Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders. The post Storm-3168: Agentic-driven cloud attacks using compromised service principals appeared first on Microsoft Security Blog .
Storm-3168: Agentic-driven cloud attacks using compromised service principals
calendar_today
September 25, 2026
person
Microsoft Security Research, Yossi Weizman and Tushar Mudi
domain
microsoft-defender