Storm-3168 used stolen Azure identities to map an environment, destroy cloud resources and collect storage keys within ...
In an incident observed in early June 2026, attackers used two compromised service principals application identities used to ...
Storm-3168, an AI-orchestrated threat actor also known as JADEPUFFER, used two compromised service principals to delete 100+ ...
Microsoft says Jadepuffer, an autonomous agentic AI attacker first reported in July, is now targeting Azure resources; ...
Microsoft details Storm-3168, the JADEPUFFER-linked actor that used stolen service principals to delete Azure storage and ...
Confirmed on September 27, 2026ConclusionOrganizations using Azure AI Anomaly Detector must switch to operations that do not rely on API calls to the legacy service before it is retired on October 1, ...
Microsoft has uncovered an Azure-focused destructive campaign tied to Storm-3168, also known as JADEPUFFER, in which ...
Slicing bytes copies. On a small payload nobody notices, but slice a large packet or image buffer in a loop and the copies ...
Cactus Compute's Needle 2 is a 14MB function-calling model that turns typed instructions into Python function calls on the ...
September 22, 2026ConclusionOrganizations using Python 2.7, Python 3.8, PowerShell 7.1, or PowerShell 7.2 runbooks in Azure Automation must identify the affected items and complete the decision-making ...
Exploiting Unauthenticated API Gateways in AWS September 21, 2026 sara.pearlman@guidepointsecurity.com BLOG 5 min. Over the past year, GuidePoint’s Threat and Attack Simulation (TAS) team has ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results