The Storm-2949 attack in Azure: from identity theft to full compromise
Technical postmortem of the Storm-2949 case in Azure: how an identity-based chain and abuse of App Services enabled exfiltration of Key Vault secrets and SQL Database data without deploying malware, and which signals and controls failed in corporate environments.