Urgent.News

What's breaking now, across thousands of outlets.

Tech

JadePuffer crims hijacked Azure identities and used them to blow up cloud resources

Smells like more agentic ransomware, Redmond warns

JadePuffer crims hijacked Azure identities and used them to blow up cloud resources

Microsoft has detected a malicious actor, Storm-3168, responsible for stolen Azure identities and destructive attacks on cloud resources. The threat actor, linked to the JadePuffer ransomware, conducted an 18-hour attack over early June, compromising two service principals for extensive Azure-focused resource destruction and credential collection.

The compromised service principals were used for reconnaissance, resource discovery, and destructive operations, including the deletion of over 100 Azure Storage accounts and an Azure Key Vault. The attacker also attempted to delete Azure SQL databases, but failed due to unsupported API versions. Despite the extensive damage, no ransom note was sent, and no data exfiltration was confirmed.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

Bootstrap for Blazor: Styling the Task Tracker

This is the final post in the series. The Task Tracker has been built, refactored, rendered, and made interactive, genuinely working since Part 4, but visually plain, using nothing but default…

More from Monday 28 September →