The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours.
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
About this summary. This is a short, independently written summary of an article first published by The Hacker News. Cyber Security News did not report or verify the underlying story. Read the original: https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html

Source attribution: headline and facts are from The Hacker News (thehackernews.com). Summary method: excerpt of the source description. See our source attribution policy.





