
highCyber Attacks
JADEPUFFER-Linked Attackers Deploy Compromised Service Principals to Delete Azure Resources
Microsoft has attributed a series of destructive operations in early June 2026 to the threat actor tracked as JADEPUFFER, also known as Storm-3168. The attackers used compromised service principals to gain elevated privileges and delete Azure resources over a period of approximately 18 hours. Microsoft describes this activity as an evolution of the threat actor's tradecraft, leveraging identity-based attacks rather than traditional exploit chains.
The Hacker News1 min read