IAMDevBox
  • Guides
  • Tools
  • Trending
  • Contact
  • Search
Home » Tags

Tag · 1 article

SSPR

Oct 1, 2026 · 6 min read

Storm-3068: How SSPR Abuse Turns One Azure AD Account Into Kubernetes Credential Theft

Microsoft's Storm-3068 campaign chains self-service password reset abuse, MFA method hijacking, and Azure DevOps pipeline manipulation to steal Kubernetes kubeconfig files. Here's the exact attack chain and the SSPR, Conditional Access, and RBAC controls that stop it.
IAMDevBox

Identity and access management guides and browser tools for engineers who run Keycloak, ForgeRock, Ping Identity, SailPoint, OAuth 2.0 and SAML in production.

Guides

  • Keycloak
  • OAuth 2.0 & OIDC
  • SAML & SSO
  • ForgeRock & Ping Identity
  • SailPoint IdentityIQ
  • All guides

Tools

  • JWT Decoder
  • PKCE Generator
  • SAML Decoder
  • OAuth 2.0 Playground
  • OIDC Discovery Checker
  • All tools

Resources

  • ForgeRock deployment checklist
  • Trending
  • Search
  • About
  • RSS feed

Connect

  • GitHub
  • YouTube
  • Dev.to
  • Mastodon
  • Contact
© 2026 IAMDevBox. Independent and vendor-neutral. Tools run locally in your browser. Built with Hugo