#jadepuffer
JadePuffer crew trashes Azure cloud 🌩️

The JadePuffer (Storm-3168) threat actors reports Microsoft, leveraged stolen Azure identities for cloud destruction and credential collection, following their agentic ransomware exploits.

Sophisticated adversaries still benefit from simple credential leaks.
September 29, 2026 at 7:54 PM
JadePuffer crims hijacked Azure identities and used them to blow up cloud resources
JadePuffer crims hijacked Azure identities and used them to blow up cloud resources
Smells like more agentic ransomware, Redmond warns
www.theregister.com
September 28, 2026 at 8:42 PM
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.
JadePuffer agentic AI attacks target Azure, destroy cloud resources
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.
www.bleepingcomputer.com
September 28, 2026 at 3:49 PM
JADEPUFFEr, the AI-powered ransomware group, is destroying Azure environments as part of its extortion campaigns, most likely to put pressure on victims

www.microsoft.com/en-us/securi...
Storm-3168: Agentic-driven cloud attacks using compromised service principals | Microsoft Security Blog
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and prov...
www.microsoft.com
September 27, 2026 at 12:33 AM
JadePuffer crims hijacked Azure identities and used them to blow up cloud resources www.theregister.com/security/202...
JadePuffer crims hijacked Azure identities and used them to blow up cloud resources
Smells like more agentic ransomware, Redmond warns
www.theregister.com
September 29, 2026 at 12:30 AM
JadePuffer agentic AI attacks target Azure, destroy cloud resources
www.bleepingcomputer.com/news/securit...
JadePuffer agentic AI attacks target Azure, destroy cloud resources
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.
www.bleepingcomputer.com
September 29, 2026 at 11:55 AM
Microsoft linked destructive Azure activity to Storm-3168 /JADEPUFFER.

Two compromised service principals performed hundreds of discovery and destructive operations across Storage, SQL, Key Vault, VMs and recovery resources.

cyberupdates365.com/jadepuffer-s...

#Cybersecurity #Azure #CloudSecurity
JadePuffer Storm-3168 Azure Attack Wipes Cloud Resources
JadePuffer, tracked as Storm-3168, used compromised Azure service principals to delete cloud resources and collect credentials.
cyberupdates365.com
September 28, 2026 at 1:15 PM
-New Zealand says AI is reshaping the cyber landscape
-Snowflake hacker sentenced to 70 months
-Mini Shai-Hulud returns, by accident
-Storm-3168 (JADEPUFFER) destroys Azure data
-ShinyHunters continues Oracle PeopleSoft attacks
-Dataflow Security profile
-31 malicious Chrome extensions
September 28, 2026 at 8:04 AM
JadePuffer is using AI-driven attacks to target Microsoft Azure, stealing credentials and destroying cloud resources. In observed attacks, the group deleted over 100 storage accounts.

via @bleepingcomputer.com

www.bleepingcomputer.com/news/securit...
JadePuffer agentic AI attacks target Azure, destroy cloud resources
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.
www.bleepingcomputer.com
September 28, 2026 at 6:37 PM
JadePuffer crims hijacked Azure identities and used them to blow up cloud resources

Smells like more agentic ransomware, Redmond warns
#hackernews #news
JadePuffer crims hijacked Azure identities and used them to blow up cloud resources
Smells like more agentic ransomware, Redmond warns
www.theregister.com
September 29, 2026 at 9:18 PM
Microsoft has identified a new ransomware strain, Storm-3168, that uses stolen Azure AD identities to delete storage accounts and harvest keys. #Storm3168 #ransomware #AzureAD #storage https://securityaffairs.com/199905/cyber-crime/storm-3168-linked-to-jadepuffer-abused-stolen-azure-identities.html
Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities
Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage and harvest keys.
securityaffairs.com
September 29, 2026 at 8:30 AM
JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack www.darkreading.com/cloud-securi... #darkreading #cybersecurity
JadePuffer AI Actor Compromises Azure in Destructive Cloud Attack
The "agentic threat actor" may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases.
www.darkreading.com
September 28, 2026 at 9:19 PM
Microsoft has identified extensive cloud resource destruction activity linked to JADEPUFFER, which Microsoft tracks as Storm-3168. The activity used compromised service principals and performed cloud credential collection that could be used to facilitate future exfiltration. msft.it/6015a9lob
Storm-3168: Agentic-driven cloud attacks using compromised service principals | Microsoft Security Blog
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders.
msft.it
September 25, 2026 at 3:42 PM
September 30, 2026 at 1:00 AM
Azure service principals compromised by JADEPUFFER led to mass deletions—identity exposure is devastating. #CloudSecurity #Azure #JADEPUFFER #IdentitySecurity #Ransomware #AI https://thedailytechfeed.com/jadepuffer-attackers-wipe-azure-resources-via-compromised-service-principals/
September 28, 2026 at 9:26 AM
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html
September 28, 2026 at 11:47 AM
Are we human?
www.theregister.com
September 29, 2026 at 7:41 PM
Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent.
JadePuffer ransomware used AI agent to automate entire attack
Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, conducted entirely by a large language model (LLM) agent.
www.bleepingcomputer.com
July 4, 2026 at 2:18 PM
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html

#CyberSecurity #InfoSec
September 28, 2026 at 1:00 PM
JadePuffer agentic AI attacks target Azure, destroy cloud resources

The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...]
#hackernews #news
JadePuffer agentic AI attacks target Azure, destroy cloud resources
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...]
www.bleepingcomputer.com
September 29, 2026 at 4:29 PM
JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack https://www.darkreading.com/cloud-security/jadepuffer-ai-actor-azure-tenant-destructive-cloud-attack
September 28, 2026 at 3:47 PM