⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

September 28, 2026

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources Ravie LakshmananSep 28, 2026Cloud Security / Identity Security The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations were facilitated by compromising service principals and targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services," researchers Yossi Weizman and Tushar Mudi, along with the Microsoft Security Research team, said. JADEPUFFER was first documented…

CVEs: CVE-2025-3248