@itlandytech: Microsoft researchers have linked the threat actor behind JadePuffer (tracked as Storm-3168)—the first documented LLM-driven ransomware—to a massive cloud attack using compromised Azure identities. Here is what happened and why it matters for cloud security teams: The Attack Vector The threat actors hijacked two service principals (machine identities) within a single Azure tenant. The likely root cause? Plaintext credentials previously exposed in a public GitHub issue. 18 Hours of Escalation * Recon & Discovery: Over 15+ hours, one service principal ran 300+ read operations across Azure VMs, subscriptions, and resource groups using python-requests. * Credential Hunting: The attacker targeted Azure App Service configuration stores and executed ListKeys calls to extract access keys—including those for Azure Site Recovery. * Mass Resource Destruction: In a 7-minute window, the secondary identity attempted to delete over 100 Azure Storage accounts, along with Key Vaults, Function Apps, and SQL databases. Key Takeaways for Security Leaders * Machine Identities Need Strict Guardrails: Non-human credentials (service principals) are prime targets. Implement strict Least Privilege and continuous rotation. * Resource Locks Save the Day: Azure resource locks and account-level deletion protections successfully blocked multiple destruction attempts, including backup locks. * Secret Hygiene Remains Step Zero: Automated secrets scanning on public and internal code repositories is non-negotiable. As AI agents automate both reconnaissance and execution, speed to detection is no longer optional—it is the baseline. #CloudSecurity #CyberSecurity #Azure #Ransomware #IdentitySecurity

itlandytech
itlandytech
Open In TikTok:
Region: GB
Tuesday 29 September 2026 10:23:46 GMT
784
11
0
0

Music

Download

Comments

There are no more comments for this video.
To see more videos from user @itlandytech, please go to the Tikwm homepage.

Other Videos


About