Storm-3168 repeated Azure App Services probing campaign
Campaign
Summary
Hide ▲
Show ▼
A repeated probing campaign from Storm-3168 linked infrastructure hit several Azure App Services across different customers, signaling coordinated cloud reconnaissance with potential follow-on access risk. The activity was judged likely automated or scripted because the work was split across multiple service principals and separated by timing gaps between operations.
Related Happenings
Langflow actively exploited initial access flaw (CVE-2025-3248)
Vulnerability
H score40
First: 28.09.2026 12:08
Last: 28.09.2026 12:08
Sources 1
How related:
The agentic attack exploited a known security flaw in Langflow (CVE-2025-3248) to break in, harvested credentials, burrowed deeper into the network, encrypted Nacos service configuration files, dropped the original database tables, and left a ransom note demanding a Bitcoin payment.
About this happening:
The Langflow flaw CVE-2025-3248 was exploited for initial access by JADEPUFFER, creating credential-harvesting and ransomware risk for exposed deployments. The...
Langflow actively exploited initial access flaw (CVE-2025-3248)
VulnerabilityHow related: The agentic attack exploited a known security flaw in Langflow (CVE-2025-3248) to break in, harvested credentials, burrowed deeper into the network, encrypted Nacos service configuration files, dropped the original database tables, and left a ransom note demanding a Bitcoin payment.
About this happening: The Langflow flaw CVE-2025-3248 was exploited for initial access by JADEPUFFER, creating credential-harvesting and ransomware risk for exposed deployments. The...
2026 Cloud misconfiguration patterns diverge across AWS, Azure, and Google Cloud
Trend
H score7
First: 07.09.2026 14:45
Last: 07.09.2026 14:45
Sources 1
About this happening:
A 2026 cloud security index found that misconfiguration risk looks very different across AWS, Azure, and Google Cloud, increasing the chance that teams misjudge th...
2026 Cloud misconfiguration patterns diverge across AWS, Azure, and Google Cloud
TrendAbout this happening: A 2026 cloud security index found that misconfiguration risk looks very different across AWS, Azure, and Google Cloud, increasing the chance that teams misjudge th...
Microsoft Teams desktop client on Windows launch delay disruption
Service Disruption
H score0
First: 04.09.2026 17:30
Last: 04.09.2026 17:30
Sources 1
About this happening:
Microsoft Teams on Windows is experiencing a known launch disruption that can prevent some users from loading the desktop client or delay startup by up to two minutes. The issue i...
Microsoft Teams desktop client on Windows launch delay disruption
Service DisruptionAbout this happening: Microsoft Teams on Windows is experiencing a known launch disruption that can prevent some users from loading the desktop client or delay startup by up to two minutes. The issue i...
Microsoft 365 apps search disruption
Service Disruption
H score0
First: 18.08.2026 12:24
Last: 18.08.2026 12:24
Sources 1
About this happening:
Microsoft is facing a search disruption in Microsoft 365 apps that is preventing some users from finding content in SharePoint Online, OneDrive, Outlook on the w...
Microsoft 365 apps search disruption
Service DisruptionAbout this happening: Microsoft is facing a search disruption in Microsoft 365 apps that is preventing some users from finding content in SharePoint Online, OneDrive, Outlook on the w...
Microsoft Azure and Microsoft 365 outage caused by maintenance bug
Service Disruption
H score0
First: 24.07.2026 18:41
Last: 24.07.2026 18:41
Sources 1
About this happening:
A maintenance-system bug triggered a massive Microsoft outage that disrupted access to Azure and Microsoft 365 services for customers tied to West US infrastru...
Microsoft Azure and Microsoft 365 outage caused by maintenance bug
Service DisruptionAbout this happening: A maintenance-system bug triggered a massive Microsoft outage that disrupted access to Azure and Microsoft 365 services for customers tied to West US infrastru...
Timeline
-
28.09.2026 12:08 2 articles · 3h ago
Storm-3168 probes several Azure App Services across different customers
Campaign Scope UpdateMicrosoft detected repeated probing from Storm-3168 linked infrastructure against several Azure App Services used by different customers. The activity appeared likely automated or scripted because the work was divided across multiple service principals and separated by timing gaps between operations.
Show sources
- JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources — thehackernews.com — 28.09.2026 12:08
- JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources — thehackernews.com — 28.09.2026 12:08