Technology
Microsoft links agentic ransomware crew to a destructive Azure campaign
Microsoft Security Research tied the JADEPUFFER crew, tracked as Storm-3168, to about 18 hours of activity in early June in which two compromised Azure service principals belonging to the same tenant performed over 300 reads for reconnaissance and then more than 150 destructive or credential-collection operations in 35 minutes. Most of over 100 targeted Azure Storage accounts were deleted, along with a Key Vault, Function App and App Service plan; resource locks blocked some attempts. No ransom note or confirmed exfiltration was seen.