CyberSecurity News
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
AI summary
The JADEPUFFER threat actor has been found to be behind destructive actions in a Microsoft Azure environment, using compromised service principals to carry out these actions. Microsoft is tracking this activity, referring to it as Storm-3168, and considers it an evolution of the threat actor's tactics. The attack occurred over an 18-hour period in early June 2026. The attackers used the compromised service principals to delete Azure resources. Microsoft has identified this as a notable development in the threat actor's methods. The incident highlights the threat actor's ability to adapt and cause significant disruption in cloud environments.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

