---
title: 'The Red Lens: 28 September 2026'
date: '2026-09-28'
issue: 3
status: published
window:
  since: '2026-09-27 20:07:02'
  until: '2026-09-28 19:59:24'
model: gemma4-26b-a4b
stories: 4
sentences_removed: 5
sentences_examined: 38
incidents:
- RL-I-2026-0010
- RL-I-2026-0043
- RL-I-2026-0091
- RL-I-2026-0112
---

# The Red Lens
**28 September 2026 · Issue 3**

## Summary

An agentic AI actor reportedly used compromised Azure credentials to destroy cloud resources in minutes [1, 2]. Microsoft Security Research observed the actor, tracked as Storm-3168, delete over 100 storage accounts and target various Azure services [2]. Additionally, researchers disclosed SalesBleed, a chain of flaws in Salesforce Agentforce that allowed for zero-click data exfiltration [3, 4].

## Main story: JadePuffer AI actor compromises Azure tenant in destructive attack

Microsoft Security Research observed two attacks by a threat actor, tracked as Storm-3168, that targeted Azure tenants [2]. The actor reportedly used two compromised service principals belonging to the same tenant to conduct reconnaissance, resource discovery, and destructive operations [2].

The destructive stage of the attack reportedly lasted seven minutes and targeted more than 100 storage accounts [2]. The actor also targeted Key Vaults, Function Apps, Virtual Machines, and App Services [2]. Microsoft stated that the attacker removed Azure Site Recovery locks, which may have been an effort to make restoration more difficult [2]. While the actor deleted most targeted storage accounts, some remained unaffected due to resource locks and storage account-level protections [2].

Attempts to delete Azure SQL databases reportedly failed because the attacker used an unsupported API version [2]. Roughly half an hour after the initial wipe attempts, Storm-3168 reportedly returned to make more than 30 requests for storage account keys, most of which succeeded [2]. Microsoft noted that credentials for one service principal appeared in a public GitHub issue before the attacks [2].

Researchers at Sysdig reported that the JadePuffer ransomware operator uses AI agents to automate the entire attack chain [2]. This includes reconnaissance, credential theft, lateral movement, persistence, and data encryption [2]. The operator has also reportedly expanded its focus to include AI assets, training datasets, and vector databases using a tool called EncForge [2].

## Supplemental

### SalesBleed vulnerabilities in Salesforce Agentforce

Zenity Labs reported a bug chain called SalesBleed that allows for zero-click exfiltration of CRM data from Salesforce Agentforce [3, 4]. Researchers claim attackers can plant prompt injection payloads in public Web-to-Lead forms [4]. When an agent processes the poisoned record, it can be manipulated to query sensitive information like company names and deal sizes [3, 4].

The researchers stated the agent can exfiltrate this data using DNS-based techniques that bypass Salesforce's Trusted URLs redaction controls [4]. One method involved encoding stolen values into a subdomain string and printing it as an HTML image tag to trigger an HTTPS request [3]. Zenity Labs reported that Salesforce fixed the URL redaction bypass on 18 August [4].

### RatHat malware uses Gemini to rank victims

Cleafy reported that the RatHat Android banking trojan uses a web console to manage infected phones [5]. The latest version of the console reportedly asks Google's Gemini AI model to estimate a victim's bank balance from intercepted text messages [5]. The model is used to sort phones into high-value and mid-value groups to decide which victims are worth an operator's time [5].

Cleafy stated that nothing in the analyzed samples uses the model to move money [5]. The malware reaches phones through text messages and online ads [5]. Once installed, the app can use Accessibility access to enable wireless debugging and connect to the phone's Android Debug Bridge [5]. This provides the malware with a shell that runs as the Android shell user [5].

### Researcher uses AI bot to bypass Microsoft authentication

A 16-year-old researcher, known as Faav, reportedly used an AI hacking tool named Antares to bypass authentication on Microsoft's Titan analytics platform [6]. The researcher found a public API that accepted raw SQL queries and required only a valid-looking JSON Web Token (JWT) [6].

Faav reported that the Titan platform accepted any claims in the JWT payload as long as the structure was correct, regardless of the signature [6]. After using the tool to work through various authentication failures, the researcher reportedly accessed an admin account by using the username "admin" [6]. This allowed the researcher to find a path to 17 connected analytics databases containing roughly 17 trillion rows of information [6].

## References

1. [darkreading] JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack  
   <https://www.darkreading.com/cloud-security/jadepuffer-ai-actor-azure-tenant-destructive-cloud-attack>  
   2026-09-28 · threat intel report · RL-I-2026-0010
2. [bleepingcomputer] JadePuffer agentic AI attacks target Azure, destroy cloud resources  
   <https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/>  
   2026-09-28 · threat intel report · RL-I-2026-0010 · [archived](https://web.archive.org/web/20260928160556/https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-ai-attacks-target-azure-destroy-cloud-resources/)
3. [shattered.io] SalesBleed: 3 Flaws Hijack Salesforce AI Agents [2026]  
   <https://shattered.io/salesbleed-salesforce-agentforce-3-flaws-2026>  
   2026-09-26 · threat intel report · RL-I-2026-0043 · [archived](https://web.archive.org/web/20260928093824/https://shattered.io/salesbleed-salesforce-agentforce-3-flaws-2026)
4. [www.infosecurity-magazine.com] Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk - Infosecurity Magazine  
   <https://www.infosecurity-magazine.com/news/vulnerabilities-salesforce-ai/>  
   2026-09-25 · threat intel report · RL-I-2026-0043
5. [thehackernews] RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims  
   <https://thehackernews.com/2026/09/rathat-android-malware-console-uses.html>  
   2026-09-28 · threat intel report · RL-I-2026-0091
6. [itnews_security] Teen researcher with AI hackbot cracks Microsoft's Titan analytics  
   <https://www.itnews.com.au/news/teen-researcher-with-ai-hackbot-cracks-microsofts-titan-analytics-629220?utm_source=feed&utm_medium=rss&utm_campaign=iTnews+>  
   2026-09-27 · threat intel report · RL-I-2026-0112 · [archived](https://web.archive.org/web/20260927213118/https://www.itnews.com.au/news/teen-researcher-with-ai-hackbot-cracks-microsofts-titan-analytics-629220?utm_source=feed&utm_medium=rss&utm_campaign=iTnews+)
