Follow the latest coverage, related explainers and connected technology stories.
Microsoft explains how the Storm-3068 attack began with an account compromise through self-service password reset, then extended to Azure DevOps, development pipelines, and Kubernetes resources. The case highlights the importance of protecting identities, controlling deployment-pipeline permissions, and reviewing connections between development and cloud environments.