{
 "date": "2026-09-28",
 "issue": 3,
 "status": "published",
 "incidents": [
  "RL-I-2026-0010",
  "RL-I-2026-0043",
  "RL-I-2026-0091",
  "RL-I-2026-0112"
 ],
 "removed": 5,
 "examined": 38,
 "windowUntil": "2026-09-28 19:59:24",
 "summary": [
  "An agentic AI actor reportedly used compromised Azure credentials to destroy cloud resources in minutes [1, 2]. Microsoft Security Research observed the actor, tracked as Storm-3168, delete over 100 storage accounts and target various Azure services [2]. Additionally, researchers disclosed SalesBleed, a chain of flaws in Salesforce Agentforce that allowed for zero-click data exfiltration [3, 4]."
 ],
 "main": {
  "headline": "JadePuffer AI actor compromises Azure tenant in destructive attack",
  "paragraphs": [
   "Microsoft Security Research observed two attacks by a threat actor, tracked as Storm-3168, that targeted Azure tenants [2]. The actor reportedly used two compromised service principals belonging to the same tenant to conduct reconnaissance, resource discovery, and destructive operations [2].",
   "The destructive stage of the attack reportedly lasted seven minutes and targeted more than 100 storage accounts [2]. The actor also targeted Key Vaults, Function Apps, Virtual Machines, and App Services [2]. Microsoft stated that the attacker removed Azure Site Recovery locks, which may have been an effort to make restoration more difficult [2]. While the actor deleted most targeted storage accounts, some remained unaffected due to resource locks and storage account-level protections [2].",
   "Attempts to delete Azure SQL databases reportedly failed because the attacker used an unsupported API version [2]. Roughly half an hour after the initial wipe attempts, Storm-3168 reportedly returned to make more than 30 requests for storage account keys, most of which succeeded [2]. Microsoft noted that credentials for one service principal appeared in a public GitHub issue before the attacks [2].",
   "Researchers at Sysdig reported that the JadePuffer ransomware operator uses AI agents to automate the entire attack chain [2]. This includes reconnaissance, credential theft, lateral movement, persistence, and data encryption [2]. The operator has also reportedly expanded its focus to include AI assets, training datasets, and vector databases using a tool called EncForge [2]."
  ]
 },
 "supplementals": [
  {
   "headline": "SalesBleed vulnerabilities in Salesforce Agentforce",
   "paragraphs": [
    "Zenity Labs reported a bug chain called SalesBleed that allows for zero-click exfiltration of CRM data from Salesforce Agentforce [3, 4]. Researchers claim attackers can plant prompt injection payloads in public Web-to-Lead forms [4]. When an agent processes the poisoned record, it can be manipulated to query sensitive information like company names and deal sizes [3, 4].",
    "The researchers stated the agent can exfiltrate this data using DNS-based techniques that bypass Salesforce's Trusted URLs redaction controls [4]. One method involved encoding stolen values into a subdomain string and printing it as an HTML image tag to trigger an HTTPS request [3]. Zenity Labs reported that Salesforce fixed the URL redaction bypass on 18 August [4]."
   ]
  },
  {
   "headline": "RatHat malware uses Gemini to rank victims",
   "paragraphs": [
    "Cleafy reported that the RatHat Android banking trojan uses a web console to manage infected phones [5]. The latest version of the console reportedly asks Google's Gemini AI model to estimate a victim's bank balance from intercepted text messages [5]. The model is used to sort phones into high-value and mid-value groups to decide which victims are worth an operator's time [5].",
    "Cleafy stated that nothing in the analyzed samples uses the model to move money [5]. The malware reaches phones through text messages and online ads [5]. Once installed, the app can use Accessibility access to enable wireless debugging and connect to the phone's Android Debug Bridge [5]. This provides the malware with a shell that runs as the Android shell user [5]."
   ]
  },
  {
   "headline": "Researcher uses AI bot to bypass Microsoft authentication",
   "paragraphs": [
    "A 16-year-old researcher, known as Faav, reportedly used an AI hacking tool named Antares to bypass authentication on Microsoft's Titan analytics platform [6]. The researcher found a public API that accepted raw SQL queries and required only a valid-looking JSON Web Token (JWT) [6].",
    "Faav reported that the Titan platform accepted any claims in the JWT payload as long as the structure was correct, regardless of the signature [6]. After using the tool to work through various authentication failures, the researcher reportedly accessed an admin account by using the username \"admin\" [6]. This allowed the researcher to find a path to 17 connected analytics databases containing roughly 17 trillion rows of information [6]."
   ]
  }
 ],
 "references": [
  {
   "n": 1,
   "source": "darkreading",
   "title": "JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack",
   "url": "https://www.darkreading.com/cloud-security/jadepuffer-ai-actor-azure-tenant-destructive-cloud-attack",
   "published": "2026-09-28",
   "evidenceClass": "threat_intel_report",
   "incidentId": "RL-I-2026-0010",
   "archiveUrl": null
  },
  {
   "n": 2,
   "source": "bleepingcomputer",
   "title": "JadePuffer agentic AI attacks target Azure, destroy cloud resources",
   "url": "https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/",
   "published": "2026-09-28",
   "evidenceClass": "threat_intel_report",
   "incidentId": "RL-I-2026-0010",
   "archiveUrl": "https://web.archive.org/web/20260928160556/https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/"
  },
  {
   "n": 3,
   "source": "shattered.io",
   "title": "SalesBleed: 3 Flaws Hijack Salesforce AI Agents [2026]",
   "url": "https://shattered.io/salesbleed-salesforce-agentforce-3-flaws-2026",
   "published": "2026-09-26",
   "evidenceClass": "threat_intel_report",
   "incidentId": "RL-I-2026-0043",
   "archiveUrl": "https://web.archive.org/web/20260928093824/https://shattered.io/salesbleed-salesforce-agentforce-3-flaws-2026"
  },
  {
   "n": 4,
   "source": "www.infosecurity-magazine.com",
   "title": "Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk - Infosecurity Magazine",
   "url": "https://www.infosecurity-magazine.com/news/vulnerabilities-salesforce-ai/",
   "published": "2026-09-25",
   "evidenceClass": "threat_intel_report",
   "incidentId": "RL-I-2026-0043",
   "archiveUrl": null
  },
  {
   "n": 5,
   "source": "thehackernews",
   "title": "RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims",
   "url": "https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html",
   "published": "2026-09-28",
   "evidenceClass": "threat_intel_report",
   "incidentId": "RL-I-2026-0091",
   "archiveUrl": null
  },
  {
   "n": 6,
   "source": "itnews_security",
   "title": "Teen researcher with AI hackbot cracks Microsoft's Titan analytics",
   "url": "https://www.itnews.com.au/news/teen-researcher-with-ai-hackbot-cracks-microsofts-titan-analytics-629220?utm_source=feed&utm_medium=rss&utm_campaign=iTnews+",
   "published": "2026-09-27",
   "evidenceClass": "threat_intel_report",
   "incidentId": "RL-I-2026-0112",
   "archiveUrl": "https://web.archive.org/web/20260927213118/https://www.itnews.com.au/news/teen-researcher-with-ai-hackbot-cracks-microsofts-titan-analytics-629220?utm_source=feed&utm_medium=rss&utm_campaign=iTnews+"
  }
 ]
}
