Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Storm-3168’s Swift Azure Resource Deletion Exposes Security Gaps

Storm-3168’s Swift Azure Resource Deletion Exposes Security Gaps

Posted on September 29, 2026 By CWS

Storm-3168 executed a swift and destructive attack on an Azure environment by exploiting compromised cloud identities. This incident underscores the severe implications of stolen application credentials, granting attackers extensive control over data and services. The attack, connected to JADEPUFFER ransomware activities, highlights the rising threat posed by automated cloud assaults.

Uncovering the Attack

Investigators identified two compromised service principals within a single tenant. One principal mapped the environment while the other was responsible for resource destruction and storage key collection. The attacker, tracked by Microsoft as Storm-3168, targeted various Azure components, including Storage accounts, SQL databases, and recovery controls.

Microsoft’s report, shared with Cyber Security News, indicated no confirmed ransom demands or data theft, yet the attack’s characteristics suggest a focus on extortion. The breach highlights vulnerabilities that can arise long before destructive actions occur, such as exposed credentials on public platforms like GitHub.

Details of the Azure Breach

In June 2026, the initial compromised identity conducted over 300 read operations across Azure resources, mapping virtual machines and subscriptions. Shortly after, a second identity swiftly scanned resources and began probing App Service configurations. The destructive operations commenced less than a minute after these reconnaissance activities.

Over seven minutes, Storm-3168 attempted to delete more than 100 storage accounts, successfully removing most. Attempts to delete SQL databases were thwarted by unsupported API versions, showcasing the importance of independent safeguards like resource locks.

Security Implications and Recommendations

The simultaneous use of multiple identities and tokens for deletion and key collection suggests coordinated automation. Organizations must promptly revoke exposed credentials, investigate their use, and adhere to the principle of least privilege for identities. An Azure Arc report further emphasizes the risks of accessible deployment secrets.

Administrators are advised to restrict access to backups, monitor changes to recovery controls, and review identity permissions regularly. Security teams should be vigilant for unusual resource discovery and deletion activities, as highlighted in reports on Key Vault access risks.

Indicators of compromise (IoCs) were identified, including specific IP addresses related to malicious Azure Resource Manager requests. These indicators are crucial for threat intelligence and incident response.

To enhance incident response, organizations are encouraged to integrate threat intelligence tools, cutting down the investigation time for security operations centers (SOCs) and improving overall cyber resilience.

Cyber Security News Tags:automated cloud threats, Azure resources, Azure security, cloud attack, cloud identity theft, cloud infrastructure, cloud recovery, Cybersecurity, data extortion, data protection, JADEPUFFER, Microsoft, Ransomware, service principals, Storm-3168

Post navigation

Previous Post: OpenAI Halts Model Training After Security Breach
Next Post: Amsterdam Man Arrested in ShinyHunters Hacking Probe

Related Posts

Yurei Ransomware File Encryption, Operation Model and Data Transfer Methods Uncovered Yurei Ransomware File Encryption, Operation Model and Data Transfer Methods Uncovered Cyber Security News
Sensitive GovCloud Credentials Exposed on GitHub Sensitive GovCloud Credentials Exposed on GitHub Cyber Security News
Qilin Ransomware Using Ghost Bulletproof Hosting to Attack Organizations Worldwide Qilin Ransomware Using Ghost Bulletproof Hosting to Attack Organizations Worldwide Cyber Security News
Malware Infiltrates Popular Rust Packages in Major Attack Malware Infiltrates Popular Rust Packages in Major Attack Cyber Security News
Phishing Attack Exploits GitHub Alerts to Distribute Malware Phishing Attack Exploits GitHub Alerts to Distribute Malware Cyber Security News
Sendmarc Appoints Dan Levinson as Customer Success Director in North America Sendmarc Appoints Dan Levinson as Customer Success Director in North America Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WatchGuard API Flaws Allow Command Execution
  • Microsoft Analyzes NeedyMantis Malware from Daemon Tools Hack
  • Amsterdam Man Arrested in ShinyHunters Hacking Probe
  • Storm-3168’s Swift Azure Resource Deletion Exposes Security Gaps
  • OpenAI Halts Model Training After Security Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WatchGuard API Flaws Allow Command Execution
  • Microsoft Analyzes NeedyMantis Malware from Daemon Tools Hack
  • Amsterdam Man Arrested in ShinyHunters Hacking Probe
  • Storm-3168’s Swift Azure Resource Deletion Exposes Security Gaps
  • OpenAI Halts Model Training After Security Breach

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark