Skip to main content
See every side of every news story
Published • loading... • Updated

JadePuffer Agentic AI Attacks Target Azure, Destroy Cloud Resources

Microsoft said one identity spent more than 15 hours mapping Azure resources before more than 150 destructive or credential-related operations followed.

  • On Friday, Microsoft reported that the threat actor Storm-3168, also known as Jadepuffer, compromised two Azure service principals over an 18-hour period in early June to conduct extensive resource destruction and credential collection.
  • Jadepuffer, an autonomous AI attacker first identified in July, utilized machine identities to map resources before launching a seven-minute burst of destruction, according to researchers Yossi Weizman and Tushar Mudi.
  • Attackers attempted to delete more than 100 Azure Storage accounts and made more than 30 successful ListKeys requests, potentially allowing further data access, though no ransom note was ever sent.
  • Microsoft found that the initial compromise likely stemmed from client IDs and secrets previously exposed in a public GitHub issue, warning that removing such disclosures does not remediate exposure until credentials are fully rotated.
  • Lead security automation architect Nick Tausek of Swimlane noted that such AI-orchestrated attacks require security operations centers to connect identity activity with cloud changes before damage spreads, emphasizing coordinated response planning.
Insights by Ground AI

12 Articles

Microsoft reconstructed an attack attributed to JadePuffer, an actor already known to have entrusted an IA with an almost complete ransomware chain. This time, a few minutes were enough to destroy a large part of an Azure environment.

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 75% of the sources are Center
75% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

IT Security News - cybersecurity, infosecurity news broke the news on Friday, September 25, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal