Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
FBI Operation Blackout Dismantles Overseas Scammers Targeting Americans
September 30, 2026
Critical Azure DevOps and Kubernetes Flaw Exposes Cloud Environments
September 30, 2026
Vectra AI Now Monitors Claude AI Chats, Files, and Agent Activity
September 30, 2026
Home/Threats/Critical Azure DevOps and Kubernetes Flaw Exposes Cloud Environments
Threats

Critical Azure DevOps and Kubernetes Flaw Exposes Cloud Environments

Key Takeaways A single compromised account can lead to extensive cloud environment breaches, including Azure DevOps and Kubernetes resources. The attack, attributed to Storm-3068, leveraged...

David kimber
David kimber
September 30, 2026 3 Min Read
3 0

Key Takeaways

  • A single compromised account can lead to extensive cloud environment breaches, including Azure DevOps and Kubernetes resources.
  • The attack, attributed to Storm-3068, leveraged legitimate administrative tools and existing access rights rather than exploiting software vulnerabilities or custom malware.
  • Initial access was gained through a self-service password reset, followed by the attacker registering their own authentication methods for persistent access.
  • The incident highlights the critical importance of securing development pipelines and cloud environments, as they can provide a direct path to sensitive data and infrastructure.
  • Organizations must implement robust security measures, including phishing-resistant MFA, least-privilege access, and stringent code review processes.

A recent security incident has brought to light a critical vulnerability in cloud environments, demonstrating how a single compromised user account can serve as a gateway to an organization’s entire cloud infrastructure, encompassing Azure DevOps, development pipelines, and Kubernetes resources. This sophisticated attack did not rely on novel software flaws or bespoke malware but instead exploited the inherent trust within an organization’s everyday services and existing access rights.

Table Of Content

  • Key Takeaways
  • Hackers Turn One Compromised Account Into Access
  • Cloud Access

Investigators uncovered a method where an attacker moved from a simple password recovery process to gaining deep access into critical development and operational systems. This path allowed the intruder to access source code, deployment configurations, and infrastructure credentials, effectively turning routine access into a major breach.

Microsoft’s security analysts, who identified the threat actor as Storm-3068, determined that the initial compromise stemmed from the takeover of an account via a self-service password reset. According to Microsoft in a report, the attacker solidified their foothold by registering their own authentication methods, thereby securing persistent access to the compromised identity.

This incident underscores the increasing attractiveness of development systems as targets for cyber adversaries. Similar attacks, though involving different threat actors, have previously abused legitimate cloud features within Microsoft Entra ID accounts. In this specific case, the interconnected nature of repositories, automation pipelines, and various cloud resources significantly amplified the impact of the initial account compromise.

Hackers Turn One Compromised Account Into Access

Upon successfully compromising the initial account, Storm-3068 proceeded to utilize legitimate administrative tools and automated scripts to meticulously examine Azure DevOps projects, repositories, pipelines, and deployment environments. This reconnaissance phase was crucial for the intruder to understand the interconnectedness of systems and identify locations where valuable credentials might reside. Azure DevOps proved particularly useful due to its integrated nature, bridging software development and cloud operations.

Unlike other incidents, such as a separate Azure DevOps MCP flaw that exploited specific vulnerabilities, this intrusion leveraged an account’s existing permissions. The attacker systematically mapped trusted deployment paths and connected resources, effectively exploiting the organization’s own architecture.

Following the reconnaissance, the threat actor engineered a malicious pipeline designed for large-scale collection of Kubernetes credentials. This involved deploying a kube agent and executing multiple jobs aimed at extracting cluster configuration files. These files contained vital connection details and authentication information necessary to access targeted Kubernetes resources, as detailed in the investigation report. Microsoft confirmed that the attacker deployed a pipeline capable of accessing over 50 resources and authenticating to various services. Ultimately, seven stolen cluster configuration files were found to have been added to a repository, providing the necessary credentials to access the targeted Kubernetes clusters.

