home.social

#azure — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #azure, aggregated by home.social.

fetched live
  1. CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials

    A sophisticated credential theft campaign manipulates DNS and HTTP traffic on captive portal networks at hotels, conference centers, and hospitality venues to redirect victims to attacker-controlled infrastructure. The operation harvests Microsoft 365 credentials through phishing pages, device code phishing abusing Microsoft Entra ID authentication flow, and malware delivery via ClickFix social engineering techniques. Evidence indicates compromised shared captive portal services rather than individual venue breaches, with affected gateways identified in several U.S. cities, India, and Saudi Arabia. The campaign deploys two primary malware tools: CornFlake, a Go-based RAT providing persistent access and extensive surveillance capabilities, and ChocoShell, an in-memory PowerShell stealer that harvests browser credentials, Microsoft 365 tokens, and Azure AD tokens. The operation targets travelers across multiple sectors and has expanded to include Android devices through malicious APK files.

    Pulse ID: 6a7bdb051d6a41c7ea440061
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:31:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APK #Android #Azure #Browser #CyberSecurity #DNS #HTTP #Hospital #India #InfoSec #Malware #Microsoft #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SaudiArabia #SocialEngineering #Troll #bot #AlienVault

  2. CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials

    A sophisticated credential theft campaign manipulates DNS and HTTP traffic on captive portal networks at hotels, conference centers, and hospitality venues to redirect victims to attacker-controlled infrastructure. The operation harvests Microsoft 365 credentials through phishing pages, device code phishing abusing Microsoft Entra ID authentication flow, and malware delivery via ClickFix social engineering techniques. Evidence indicates compromised shared captive portal services rather than individual venue breaches, with affected gateways identified in several U.S. cities, India, and Saudi Arabia. The campaign deploys two primary malware tools: CornFlake, a Go-based RAT providing persistent access and extensive surveillance capabilities, and ChocoShell, an in-memory PowerShell stealer that harvests browser credentials, Microsoft 365 tokens, and Azure AD tokens. The operation targets travelers across multiple sectors and has expanded to include Android devices through malicious APK files.

    Pulse ID: 6a7bdb051d6a41c7ea440061
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:31:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APK #Android #Azure #Browser #CyberSecurity #DNS #HTTP #Hospital #India #InfoSec #Malware #Microsoft #OTX #OpenThreatExchange #Phishing #PowerShell #RAT #SaudiArabia #SocialEngineering #Troll #bot #AlienVault

  3. Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

    On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.

    Pulse ID: 6a7bdb4167c384aad06f1253
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:32:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault

  4. Tracking Shai-Hulud: Inside the ChainDrop NPM Worm

    On August 4, 2026, ChainDrop, a self-propagating worm variant of Mini Shai-Hulud linked to TeamPCP, infiltrated the npm ecosystem through a compromised maintainer account of the keyv ecosystem. The attacker injected malicious code into GitHub repositories, weaponizing legitimate CI/CD pipelines to publish poisoned packages with valid SLSA Build Level 3 provenance attestations, making them indistinguishable from clean releases. ChainDrop spread to over 400 packages within four hours by stealing npm tokens and republishing infected versions. The worm employs Ethereum smart contracts for C2 infrastructure, enabling domain rotation without modifying deployed malware. It features destructive capabilities, wiping victim home directories upon token revocation, and achieves persistence through IDE and AI-agent configuration files. The payload harvests credentials from npm, GitHub, AWS, Azure, GCP, Kubernetes, HashiCorp Vault, and other services, exfiltrating data via GitHub repositories and EtherHiding techniques.

    Pulse ID: 6a7bdb4167c384aad06f1253
    Pulse Link: otx.alienvault.com/pulse/6a7bd
    Pulse Author: AlienVault
    Created: 2026-08-12 02:32:33

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AWS #Azure #CyberSecurity #ELF #EtherHiding #GitHub #InfoSec #Malware #NPM #OTX #OpenThreatExchange #RAT #Worm #bot #AlienVault

  5. 🤖 What if an #AI agent could investigate an Azure incident and trigger your #PowerShell runbooks automatically?

    @[email protected] demonstrates how #Azure #SRE Agent, #MCP, and PowerShell can work together to automate incident response and remediation.

    👉 youtu.be/BBISIWdKWqU?si=CkF...

    - YouTube

  6. 🤖 What if an #AI agent could investigate an Azure incident and trigger your #PowerShell runbooks automatically?

    @[email protected] demonstrates how #Azure #SRE Agent, #MCP, and PowerShell can work together to automate incident response and remediation.

    👉 youtu.be/BBISIWdKWqU?si=CkF...

    - YouTube

  7. Microsoft entscheidet, ob dein Linux startet

    Ende Juni ist ein Microsoft-Zertifikat ausgelaufen – und ohne das fährt dein Linux-Rechner nicht mehr hoch

    Linux-Bootloader hängen an Microsoft-Signaturen. Das Zertifikat ist abgelaufen. Ob dein System noch bootet, hängt von BIOS-Version und Herstellersupport ab. Der Artikel zeigt, wie du das Problem löst – und warum Secure Boot ein Souveränitätsproblem ist. Reden wir drüber!

    chrislo.de/blog/2026-08-10-07-

    #chrislo #digitaleunabhängigkeit #Linux #Microsoft #SecureBoot #UEFI #ITSicherheit #DigitaleSouveränität #OpenSource #Datenschutz #Azure #fwupd

  8. Microsoft entscheidet, ob dein Linux startet

    Ende Juni ist ein Microsoft-Zertifikat ausgelaufen – und ohne das fährt dein Linux-Rechner nicht mehr hoch

    Linux-Bootloader hängen an Microsoft-Signaturen. Das Zertifikat ist abgelaufen. Ob dein System noch bootet, hängt von BIOS-Version und Herstellersupport ab. Der Artikel zeigt, wie du das Problem löst – und warum Secure Boot ein Souveränitätsproblem ist. Reden wir drüber!

    chrislo.de/blog/2026-08-10-07-

    #chrislo #digitaleunabhängigkeit #Linux #Microsoft #SecureBoot #UEFI #ITSicherheit #DigitaleSouveränität #OpenSource #Datenschutz #Azure #fwupd

  9. Visual Studio is moving beyond traditional code assistance toward a more agent-driven development experience. The new Copilot Agent, powered by the GitHub Copilot SDK, can help developers handle feature changes, bug fixes, refactoring, and other development tasks with greater autonomy, while built-in .NET and Azure skills add specialized knowledge directly into the workflow.
    #Copilot #ArtificialIntelligence #AI #VisualStudio #Azure #DotNET #AgenticAI

    devblogs.microsoft.com/visuals

  10. Visual Studio is moving beyond traditional code assistance toward a more agent-driven development experience. The new Copilot Agent, powered by the GitHub Copilot SDK, can help developers handle feature changes, bug fixes, refactoring, and other development tasks with greater autonomy, while built-in .NET and Azure skills add specialized knowledge directly into the workflow.
    #Copilot #ArtificialIntelligence #AI #VisualStudio #Azure #DotNET #AgenticAI

    devblogs.microsoft.com/visuals