TGViewer
CloudSec Wine CloudSec Wine @cloud_sec · 2.27K subscribers
Post #1580 71
👩‍💻 Storm-3168: Agentic-driven cloud attacks using compromised service principals

Storm-3168 (JADEPUFFER) used compromised Azure service principals to conduct automated reconnaissance, bulk deletion of Storage Accounts, Key Vaults, and Function Apps, and credential harvesting via ListKeys, consistent with ransomware-aligned objectives. Mitigations include least privilege, secret rotation, and resource locks.

https://www.microsoft.com/en-us/security/blog/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals

#azure
  • ❤ 2
  • 👍 1
  • 🔥 1
More from @cloud_sec
  1. Oct 6, 2026🤖 Securing the software factory at machine speed GitLab's CISO argues that agentic AI dev…
  2. Oct 5, 2026🤖 Throw Away the Playbook: Security in the AI-Native SDLC We, as an industry, should have…
  3. Oct 2, 2026🔴 Strengthen your CI/CD pipeline with new Secure Source Manager capabilities Google Cloud…
  4. Oct 1, 2026🔶 Exploring the new AWS Sign Up experience This post will explore what this new concept d…
  5. Sep 30, 2026🤖 Hacking OpenAI Researchers chained a libheif heap buffer overflow (via Discourse/ImageM…
  6. Sep 29, 2026👩‍💻 How to secure edge AI in customer-owned environments Edge AI shifts trust responsibi…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →