Microsoft Storm-3068 Exploits Azure DevOps for Kubernetes Credential Theft
Article Content
- •Storm-3068 exploited Azure DevOps to gain Kubernetes credentials.
- •The attack involved modifying pipeline scripts to deploy malicious tools.
- •DART provided rapid response and remediation recommendations.
On September 29, 2026, Microsoft reported an intrusion by the threat actor Storm-3068, which gained access to a user account via a self-service password reset. The attacker then took control of the identity and targeted Azure DevOps to enumerate repositories and deployment environments. A malicious pipeline was created to harvest Kubernetes credentials at scale, deploying a kube agent and modifying scripts to install remote management tools. The investigation revealed that seven stolen kubeconfig files were added to a repository, facilitating access to Kubernetes clusters. Microsoft’s Detection and Response Team (DART) responded swiftly to contain the intrusion and provided guidance for remediation. The attack highlights the vulnerabilities in developer environments and the potential for supply chain attacks to escalate into broader cloud breaches.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Chisel and Microsoft Azure in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Breeze Comet Targets Brazilian Financial Sector with Systemic Fraud Since 2024, the financially motivated threat actor Breeze Comet has targeted Brazilian financial services, retail, and eCommerce organizations, executing hundreds of fraudulent transactions via the Pix payment system. This group, previously known as UNC5669, employs tactics such as password spraying and social…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…