The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals.Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor’s tradecraft. The attack took place in early June 2026 over a period of about 18 hours.”The destructive operations
First seen on thehackernews.com
Jump to article: thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html
![]()

