A threat actor is selling employee databases stolen from Microsoft Azure infrastructure of multiple Fortune 500 companies using compromised credentials, exposing sensitive account records and presenting an enterprise security risk.
The Russian threat group Midnight Blizzard's Storm-2945 sub-cluster has compromised hospitality sign-in portals worldwide since May 2026, delivering malware and stealing traveler credentials.
Attackers manipulate DNS settings on hotel and conference center Wi-Fi to redirect users to fraudulent Microsoft 365 login pages, targeting credential theft from business travelers.