HackerFeeds

CyberSecurity News

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

The Hacker News
· September 28, 2026

AI summary

The JADEPUFFER threat actor has been found to be behind destructive actions in a Microsoft Azure environment, using compromised service principals to carry out these actions. Microsoft is tracking this activity, referring to it as Storm-3168, and considers it an evolution of the threat actor's tactics. The attack occurred over an 18-hour period in early June 2026. The attackers used the compromised service principals to delete Azure resources. Microsoft has identified this as a notable development in the threat actor's methods. The incident highlights the threat actor's ability to adapt and cause significant disruption in cloud environments.

Read the full article at The Hacker Newsthehackernews.com/2026/09/jadepuffer-linked-attackers-used.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.