Microsoft details Storm-3168 agentic cloud attacks: 100+ storage deletions in 7 minutes
yuridiogenes · x · 2026-09-26
Microsoft Security Research published new findings on Storm-3168 (JADEPUFFER), an evolution of what Sysdig identified in July 2026 as the first documented agentic ransomware operation. Attackers used two compromised service principals with divided roles — discovery, destruction, and credential collection — with timing and overlapping token streams strongly indicating scripted execution, including 100+ storage account deletion attempts in about seven minutes. Collected cloud credentials could facilitate future exfiltration.
More from Safety
- AI safety advocate: builders see >10% extinction risk; critics say EA values distort AI policy — AaronBergman18 · 2026-09-26
- Cambridge explores AI to cut regulatory paperwork for medical AI software — lawrennd · 2026-09-26
- Cyber insurers consider limiting coverage as agentic AI hacks defy pricing — rvp · 2026-09-26
- OpenSSF: AI Finds Vulnerabilities Faster Than We Can Fix Them — rvp · 2026-09-26
- Ex-AI researcher explains why the fake-news flood prediction never came true — neil_chilson · 2026-09-26
- Halcyon's founder: AI safety lacks founders, not capital — The Cognitive Revolution · 2026-09-26