Skip to main content
Microsoft Security

Retail shop worker using a digital tablet checks inventory in a storage room

Inside the attack chain: Threat activity targeting Azure Blob Storage

Azure Blob Storage is a high-value target for threat actors due to its critical role in storing and managing massive amounts of unstructured data at scale across diverse workloads and is increasingly targeted through sophisticated attack chains that exploit misconfigurations, exposed credentials, and evolving cloud tactics.

Threat intelligence

  • Retail shop worker using a digital tablet checks inventory in a storage room
    • 20 min read

    Inside the attack chain: Threat activity targeting Azure Blob Storage

    Azure Blob Storage is a high-value target for threat actors due to its critical role in storing and managing massive amounts of unstructured data at scale across diverse workloads and is increasingly targeted through sophisticated attack chains that exploit misconfigurations, exposed credentials, and evolving cloud tactics.
  • Professor works at a table in a campus office space
    • 12 min read

    Investigating targeted “payroll pirate” attacks affecting US universities

    Microsoft Threat Intelligence has identified a financially motivated threat actor that we track as Storm-2657 compromising employee accounts to gain unauthorized access to employee profiles and divert salary payments to attacker-controlled accounts, attacks that have been dubbed “payroll pirate”.
  • Photo of two employees collaborating during a Microsoft Teams meeting while working in an open office setting on dual monitors.
    • 23 min read

    Disrupting threats targeting Microsoft Teams

    Threat actors seek to abuse Microsoft Teams features and capabilities across the attack chain, underscoring the importance for defenders to proactively monitor, detect, and respond effectively.

Stay ahead of threats

Get expert insights, threat intelligence, and the latest cybersecurity reports from Security Insider.

AI and machine learning

Modernize your security operations center

Confidently secure your multicloud, multiplatform environment with Microsoft Sentinel – a cloud-native security information and event management (SIEM) solution.

Latest posts