This sequence of events illustrates that development platforms can expose far more than just source code. Repositories, service connections, and deployment settings effectively create a detailed roadmap into an organization’s broader IT environment. This allows an attacker to broaden their access by exploiting trusted relationships already established within the business, as highlighted by Microsoft.

Cloud Access

Beyond credential harvesting, Storm-3068 further escalated its access by modifying pipeline scripts to install the Atera remote management agent and download the Chisel tunneling utility. Investigators concluded these actions were aimed at establishing alternative remote-access channels and exposing the Kubernetes API server for potential direct interaction with the clusters, according to Microsoft.

Chisel commands were used to create a reverse tunnel to an external IP address, though the specific address was not disclosed in the provided information. The detailed intrusion was meticulously reconstructed through an analysis of Azure DevOps audit logs and Git version history, which also helped identify the stolen credentials deposited in the repository, as documented in the <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/8914cb25-f2e-471c-b190-86fa64e15983/Hackers-Turn-One-Compromised-Account-Into-Access-to-Azure-DevOps-and-Kubernetes.pdf?AWSAccessKeyId=ASIA2F3EMEYEZJDBJDDK&Signature=DM0cLQ63WF0RAe6uoG2Rbt5m2bM%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEJv%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIBhfy4xvDSD8ElqcIZNVEC14oU%2FkfCrVpiOpw8DxlBxYAiEA4b5SdTh%2B72%2FyZ1dVtpgx%2FVcECJHsJ00%2B3qeLO%2BLeZl8q%2BgQIYxABGgw2OTk3NTMzMDk3MDUiDA%2B%2BxvbVySrfZpyXTSrXBKhLNmGGjklZ8l%2BN7ffBVt0i0md5xtRr119vCjz5xvkxkqtZHYtjwh%2FgwbKRvcShJeWN%2Big0ldWJGSQt2x8eqIBcE1Xcoe6LcsrEwUM81KRIf2OApUTaun1agQP1rgXtYBq29z2Ui78dICaaCDTfZM7hElCbCz8ypKiLSRs9fMgLHpPn37lrLmuQQKVGs37O949GjAnhDkMNMVAskfVf%2F8x5IBgfIIYSmeDWN0v7uzZT3ZapFYCLBWw7XUvx%2BeLdrXD8Y5OY0yWC8ocwMur94a4WuGpEUilzzsaS84k7fRNdyElUiTlq3TsVkgy3rtL31GZbMSiD6xhYI1RnELSeYOe02PUE6YxPpZugIZkU8RG121qtejnjw5a3dooa3UqzXLuFyk5thtcTMt6LkAFGife0I%2BNZIFsbKmCQGFLsnSyv2GDrzTWFSz%2Bx59QKJ%2BlGG1E0cXbVSDcNWgYIHBo1IMWy57riYfkWjJ3PiYRZA2wyHu6Hk8GWjK7eGt6yf2D%2BNdI6ZYTZFgobTPa58EAoAFHgyup9tQpfvWSKQP8K2jBOaOClfCZV8xVi531KOHk%2FwZD4Zgk8ybFOg5F9YUIFKJc0UdakOWN6zzNq5g9Y%2BlCXWT%2Fa50yKuT%2BZbA%2FsThmhESx3q7Iu4Z3Jlv%2FC9eAd0F9lXqaQrOv2

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarephishingSecurityThreat

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Vectra AI Now Monitors Claude AI Chats, Files, and Agent Activity

Next Post

FBI Operation Blackout Dismantles Overseas Scammers Targeting Americans

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
OperTraitors Tool Exposes Critical Kubernetes Privilege Escalation Paths
September 30, 2026
AI Agent Discovers Critical Linux Kernel Vulnerability CVE-2023-XXXX
September 30, 2026
Critical RCE in Unsloth Studio Lets Malicious Hugging Face Models Execute Code
September 30, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us