JadePuffer lets an AI agent run recon, credential theft, privilege escalation and resource deletion in Azure tenants, a dev.to analysis says. No operator pauses between the familiar steps, so cloud teams get less time between first access and deleted resources.
Reality
- Evidence20
- Adoption
- Insufficient
- Hype gap+20
- Incentives35
- Confidence20
Front Door, API Management and private networking cost about $1,730 a month in West Europe in a dev.to Container Apps reference stack for .NET. With the .NET compute at $20 to $140 a month, the risk sits in the hand-offs between its layers.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence40
AWS's CloudWatch Omni, generally available since September 23, lets Okta and Entra ID users investigate incidents without AWS console access. CloudWatch dashboard sharing has let outsiders view prebuilt graphs since 2020, so what Omni adds is the investigation itself, one of the reasons teams paid for third-party platforms.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence55
Microsoft's Defender Experts say Storm-3068 reset one user's password and ran an Azure DevOps pipeline authorized to reach more than 50 resources. It pulled the kubeconfig files that authenticate to a Kubernetes cluster.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+30
- Incentives
- Insufficient
- Confidence62
Microsoft will allow only scripts from its own CDN domains during Entra ID browser sign-ins under a Content Security Policy enforced from mid-October 2026. Browser extensions and tools that inject code into the sign-in page will stop working as the rollout completes in late October.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence70
Microsoft says Storm-3168 used a compromised service principal to delete Azure storage accounts, a Key Vault and an App Service plan in about seven minutes. The deletions ran on roles it already held, so role scope and locks had to exist before the credentials leaked.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Consent phishing, the most common OAuth entry point according to SC World, leaves a victim tenant three audit events and no app registration record. Registration monitoring misses it, so the hunt moves to consent and delegated-grant operations in the defender's own logs.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence55
A seller using the name TheHatman is offering employee directory exports from nine named enterprises. Hudson Rock ties the theft to infostealer credentials, not a compromise of the provider.
Perspective Coverage
5 publishers
- Builder
- Builder 25%
- Operator
- Operator 61%
- Investor
- Investor 14%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+30
- Incentives50
- Confidence60
Microsoft shipped 22 updates, six of them scored 10.0, mostly in Entra ID, Exchange Online and Azure. Fixed server-side is not the same as verified in your tenant.
Perspective Coverage
5 publishers
- Builder
- Builder 20%
- Operator
- Operator 65%
- Investor
- Investor 15%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+40
- Incentives55
- Confidence55
Detection at the first hop forced CISA's red team onto donated access at Organization B. It did not stop the team reaching the same sensitive systems it reached at Organization A.
Perspective Coverage
5 publishers
- Builder
- Builder 39%
- Operator
- Operator 53%
- Investor
- Investor 8%
Reality
- Evidence76
- Adoption
- Insufficient
- Hype gap+12
- Incentives35
- Confidence72
Arctic Wolf says the cluster it tracks as PREY-0058 deploys no malware at all. A call from fake IT leads to a proxied login page, and the stolen session token comes back from inside the victim's own ASN.
Perspective Coverage
3 publishers
- Builder
- Builder 17%
- Operator
- Operator 75%
- Investor
- Investor 8%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence60
Microsoft has tracked passkey- and SSO-themed help desk impersonation since May 2026, with the calls steering employees into adversary-in-the-middle proxies and device-code grants that hand over live Microsoft 365 sessions.
Perspective Coverage
6 publishers
- Builder
- Builder 28%
- Operator
- Operator 62%
- Investor
- Investor 10%
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+10
- Incentives45
- Confidence60
Microsoft told admins on Friday that SMS first-factor sign-in retires from February 2027, and that its own SMS and voice delivery ends on February 1, so tenants that want to keep phone codes must buy telephony elsewhere.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap0
- Incentives35
- Confidence74
A two-stage eval forces every shortlist to hold the correct tool plus its four strongest BM25 siblings. Selection accuracy comes in at 90 to 97 percent. That puts the 5 percent paraphrase recall on the critical path.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap0
- Incentives35
- Confidence55
Proofpoint tracked three waves of TeamFiltration password spraying against Microsoft 365 tenants in Chile between July 21 and August 16. The seven accounts that opened were all functional identities carrying provisioned passwords with no MFA.
Reality
- Evidence50
- Adoption60
- Hype gap+10
- Incentives65
- Confidence55
The AWS post co-written with HEMA says the structured half of its internal knowledge was already in good shape, and that the procedural half had little written documentation to fall back on.
Reality
- Evidence38
- Adoption42
- Hype gap+22
- Incentives78
- Confidence58
The September 2026 security updates leave affected tunnels stuck in Connecting. Microsoft's interim mitigation pins each profile to a single protocol and drops the fallback attempt while it works on a permanent fix.
