JadePuffer crims hijacked Azure identities and used them to blow up cloud resources

Microsoft says the JadePuffer threat actor used stolen Azure service principals to conduct reconnaissance, collect credentials, and delete large numbers of cloud resources, including storage accounts, Key Vault, and App Service components—activity consistent with preparing a ransomware or extortion event. For CIOs and IT leaders, this is a reminder that compromised machine identities can be just as damaging as stolen user accounts, making identity hygiene, secret management, and cloud recovery protections core business-resilience priorities.

The Register3 min read
Read full article
JadePuffer crims hijacked Azure identities and used them to blow up cloud resources

Read the full story at The Register →