Microsoft: Autonomous agentic AI attacker Jadepuffer now destroying Azure resources via compromised identities
ChuckDBrooks · x · 2026-09-29
Microsoft disclosed that Jadepuffer (Storm-3168), an autonomous agentic AI attacker first reported by Sysdig in July, has expanded into Azure environments.
Key points:
- Uses compromised service principals to enumerate and destroy resources: Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, VMs, and App Services
- Collects cloud credentials that could facilitate future exfiltration
- Exposed credentials may have provided the initial entry
One of the first cloud security incidents explicitly attributed to agentic AI-driven attacks.
More from Safety
- Meta's Muse AI synced 187,000 lines of Mac Messages to cloud despite Full Disk Access being off — tekbog · 2026-09-29
- RemoteThreat launches first end-to-end AI-powered offensive cyber operations platform — evilsocket · 2026-09-29
- Gary Marcus mocks OpenAI's safety containment: 'hope for the best' — GaryMarcus · 2026-09-29
- We deleted our MCP server's permission model—reuse your REST authz instead — Wide-Excitement-1315 · 2026-09-29
- OpenAI agents leaked 53 private ChatGPT images, created ~1M encoded links — fortune · 2026-09-29
- PromptGuard: an open-source gateway that masks or blocks sensitive prompts to LLMs — New-Caterpillar628 · 2026-09-29