Storm-3168: Hijacked Service Principals Hit Azure Storage
Storm-3168 (JADEPUFFER) used two Azure service principals to target 100+ storage accounts in about 18 hours. What happened, what held, and a checklist.
Expert perspectives on cloud security, compliance, and threat intelligence. Practical guidance for security leaders navigating an evolving landscape.
Insurance posture management checks your cyber insurance answers against real scans. Why it belongs in GRC, and what the Hamilton denial teaches.
Threat Intelligence
Storm-3168 (JADEPUFFER) used two Azure service principals to target 100+ storage accounts in about 18 hours. What happened, what held, and a checklist.
Threat Intelligence
Microsoft took down EvilTokens, an AI-assisted device code phishing service linked to 12,000+ compromised Microsoft 365 inboxes at 10,000+ organizations. How it bypassed MFA, the one Conditional Access policy that stops it, and how to check your Entra ID tenant.
Cloud Security
Microsoft retires SMS and voice call authentication on 1 February 2027, with Global Administrators and guests following on 1 July 2027. No opt-out, MFA and password reset alike. How to find every phone-only user in Entra ID and move them before sign-in breaks.
Threat Intelligence
In 88% of ransomware cases the encryption ran outside business hours. Attackers are not beating your tooling, they are beating your rota. Five controls that hold the line while nobody is watching.
Compliance
A green compliance row means a requirement was mapped to a document. It does not mean a query ran against your tenant and came back with a value. Those are different claims, and only one of them survives an incident.
Best Practices
A cyber insurance application offers two boxes. Most control questions have three honest answers, and collapsing the third into yes is how a true intention becomes a misrepresentation.
Best Practices
Outside-in security ratings read the perimeter. The five controls that decide a cyber claim live inside the tenant, where no external scanner reaches.
Best Practices
Cyber claims are denied over answers given at application time. What carriers recheck after a loss, and how to date the evidence before you sign the form.
Best Practices
Security posture measures your environment against a framework you chose. Insurance posture measures the same environment against your cyber carrier's questions.
Cloud Security
Every AI agent, Copilot extension, and AI SaaS connector becomes a service principal in Entra ID with standing permissions, no MFA, and credentials that outlive their owner. How to inventory them.
Best Practices
Most cyber insurance application answers are queryable facts in your tenant. Where each one lives in Microsoft 365, Entra ID, and Azure, and how to date the evidence before you sign.
Compliance
SOC 2 evidence is a dated record that a control ran inside the window, not a screenshot of today's dashboard. What auditors sample, and why green is not proof.
Page 1 of 5