✉news EnvironmentWeather first seen 12 h ago, last 2 h ago, peak #7
Storm-3168 attackers exploit Azure via compromised service principals
Original: Active Exploitation Alert: Storm-3168 (JADEPUFFER) Agentic Attack Targets Azure via Compromised Service Principals
Security firm Rescana has issued an alert about active exploitation by the threat group Storm-3168, also tracked as JADEPUFFER, which is using compromised Azure service principals to attack Microsoft Azure environments. The campaign is described as an agentic attack, meaning the attackers deploy automated tooling to move through cloud infrastructure. Organizations running Azure are being urged to review service principal credentials and permissions.
Why now: Active exploitation of widely used Microsoft Azure cloud infrastructure creates urgent concern for organizations worldwide.
Storm-3168JADEPUFFERMicrosoft AzureRescana
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/994992