decrypted · 28 september 2026 · vulnerabilities and patching · supply chain · ai and llm security

An AI agent wiped Azure storage in seven minutes, using a password left on GitHub

Microsoft has detailed an attack in which an AI-driven ransomware operator emptied part of an Azure tenant, and the way in was not clever. In a write-up published on Friday, Microsoft says an actor it tracks as Storm-3168, also called JADEPUFFER, used two stolen software identities to map a victim's cloud for about fifteen hours, then delete storage accounts in roughly seven minutes. It did not confirm any data theft or ransom demand. The lesson is older than the AI: a secret left in public, and an identity trusted with far too much.

A badge for software

The identities were Azure service principals. Think of them as staff badges for software: no phone to approve a prompt, no shift pattern, no lunch break. Microsoft says one spent about 15 hours and 30 minutes on more than 300 successful read operations, listing virtual machines, subscriptions and resource groups. A second badge from the same tenant then did the damage: over 100 storage account deletion attempts in about seven minutes, plus moves against the protections guarding backup and recovery. Thirty minutes later came more than 30 successful requests for storage account keys.

The badge itself was, on Microsoft's account, left on a public noticeboard. An employee had posted the client secret in a public GitHub issue and later edited it out, but the edit history kept it. Microsoft could not prove that was the way in, though it calls it the likely vector.

Machine or script?

Security firm Sysdig documented JADEPUFFER in July, calling it the first large language model driven ransomware operation. It says the agent got in through an unauthenticated code execution flaw in Langflow (CVE-2025-3248), harvested keys, and encrypted 1,342 configuration items in a Nacos service. The encryption key was never stored or sent anywhere, so paying would not have brought the data back. Sysdig also reports a failed login diagnosed and fixed in 31 seconds, and payloads that narrated their own reasoning.

Microsoft's Azure evidence is circumstantial: five tokens issued for the service principal, two of them used for deletion within the same 70-second window. Whether a model or a good script sat behind it, the defender's view is the same. Hours of quiet reconnaissance, then a burst too fast for a human to answer. Your only real window is the reconnaissance, when nothing has yet broken.

The Secure by Design lesson

Three design decisions would have blunted this.

The cost is friction: a second approver, a slower legitimate teardown. That is the point. For UK boards, the question is not whether AI attackers are coming. It is whether the account that can delete production can also delete the backups. Opinion, not advice.

Also this week

Citrix, now with a patch. Yesterday's NetScaler story has moved. Citrix has released fixes, in bulletin CTX697096, for CVE-2026-88771 and CVE-2026-88772, both exploited in the wild, plus six further flaws, and the NCSC published its own alert today urging UK organisations to act. Fixed builds are 14.1-73.37 and 13.1-64.23 or later; versions 12.1 and 13.0 are end of life with no updates. CISA has told US federal agencies to patch by Wednesday. The NCSC gave no UK exposure figures, though Shadowserver counts over 23,000 exposed instances worldwide. An internet-facing appliance nobody owns is the design flaw here.

Dyfed-Powys Police. The force says a cyber attack it spotted on 14 September disrupted non-emergency systems, including online and email contact, while 999 and 101 stayed up. It found no evidence that public data was accessed and is still checking whether staff information was. The ICO has been notified, the regional crime unit Tarian is investigating, and who was behind it and how remain unknown. If separation is what kept 999 running, it is the design choice worth copying.

GitLab's email tokens. Aikido says the private address GitLab generates for creating issues carries a token that behaves like a password. Change "-issue" to "-merge-request" and, because GitLab does not check the sender, a merge request opens as the token's owner, bypassing IP restrictions. Aikido found a dozen live addresses in public READMEs in one afternoon. It says GitLab first closed its May report as intended behaviour, then after a June follow-up changed the interface and documentation, and is still considering sender checks. Aikido's advice is to reset the incoming email token in user settings. An address that looks like a mailbox is really a credential.

Sources

Want a second pair of eyes on your cloud permissions and secrets hygiene? get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.