THEMETASEC

Cybersecurity News, Aggregated

Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities

Security Affairs · 2 hours ago Breach

Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage in minutes and harvest keys. Microsoft just published the first detailed look at what JADEPUFFER does inside Azure. Sysdig first spotted the group’s activity in July 2026 and called it the first documented agentic ransomware operation. Microsoft tracks the same […]

Read full story at Security Affairs →