AI Weekly Malaysia

Back to items Summaries

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

ID
29245
Status
summarized
Published
28 Sep 2026, 5:08 PM
Fetched
28 Sep 2026, 6:28 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/jadepuffer-linked-attackers-used.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.5
Created
28 Sep 2026, 6:29 PM
Tags
Audience
developersai_ml_learnersai_agent_userssaas_startup_founders

What happened

Microsoft, tracking the actor as Storm-3168, reports that JADEPUFFER-linked attackers used two compromised service principals in a single Azure tenant to run destructive operations over about 18 hours in early June 2026, deleting Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, recovery protection locks, Virtual Machines, and App Services. JADEPUFFER was first documented by Sysdig as the first ransomware operation run end-to-end with an LLM, entering through a known Langflow flaw (CVE-2025-3248), and the same Langflow instance was later hit again with ENCFORGE, a Go-based strain that scans roughly 180 file extensions covering model checkpoints, vector databases, training datasets, and embedding indices, plus macOS Keychain stores, Xcode project files, and Apple Pages and Numbers documents.

Why it matters

Three concrete decisions: patch Langflow for CVE-2025-3248 if you self-host it, because that was the documented entry point. Don't assume Azure-native recovery saves you here, since recovery protection locks were among the deleted resources, so keep copies of vector databases, model checkpoints, and training datasets outside the subscription that runs them. And inventory your service principals and what each one can delete, because the access in this incident came from service principals in one tenant, not from user accounts.

Discussion angle

Ask who in the room can list their tenant's service principals and say what each is allowed to delete, then ask where their model checkpoints and vector DB backups actually live relative to the workload subscription.

Top