AI Weekly Malaysia

Summaries

Short AI and tech summaries with source links, signal scores, and why each update matters for builders, founders, and Malaysian tech workers.

Reset

Showing 1-1 of 1 results

DateProviderScoreSummary
17 Aug 2026, 7:43 PMThe Register6.5 Crook hawks millions of records allegedly plundered from corporate Azure tenants

A threat actor called 'TheHatman' is selling millions of employee records allegedly exfiltrated from Microsoft Azure environments of nine major companies, including McDonald's (1.7M records), TCS (800K), Vodafone (425K), and HCL (250K). Hudson Rock assessed the data as 'highly likely authentic,' noting it contains phone numbers, physical addresses, job titles, reporting structures, group memberships, and—critically—identities of Global Administrator accounts, making it a phishing and privilege-escalation shortlist.

Why: If you run Azure AD/Entra ID, this illustrates what a directory export actually leaks beyond email: org charts, service account details, and who holds Global Admin. Audit your Entra ID for infostealer-compromised credentials, enforce phishing-resistant MFA on all admin accounts, and review third-party app permissions—Hudson Rock specifically flagged overly permissive third-party apps as a likely vector. The data exposure is severe even without passwords, because knowing your Global Admins by name is enough for targeted attacks.

Top