Cybersecurity · September 29, 2026
Microsoft says the threat group it tracks as Storm-3168, also publicly known as JadePuffer, hijacked compromised Azure service principals to carry out a destructive campaign inside a victim's cloud tenant. The intrusion unfolded over roughly 18 hours in early June 2026 and, according to Microsoft, reflects a meaningful shift in the group's usual tradecraft. BleepingComputer separately reported that the attackers combined reconnaissance and credential theft with the deliberate destruction of core Azure resources.
// source: thehackernews.com ↗