#6
The Hacker News
general
September 28, 2026 at 09:08 UTC
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
By [email protected] (The Hacker News)
AI Summary
Microsoft-tracked threat actor JADEPUFFER (Storm-3168) conducted a destructive Azure attack in early June 2026, using compromised service principals to delete cloud-based storage, applications, and databases over approximately 18 hours. The agentic attack methodology — involving automated reconnaissance, credential theft, and resource destruction — represents an evolution in cloud-targeting TTPs that security teams must account for in Azure IAM and monitoring configurations.
Relevance score: 82.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →