Just apply same buggy network patch to all DCs at once? They use software networking so causing something like this should be easy. Or mess up network routing for *.blob.core.windows.net which pretty much all of Azure relies on.
Isn't applying the same patch everywhere at once a major anti-pattern?
Yes.
Turns out this was exactly what happened - they applied a buggy patch to all data centers at once by mistake.
I suspect a human config error. I don't see how else multiple services, in multiple regions, can all be affected at once.