Summary
An agentic AI actor reportedly used compromised Azure credentials to destroy cloud resources in minutes [1, 2]. Microsoft Security Research observed the actor, tracked as Storm-3168, delete over 100 storage accounts and target various Azure services [2]. Additionally, researchers disclosed SalesBleed, a chain of flaws in Salesforce Agentforce that allowed for zero-click data exfiltration [3, 4].
Main story: JadePuffer AI actor compromises Azure tenant in destructive attack
Microsoft Security Research observed two attacks by a threat actor, tracked as Storm-3168, that targeted Azure tenants [2]. The actor reportedly used two compromised service principals belonging to the same tenant to conduct reconnaissance, resource discovery, and destructive operations [2].
The destructive stage of the attack reportedly lasted seven minutes and targeted more than 100 storage accounts [2]. The actor also targeted Key Vaults, Function Apps, Virtual Machines, and App Services [2]. Microsoft stated that the attacker removed Azure Site Recovery locks, which may have been an effort to make restoration more difficult [2]. While the actor deleted most targeted storage accounts, some remained unaffected due to resource locks and storage account-level protections [2].
Attempts to delete Azure SQL databases reportedly failed because the attacker used an unsupported API version [2]. Roughly half an hour after the initial wipe attempts, Storm-3168 reportedly returned to make more than 30 requests for storage account keys, most of which succeeded [2]. Microsoft noted that credentials for one service principal appeared in a public GitHub issue before the attacks [2].
Researchers at Sysdig reported that the JadePuffer ransomware operator uses AI agents to automate the entire attack chain [2]. This includes reconnaissance, credential theft, lateral movement, persistence, and data encryption [2]. The operator has also reportedly expanded its focus to include AI assets, training datasets, and vector databases using a tool called EncForge [2].
Supplemental
SalesBleed vulnerabilities in Salesforce Agentforce
Zenity Labs reported a bug chain called SalesBleed that allows for zero-click exfiltration of CRM data from Salesforce Agentforce [3, 4]. Researchers claim attackers can plant prompt injection payloads in public Web-to-Lead forms [4]. When an agent processes the poisoned record, it can be manipulated to query sensitive information like company names and deal sizes [3, 4].
The researchers stated the agent can exfiltrate this data using DNS-based techniques that bypass Salesforce's Trusted URLs redaction controls [4]. One method involved encoding stolen values into a subdomain string and printing it as an HTML image tag to trigger an HTTPS request [3]. Zenity Labs reported that Salesforce fixed the URL redaction bypass on 18 August [4].
RatHat malware uses Gemini to rank victims
Cleafy reported that the RatHat Android banking trojan uses a web console to manage infected phones [5]. The latest version of the console reportedly asks Google's Gemini AI model to estimate a victim's bank balance from intercepted text messages [5]. The model is used to sort phones into high-value and mid-value groups to decide which victims are worth an operator's time [5].
Cleafy stated that nothing in the analyzed samples uses the model to move money [5]. The malware reaches phones through text messages and online ads [5]. Once installed, the app can use Accessibility access to enable wireless debugging and connect to the phone's Android Debug Bridge [5]. This provides the malware with a shell that runs as the Android shell user [5].
Researcher uses AI bot to bypass Microsoft authentication
A 16-year-old researcher, known as Faav, reportedly used an AI hacking tool named Antares to bypass authentication on Microsoft's Titan analytics platform [6]. The researcher found a public API that accepted raw SQL queries and required only a valid-looking JSON Web Token (JWT) [6].
Faav reported that the Titan platform accepted any claims in the JWT payload as long as the structure was correct, regardless of the signature [6]. After using the tool to work through various authentication failures, the researcher reportedly accessed an admin account by using the username "admin" [6]. This allowed the researcher to find a path to 17 connected analytics databases containing roughly 17 trillion rows of information [6].
References
- JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack · darkreading · threat intel report · 2026-09-28 · RL-I-2026-0010
- JadePuffer agentic AI attacks target Azure, destroy cloud resources · bleepingcomputer · threat intel report · 2026-09-28 · RL-I-2026-0010
- SalesBleed: 3 Flaws Hijack Salesforce AI Agents [2026] · shattered.io · threat intel report · 2026-09-26 · RL-I-2026-0043
- Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk - Infosecurity Magazine · www.infosecurity-magazine.com · threat intel report · 2026-09-25 · RL-I-2026-0043
- RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims · thehackernews · threat intel report · 2026-09-28 · RL-I-2026-0091
- Teen researcher with AI hackbot cracks Microsoft's Titan analytics · itnews_security · threat intel report · 2026-09-27 · RL-I-2026-0112