Skip to content
Storm-3068 Exploits Azure DevOps for Kubernetes Credential Theft

Storm-3068 Exploits Azure DevOps for Kubernetes Credential Theft

First seen 29 Sep 2026, 19:12 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 18:35 UTC
  • •Storm-3068 exploited Azure DevOps to gain Kubernetes credentials.
  • •The attack involved modifying pipeline scripts to deploy malicious tools.
  • •DART provided rapid response and remediation recommendations.

On September 29, 2026, Microsoft reported an intrusion by the threat actor Storm-3068, which gained access to a user account via a self-service password reset. The attacker then took control of the identity and targeted Azure DevOps to enumerate repositories and deployment environments. A malicious pipeline was created to harvest Kubernetes credentials at scale, deploying a kube agent and modifying scripts to install remote management tools. The investigation revealed that seven stolen kubeconfig files were added to a repository, facilitating access to Kubernetes clusters. Microsoft’s Detection and Response Team (DART) responded swiftly to contain the intrusion and provided guidance for remediation. The attack highlights the vulnerabilities in developer environments and the potential for supply chain attacks to escalate into broader cloud breaches.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-09-29
Storm-3068 intrusion reported
Microsoft disclosed that Storm-3068 gained access through a password reset and targeted Azure DevOps for credential theft.
Microsoft

More articles in this cluster (2)

Following this threat?

Track Chisel and Microsoft Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed