Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
JADEPUFFER Exploits Azure to Delete Resources

JADEPUFFER Exploits Azure to Delete Resources

Posted on September 28, 2026 By CWS

The cyber threat group known as JADEPUFFER has been actively involved in conducting destructive operations within Microsoft Azure environments by exploiting compromised service principals. This activity, tracked by Microsoft under the designation Storm-3168, represents a significant evolution in the group’s attack strategies. The attack occurred in early June 2026, spanning approximately 18 hours.

Compromised Service Principals and Targeted Resources

Microsoft’s researchers, Yossi Weizman and Tushar Mudi, along with the Security Research team, have reported that the attack involved the compromise of service principals, which were then used to target various Azure components. These components included Storage Accounts, SQL databases, Key Vaults, Function Apps, Virtual Machines, and App Services. The attack’s destructive nature highlights the group’s ability to infiltrate and disrupt critical cloud-based resources.

JADEPUFFER, initially identified by Sysdig, has been associated with pioneering ransomware operations facilitated by large language models (LLM). The group exploited a known vulnerability in Langflow (CVE-2025-3248) to infiltrate systems, gather credentials, penetrate networks, encrypt service configuration files, and leave ransom demands for Bitcoin payments. This attack was further advanced with the use of a Go-based ransomware variant named ENCFORGE, targeting AI infrastructure and various file extensions.

Advanced Techniques and AI-Driven Orchestration

The use of ENCFORGE, designed specifically for AI environments, allowed the attackers to scan for nearly 180 file extensions, including those related to AI model checkpoints and Mac-specific files. According to Sysdig, the attack was characterized by an autonomous agent that systematically harvested credentials, moved laterally within the network, and maintained persistence, all while articulating its objectives.

Microsoft’s analysis detailed two compromised service principals linked to the same Azure tenant. The first was used for reconnaissance and resource discovery, while the second facilitated destructive actions and credential collection. Enumeration activities focused on Azure Virtual Machines, resource groups, and subscriptions, with over 300 read operations conducted during the attack period.

Impact and Defensive Measures

The operation culminated in numerous destructive or credential-collection actions, including attempts to delete over 100 storage accounts within a brief span. Although most targeted Azure Storage accounts were successfully deleted, some were protected by independent safeguards, such as resource locks and deletion protection measures, which thwarted the attackers’ efforts.

Microsoft indicated that the compromised service principal’s credentials, including the client ID, secret, and tenant ID, were inadvertently exposed in a public GitHub issue by an organization employee. Despite the secret’s removal, the information remained accessible through the platform’s edit history.

Ongoing investigations by Microsoft have detected further probing activities from Storm-3168 related infrastructure, suggesting that the attacks may be automated. The attackers’ ultimate goal seems to align with ransomware motives, aiming to disable recovery capabilities, although no ransom note or data exfiltration was confirmed.

As threat actors increasingly leverage AI to coordinate complex operations across cloud environments, cybersecurity defenses must similarly evolve to counteract these sophisticated threats. The JADEPUFFER case underscores the pressing need for robust security measures and the adoption of AI-driven defense mechanisms to protect against such advanced cyber threats.

The Hacker News Tags:AI attacks, Azure, cloud security, Cybersecurity, data protection, ENCFORGE ransomware, JADEPUFFER, Langflow vulnerability, Microsoft, Ransomware, service principal compromise, Storm-3168

Post navigation

Previous Post: Kiteworks Addresses Security Threat with Server Shutdown
Next Post: Jury Rules Facebook Misled Users on Privacy in New Mexico

Related Posts

WeaselBiscuit Malware Detected in 13 npm Packages WeaselBiscuit Malware Detected in 13 npm Packages The Hacker News
Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors The Hacker News
Linux-Based Lenovo Webcams’ Flaw Can Be Remotely Exploited for BadUSB Attacks Linux-Based Lenovo Webcams’ Flaw Can Be Remotely Exploited for BadUSB Attacks The Hacker News
Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs Anthropic Uncovers Large-Scale Distillation Attacks by Chinese AI Labs The Hacker News
Chaos RaaS Emerges After BlackSuit Takedown, Demanding 0K from U.S. Victims Chaos RaaS Emerges After BlackSuit Takedown, Demanding $300K from U.S. Victims The Hacker News
UAC-0050 Expands to European Finance with RMS Malware UAC-0050 Expands to European Finance with RMS Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • PHP Addresses Security Flaw Exposing Sensitive Data
  • Jury Rules Facebook Misled Users on Privacy in New Mexico
  • JADEPUFFER Exploits Azure to Delete Resources
  • Kiteworks Addresses Security Threat with Server Shutdown
  • Citrix Releases Patches for Critical NetScaler Zero-Day Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • PHP Addresses Security Flaw Exposing Sensitive Data
  • Jury Rules Facebook Misled Users on Privacy in New Mexico
  • JADEPUFFER Exploits Azure to Delete Resources
  • Kiteworks Addresses Security Threat with Server Shutdown
  • Citrix Releases Patches for Critical NetScaler Zero-Day Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark