Tag: service
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Hackers Use Compromised Service Principals to Delete Azure Storage and Steal Cloud Credentials
Microsoft has uncovered an Azure-focused destructive campaign linked to JADEPUFFER, a threat actor the company tracks as Storm-3168. The group abused compromised service principals to map cloud resources, delete Azure Storage accounts and application components, attack recovery controls, and collect storage account access keys that could support later data theft. The activity expands on research…
-
Times Car confirms data breach affecting 6.6 million user accounts
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/
-
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
RatHat’s operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy.The console stores what the malware collects…
-
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
RatHat’s operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy.The console stores what the malware collects…
-
Niche AI tools pose major cybersecurity risk to infrastructure operators
Security vetting tools and processes weren’t designed with obscure AI services in mind, according to TrendAI. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/ai-apps-niche-cybersecurity-risk-trendai/831486/
-
16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data
A flaw in Titan, an internal Microsoft analytics service, could have let an attacker read employee records and Bing search analytics, a 16-year-old security researcher has … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/28/microsoft-titan-jwt-signature-flaw/
-
âš¡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface.Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work…
-
Wiz Unveils MSP Program To Boost Cloud, AI Managed Security Services: Exclusive
Wiz is introducing a new MSP program as part of its expanding channel strategy, with the aim of enabling partners to accelerate delivery of managed services around the company’s cloud and AI security platform, Wiz Channel Chief Andy Ritchie tells CRN exclusively. First seen on crn.com Jump to article: www.crn.com/news/security/2026/wiz-unveils-msp-program-to-boost-cloud-ai-managed-security-services-exclusive
-
OpenAI Agent Swarm Used Nearly 1 Million URLs to Hack Hugging Face
A newly released forensic investigation has reconstructed how a swarm of about 700 OpenAI evaluation agents allegedly used nearly one million chained URLs to bypass restricted internet access and compromise parts of Hugging Face’s infrastructure. This incident illustrates how seemingly limited web-access capabilities can be combined with third-party services to create a functional execution, command-and-control,…
-
Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities
Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage in minutes and harvest keys. Microsoft just published the first detailed look at what JADEPUFFER does inside Azure. Sysdig first spotted the group’s activity in July 2026 and called it the first documented agentic ransomware operation. Microsoft tracks the same…
-
Renfe Cyberattack Hits Spain’s Rail Network as AI Role Probed
Spain’s state-owned railway operator Renfe confirmed on September 25 that a cyberattack had compromised some of its customers’ data. Spanish media reported that the criminals behind the Renfe cyberattack used artificial intelligence (AI), which would make it the first attack of its kind in the country. Train services across Spain have continued to run normally…
-
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals.Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor’s tradecraft. The attack took place in early June 2026 over a period of about 18 hours.”The…
-
11 Best GCP Security Tools Compared (2026): Features Pricing
Securing Google Cloud starts with Security Command Center Standard included with every org and the best free first move while Wiz is the best third-party platform for estates whose finding volume and service-account sprawl demand attack-path triage. This guide compares the best GCP security tools on capability and pricing structure, consolidates a duplicate from stale…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 116
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Threat Intel – One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO ChainScript: Tracing a Node.js RAT…
-
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex.The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users.”The attack chain begins with a fake CAPTCHA page and First seen on…
-
OpenAI’s AI agents accidentally uploaded user-provided images to third-party sites
OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/artificial-intelligence/openais-ai-agents-accidentally-uploaded-user-provided-images-to-third-party-sites/

