Microsoft says Storm-3168 used a compromised service principal to delete Azure storage accounts, a Key Vault and an App Service plan in about seven minutes. The deletions ran on roles it already held, so role scope and locks had to exist before the credentials leaked.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Consent phishing, the most common OAuth entry point according to SC World, leaves a victim tenant three audit events and no app registration record. Registration monitoring misses it, so the hunt moves to consent and delegated-grant operations in the defender's own logs.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence55
A seller using the name TheHatman is offering employee directory exports from nine named enterprises. Hudson Rock ties the theft to infostealer credentials, not a compromise of the provider.
Perspective Coverage
5 publishers
- Builder
- Builder 25%
- Operator
- Operator 61%
- Investor
- Investor 14%
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+30
- Incentives50
- Confidence60
Two months of AWS audit logs from 125 environments went through UMAP and HDBSCAN to group more than 40,000 identities by what they actually did, and the classification rules that fell out run in plain SQL.
Reality
- Evidence45
- Adoption18
- Hype gap+20
- Incentives80
- Confidence60
Microsoft has tracked intrusions since May in which callers posing as IT told employees a passkey update was due, then steered them to a phishing page or a device-code prompt. The enrollment step is where the chain starts.
Reality
- Evidence55
- Adoption35
- Hype gap−5
- Incentives60
- Confidence58
Microsoft has tracked this since May 2026. First contact lands on an unmanaged personal phone, and the attacker's own authenticator outlives the stolen session, so tenant telemetry only starts after the account is already lost.
Reality
- Evidence55
- Adoption45
- Hype gap−10
- Incentives65
- Confidence58
CVE-2026-69836 scored 10.0 and allowed unauthenticated remote code execution against Microsoft's identity service, and because the fix landed server-side, no customer ever had a version to check or a window to schedule.
Reality
- Evidence28
- Adoption15
- Hype gap−35
- Incentives
- Insufficient
- Confidence30
Microsoft says CVE-2026-69836 is fully mitigated and needs no customer action. It has not said who exploited it, when it started, or how many tenants were touched.
Reality
- Evidence52
- Adoption
- Insufficient
- Hype gap+14
- Incentives72
- Confidence46