Cybersecurity
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
JADEPUFFER used compromised Azure service principals to delete most targeted storage accounts in an 18-hour intrusion, Microsoft says.
Summary
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedMore from Cybersecurity
Continue reading recent Cybersecurity coverage
- Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft CampaignContinue reading
- New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy ProtectionsContinue reading
- Kiteworks Urges Server Shutdown, Finds Advanced Forms VulnerabilityContinue reading
- Bitget resumes Bitcoin withdrawals after $387.5 million crypto heistContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow