chiprook
← Security
SecuritySeptember 28, 2026, 16:08

JADEPUFFER attackers used compromised service principals to delete Azure resources

The threat actor JADEPUFFER, tracked by Microsoft as Storm-3168, carried out destructive operations in a Microsoft Azure environment over roughly 18 hours in early June 2026 using compromised service principals. Microsoft described the incident as an evolution of the group's tradecraft.

JADEPUFFER attackers used compromised service principals to delete Azure resources
#Microsoft#Azure
Read next
Security

UK police data vulnerable to compromise by US government and foreign actors

Security

Attacker compromised nearly 1,000 Zyxel switches via CVE-2026-7273

Security

Hacktron details attack chain that compromised OpenAI employee accounts

Software

Microsoft retires legacy Azure Service Bus clients on September 30, 2026