaponize Collaboration Features to Breach Enterprises
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:35:43 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #cybersecurity #Entra ID #Microsoft Teams #Microsoft Threat Intelligence #ransomware #Social Engineering #TeamsPhisher
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 10 Oct 2025 03:35:43 +0000
════════════════════════
⌗ Tags: #Cybercriminals #APT #cybersecurity #Entra ID #Microsoft Teams #Microsoft Threat Intelligence #ransomware #Social Engineering #TeamsPhisher
Penetration Testing Tools
Microsoft Teams: New Report Exposes How APTs and Ransomware Groups Weaponize Collaboration Features to Breach Enterprises
Microsoft Threat Intelligence details how APTs and ransomware groups abuse Teams and Entra ID integration for recon, malware distribution, persistence, and C2 through chat messages.
⤷ Title: Critical Blunder: HP Update Bricks Corporate Laptops By Deleting Cloud Certs
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 08:49:14 +0000
════════════════════════
⌗ Tags: #Technology #cybersecurity #Entra ID #HP OneAgent #IT Disaster #Microsoft #windows
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 28 Oct 2025 08:49:14 +0000
════════════════════════
⌗ Tags: #Technology #cybersecurity #Entra ID #HP OneAgent #IT Disaster #Microsoft #windows
Penetration Testing Tools
Critical Blunder: HP Update Bricks Corporate Laptops By Deleting Cloud Certs
A flawed HP OneAgent update inadvertently deleted critical Entra ID system certificates on corporate laptops, severing them from the cloud and requiring manual recovery.