importantSYS.SOURCE: The Hacker News• 2026-09-28T14:38:21+05:30
JADEPUFFER Threat Group Exploits Compromised Azure Service Principals for Resource Deletion
JADEPUFFER threat actors exploited compromised Azure service principals to delete critical resources, leveraging AI-driven techniques and exposed credentials. The attack highlighted vulnerabilities in cloud infrastructure and demonstrated the evolving use of AI in orchestrating destructive cyber operations.
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals.
Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours.
"The destructive operations
*** END OF TRANSMISSION ***