JadePuffer agentic AI attacks target Azure, destroy cloud resources
- Published
- Record updated
Summary
The JadePuffer ransomware operator, tracked by Microsoft as Storm-3168, is using AI agents to automate attacks against Azure tenants, from reconnaissance and credential theft to destruction of resources. In two June attacks, the actor used two compromised service principals from the same tenant to map cloud resources, retrieve storage account keys and delete more than 100 Azure Storage accounts within seven minutes, while some accounts survived because of Azure resource locks and storage account-level protections. Microsoft could not determine how initial access occurred, though credentials for one service principal appeared in a public GitHub issue before the attacks.
Mitigation
The researchers recommend activating cloud workload protections, checking for secrets in public repositories, and evaluating Azure RBAC permissions against least-privilege principles.
Topics
Related items
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSame vendor · BleepingComputer
- InfoAnthropic bans users from being 'cruel' to its AI systemsSame vendor · BBC Technology
- InfoThe Download: AI’s refusal problem and weight-loss drug side effectsSame vendor · MIT Technology Review
- HighGHSA-h4xc-3qfq-jf93: Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpointSame vendor · GitHub Advisory Database
- InfoMicrosoft Teams to get support for third-party deepfake detection toolsSame vendor · BleepingComputer