How Storm-2949 turned a compromised identity into a cloud-wide breach

2026-05-19T02:52:15Z62f4d71c9867f08c17174194d25242abf4a3177f77c295ef7378567ad6cc9ba4
AI appsAI securityDirty FragKazuarLinux local privilege escalationMDASH (agentic defense)RCEStorm-2949botnetcloud breachcredential theftdata exfiltrationdetection engineeringesp4esp6identity compromisekernel vulnerabilitymisconfigurationnation-statenetworkingpeer-to-peerrxrpcsupply chain risksynthetic telemetrythird-party compromise

What happened

Microsoft Security Blog posts covering multiple high-risk topics: Storm-2949 used stolen credentials to escalate an identity compromise into a cloud-wide breach and large-scale data theft without malware; Dirty Frag — a new Linux kernel local privilege escalation affecting networking (esp4, esp6, rxrpc) — is being exploited post-compromise; Kazuar is a modular P2P nation‑state botnet enabling persistent covert access. Additional themes include exploitable misconfigurations in cloud-native AI apps (exposed UIs, weak auth, risky defaults leading to RCE/data leaks), stealthy intrusions via third‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
microsoft_security_blog
Record identifier
62f4d71c9867f08c17174194d25242abf4a3177f77c295ef7378567ad6cc9ba4
Enrichment time
2026-05-19T02:52:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.