← The Red Lens: every edition

28 September 2026 · Issue 3

JadePuffer AI actor compromises Azure tenant in destructive attack

Markdown · JSON · RSS · For agents

Each reference carries its source's own evidence class. A story is never summarised by its strongest source.

Summary

An agentic AI actor reportedly used compromised Azure credentials to destroy cloud resources in minutes [1, 2]. Microsoft Security Research observed the actor, tracked as Storm-3168, delete over 100 storage accounts and target various Azure services [2]. Additionally, researchers disclosed SalesBleed, a chain of flaws in Salesforce Agentforce that allowed for zero-click data exfiltration [3, 4].

Main story: JadePuffer AI actor compromises Azure tenant in destructive attack

Microsoft Security Research observed two attacks by a threat actor, tracked as Storm-3168, that targeted Azure tenants [2]. The actor reportedly used two compromised service principals belonging to the same tenant to conduct reconnaissance, resource discovery, and destructive operations [2].

The destructive stage of the attack reportedly lasted seven minutes and targeted more than 100 storage accounts [2]. The actor also targeted Key Vaults, Function Apps, Virtual Machines, and App Services [2]. Microsoft stated that the attacker removed Azure Site Recovery locks, which may have been an effort to make restoration more difficult [2]. While the actor deleted most targeted storage accounts, some remained unaffected due to resource locks and storage account-level protections [2].

Attempts to delete Azure SQL databases reportedly failed because the attacker used an unsupported API version [2]. Roughly half an hour after the initial wipe attempts, Storm-3168 reportedly returned to make more than 30 requests for storage account keys, most of which succeeded [2]. Microsoft noted that credentials for one service principal appeared in a public GitHub issue before the attacks [2].

Researchers at Sysdig reported that the JadePuffer ransomware operator uses AI agents to automate the entire attack chain [2]. This includes reconnaissance, credential theft, lateral movement, persistence, and data encryption [2]. The operator has also reportedly expanded its focus to include AI assets, training datasets, and vector databases using a tool called EncForge [2].

Supplemental

SalesBleed vulnerabilities in Salesforce Agentforce

Zenity Labs reported a bug chain called SalesBleed that allows for zero-click exfiltration of CRM data from Salesforce Agentforce [3, 4]. Researchers claim attackers can plant prompt injection payloads in public Web-to-Lead forms [4]. When an agent processes the poisoned record, it can be manipulated to query sensitive information like company names and deal sizes [3, 4].

The researchers stated the agent can exfiltrate this data using DNS-based techniques that bypass Salesforce's Trusted URLs redaction controls [4]. One method involved encoding stolen values into a subdomain string and printing it as an HTML image tag to trigger an HTTPS request [3]. Zenity Labs reported that Salesforce fixed the URL redaction bypass on 18 August [4].

RatHat malware uses Gemini to rank victims

Cleafy reported that the RatHat Android banking trojan uses a web console to manage infected phones [5]. The latest version of the console reportedly asks Google's Gemini AI model to estimate a victim's bank balance from intercepted text messages [5]. The model is used to sort phones into high-value and mid-value groups to decide which victims are worth an operator's time [5].

Cleafy stated that nothing in the analyzed samples uses the model to move money [5]. The malware reaches phones through text messages and online ads [5]. Once installed, the app can use Accessibility access to enable wireless debugging and connect to the phone's Android Debug Bridge [5]. This provides the malware with a shell that runs as the Android shell user [5].

Researcher uses AI bot to bypass Microsoft authentication

A 16-year-old researcher, known as Faav, reportedly used an AI hacking tool named Antares to bypass authentication on Microsoft's Titan analytics platform [6]. The researcher found a public API that accepted raw SQL queries and required only a valid-looking JSON Web Token (JWT) [6].

Faav reported that the Titan platform accepted any claims in the JWT payload as long as the structure was correct, regardless of the signature [6]. After using the tool to work through various authentication failures, the researcher reportedly accessed an admin account by using the username "admin" [6]. This allowed the researcher to find a path to 17 connected analytics databases containing roughly 17 trillion rows of information [6].

References

  1. JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack · darkreading · threat intel report · 2026-09-28 · RL-I-2026-0010
  2. JadePuffer agentic AI attacks target Azure, destroy cloud resources · bleepingcomputer · threat intel report · 2026-09-28 · RL-I-2026-0010
  3. SalesBleed: 3 Flaws Hijack Salesforce AI Agents [2026] · shattered.io · threat intel report · 2026-09-26 · RL-I-2026-0043
  4. Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk - Infosecurity Magazine · www.infosecurity-magazine.com · threat intel report · 2026-09-25 · RL-I-2026-0043
  5. RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims · thehackernews · threat intel report · 2026-09-28 · RL-I-2026-0091
  6. Teen researcher with AI hackbot cracks Microsoft's Titan analytics · itnews_security · threat intel report · 2026-09-27 · RL-I-2026-0112