thehackernews.com
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources
Microsoft identified an 18‑hour Azure breach in early June 2026, where the JADEPUFFER threat actor leveraged two compromised service principals to enumerate and delete resources. The attackers targeted Azure Storage Accounts, SQL databases, Key Vaults, Function Apps, App Services, and Virtual Machines, executing over 300 read operations and more than 150 destructive actions in a 35‑minute burst. Most storage accounts were deleted, though resource locks and deletion protection halted a few attempts. The compromise stemmed from a [...]