https://www. microsoft.com/en-us/security/b log/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/ # CloudSecurity # Ransomware # Azure # CyberSecurity # ServiceP

https://www.

4 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Microsoft just discovered attackers are using compromised service principals to run autonomous agents in your cloud. Your infrastructure is now doing the work for them. Sleep well. https://www. micros

mastodon:infosec-exchangeother2d ago kagi ↗

Microsoft just discovered attackers are using compromised service principals to run autonomous agents in your cloud. Your infrastructure is now doing the work for them. Sleep well. https://www. microsoft.com/en-us/security/b log/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/

🤖 Microsoft details Storm-3168 (JADEPUFFER), the agentic ransomware op pivoting to Azure: compromised service principals drive control-plane recon and bulk deletion of Storage accounts, SQL databases

mastodon:infosec-exchangeother2d ago kagi ↗

🤖 Microsoft details Storm-3168 (JADEPUFFER), the agentic ransomware op pivoting to Azure: compromised service principals drive control-plane recon and bulk deletion of Storage accounts, SQL databases, Key Vaults, Function Apps and VMs. 🔗 https://www. microsoft.com/en-us/security/b log/2026/09/25/storm-3168-agentic-driven-cloud-attacks-using-compromised-service-principals/ # InfoSec # Ransomware

Microsoft's Storm-3168 post shows how cloud destruction works now. Two compromised service principals, one tenant. One spent fifteen hours reading everything. The other tried to delete over a hundred

mastodon:infosec-exchangeother17h ago kagi ↗

Microsoft's Storm-3168 post shows how cloud destruction works now. Two compromised service principals, one tenant. One spent fifteen hours reading everything. The other tried to delete over a hundred storage accounts in seven minutes, mostly succeeding, then took storage keys. The identity's own permissions did the work. The way in: a client secret in a public GitHub issue, later edited out. Edit