search
Microsoft Azure
Trends
- 1Storm-3168 JADEPUFFER Attack Exploits Azure Service Principals●Active Exploitation Alert: Storm-3168 (JADEPUFFER) Agentic Attack Targets Azure via Compromised Service Principals
Microsoft is tracking active exploitation by the threat actor Storm-3168, also known as JADEPUFFER, which uses AI-driven 'agentic' attack techniques against Azure environments. The campaign relies on compromised service principals — non-user identities used by applications — to gain access to cloud resources. Security teams are being urged to audit service principal credentials, rotate secrets, and monitor for anomalous identity activity in their Azure tenants.