Reality
- Evidence64
- Adoption42
- Hype gap+10
- Incentives46
- Confidence68
Varonis Threat Labs' TrustSink needs an already-compromised Global Administrator or Authentication Policy Administrator account. Once the method is registered in the Authentication Methods Policy, it keeps capturing passwords through resets.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+14
- Incentives68
- Confidence57
A dev.to post on healthtech workspace joining argues that DNS TXT challenges and mailbox confirmations prove different things, and the Go example it ships bounds DNS freshness at 24 hours while leaving the mailbox proof undated.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives20
- Confidence50
Calendar, People and Files stop working on December 16, 2026, and Microsoft has already stopped shipping them, leaving a removal job on fleets that took the apps automatically at the end of 2025.
Reality
- Evidence74
- Adoption46
- Hype gap+20
- Incentives58
- Confidence71
Earlier coverage
- Revoking the stolen tokens left GhostCode's Intune device inside the tenant
Leadership · September 20, 2026 · 1 publisher
- Defender for Identity scores dormant AD accounts against a 90-day logon threshold
Security · September 20, 2026 · 1 publisher
- Six OAuth steps run before an MCP client makes its first tool call
Build · September 18, 2026 · 1 publisher
- Protected Resource Metadata lets an MCP client discover the sign-in flow behind a 401 -- but Entra can still block the token
Build · September 18, 2026 · 1 publisher
- AWS runs four JWT claim gates in one Lambda before an MCP tool call reaches its data
Build · September 17, 2026 · 1 publisher
- MRH Trowe ran 400 employees on self-service agents for about $14 a seat in month one
Build · September 17, 2026 · 1 publisher
- Rolling back the update that broke RDS also removes September's 9.8-rated RDS fix
Build · September 14, 2026 · 1 publisher
- Oracle 26ai moves row and cell authorisation out of application code and into data grants
Build · September 14, 2026 · 1 publisher
- Windows 365 flags a Cloud PC Provisioned before Intune has installed Teams
Build · September 13, 2026 · 1 publisher
- An external app with user consent reads mail without holding an account in the tenant
Build · September 13, 2026 · 1 publisher
- Claude for Windows ships Entra Continuous Access Evaluation switched on by default
Build · September 10, 2026 · 1 publisher
- Session cookies outnumber plaintext passwords four to one in BigBear 2.0's panel
Leadership · September 10, 2026 · 1 publisher
- Scattered Spider talks help desks into moving MFA onto attacker-controlled devices
Security · September 9, 2026 · 1 publisher
- BigBear 2.0 breaks WebAuthn in the browser to force a relayable MFA fallback
Build · September 8, 2026 · 1 publisher
- Slim Spider lifted crypto custody keys out of a Brazilian bank's cloud secret manager
Security · September 8, 2026 · 1 publisher
- Flare puts 46 percent of corporate stealer-log credentials on likely unmanaged devices
Security · September 4, 2026 · 1 publisher
- A GTK app fetches the per-resource .rdp files FreeRDP needs to reach Azure Virtual Desktop
Build · September 4, 2026 · 1 publisher
- Microsoft patched an exploited Entra ID RCE on its own side of the tenant boundary
Security · August 28, 2026 · 1 publisher
- NovaCookies turns an MFA approval into a live Microsoft 365 session for $320
Build · August 27, 2026 · 1 publisher
- Same-day GPT-5.6 on Azure kills the parity argument, leaving auth and residency to decide
Build · August 25, 2026 · 1 publisher
- Bind the consent policy, not the admin role: Entra's answer to the agent consent queue
Build · August 25, 2026 · 1 publisher
- Kubernetes Secrets are a distribution problem, and the database is where it shows
Product · August 24, 2026 · 1 publisher
- Enterprise security reviews went from 20 questions to hundreds of rows, and vendors pay first
Leadership · August 21, 2026 · 1 publisher
- A CVSS 10.0 RCE in Entra ID was exploited in the wild, and there was nothing to patch
Security · August 21, 2026 · 1 publisher
- CrowdStrike buys SGNL, and standing privilege becomes a line item you have to defend
Leadership · August 20, 2026 · 1 publisher
- 81 million attempts, 78 accounts: ROPC is where "we have MFA" stops being true
Build · August 19, 2026 · 1 publisher
- AWS moves agent authorization out of the agent and into the plumbing
Build · August 19, 2026 · 1 publisher
- "Work PC" beats DESKTOP-XXXXXXXX: Entra device-join detection needs a new anchor
Security · August 18, 2026 · 1 publisher
- Storm-0501's first move is deleting your resource locks, not encrypting your disks
Security · August 18, 2026 · 1 publisher
- Cavern's DNS Coin-Flip: When Google Apps Script Becomes Rotatable C2 Plumbing
Security · August 18, 2026 · 1 publisher
- Three permission problems wearing one service principal: why published agents return 403
Build · August 15, 2026 · 1 publisher