JadePuffer used a service principal leaked in a GitHub issue to wipe Azure resources in seven minutes
Microsoft says the operator it tracks as Storm-3168 used two compromised service principals and an AI-driven toolchain to map an Azure tenant, pull storage keys, delete recovery locks and destroy resources in a seven-minute window.
Microsoft and Sysdig have detailed JadePuffer, a ransomware operator Microsoft tracks as Storm-3168, running agent-driven attacks against Azure tenants. In two attacks observed in June, the operation used two compromised service principals in the same tenant: one for reconnaissance and resource discovery, the second for further discovery, credential collection and destruction. It targeted more than 100 storage accounts along with Key Vaults, Function Apps, virtual machines and App Services, made more than 30 requests for storage account keys, most of which succeeded, and removed Azure Site Recovery locks to block recovery. The destructive phase took seven minutes; parallel attempts to delete Azure SQL resources failed on an unsupported API version. Microsoft could not determine the initial access, but credentials for one of the service principals had appeared in a public GitHub issue before the attacks.
Why it matters
Every step here ran on permissions the service principals already had. Listing storage keys, deleting resource locks and destroying production resources are separate rights, and a principal that holds all three at once is standing destructive privilege waiting for its secret to leak. The review to run is which of your service principals can both read secrets and delete locks, and why; almost none should need both, and lock deletion in particular belongs behind a human approval. See zero standing privileges and least privilege.
The initial access is the older lesson. A client secret is a password for a workload, and it ended up in a GitHub issue the way passwords end up in chat. Workload identity federation and managed identities remove the secret entirely, which removes this whole class of leak. The AI agent matters mainly for speed: seven minutes from start to finish means a response process measured in hours only ever gets to investigate. See secrets in repositories and CI and client credentials.
Source: BleepingComputer
Related on Start with Identity
- BlogA hijacked AI coding assistant session spread Shai-Hulud to about 100 internal repositories
Mandiant describes an intrusion at an unnamed SaaS provider where a poisoned package, recommended through a developer's AI coding assistant session, led to stol
- BlogA phantom join key let anyone mint JFrog Artifactory admin tokens, and exploitation started in days
CVE-2026-82329 (CVSS 9.8) is an authentication bypass in JFrog Access. Instances without an explicit join key got a predictable one, letting an unauthenticated
- BlogAmerica.gov launches as an AI front door to federal services, with Login.gov as its sign-in
GSA and the White House National Design Studio launched America.gov, an AI-assisted entry point to federal services. The executive order behind it makes Login.g
- GlossaryService Principal
A service principal is the identity an application or automated workload uses to sign in to Microsoft Entra ID and access Azure or Microsoft Graph resources: th
- VendorAzure Key Vault
strong_contender
- CVEGitHub Enterprise Server SAML bypass via libxml2 canonicalization
GitHub Enterprise Server accepted a crafted SAML response because libxml2 canonicalization quirks let the signed XML and the consumed XML diverge. High-severity