Connect with us

Tech & AI

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Published

on

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group.

The company provides home medical devices, supplies, and related services, including sleep-apnea and respiratory equipment, oxygen therapy, hospital beds, and mobility products.

AdaptHealth first disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC) on July 2, 2026, informing that attackers accessed its systems and exfiltrated private data.

At the time, AdaptHealth’s investigation confirmed the intrusion occurred earlier and involved access to cloud-based business applications, including certain internal patient management systems, document storage platforms, and electronic health record system portals.

Advertisement

On June 15, an unnamed threat actor contacted AdaptHealth to demand a ransom payment in exchange for not leaking the stolen data.

AdaptHealth added that the breach occurred through a successful social engineering ploy that compromised the privileged account of a third-party contractor.

In an update on August 14, AdaptHealth informed that the compromise had occurred on June 5 and may have exposed the following data:

  • Full names
  • Contact information
  • Demographic information
  • Health insurance information
  • Health information

Impacted individuals should have already received a data breach notification with instructions on how to enroll in a free-of-charge 12-month credit monitoring and identity protection service.

AdaptHealth stated at the time that it had found no evidence of identity theft, fraud, or other misuse of data stolen in the attack.

Advertisement

According to information on the company’s website, AdaptHealth served about 4.1 million patients across all 50 U.S. states through a network of 680 locations as of July 2024.

In a submission to the U.S. Department of Health and Human Services, the AdaptHealth data breach affects 4,115,802 individuals.

The HIPAA Journal previously reported that ShinyHunters was responsible for the attack, based on the threat actor adding the company to the list of victims.

However, BleepingComputer coould not find an AdaptHealth entry on ShinyHunter’s extortion portal, an indication that the threat actor removed the company.

Advertisement

AdaptHealth’s confirmation of the data breach impact follows similar recent disclosures from health-tech firms Aesto Health, CareCloud, and Unlimited Technology Systems.

McKesson and Nutex Health also disclosed data breach incidents late last month, but neither has determined the number of impacted individuals yet.


article image

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report

Source link

Advertisement
Continue Reading
Click to comment

You must be logged in to post a comment Login

Leave a Reply

Tech & AI

The Metric Is Not The Mission: When The Maps Became The Territory

Published

on

The Metric Is Not the Mission is a ten-part examination of how Big Tech moved from building and expanding the open internet to increasingly shaping it around its own metrics, incentives and assumptions. Across the series, the argument follows the evolution of the platform economy—from the optimism of the early internet to the growing tensions around power, prediction, geopolitics, accountability and the future of digital life.

The series will be published in two parts each week over five weeks, with each installment building on the one before it. At the end of the series, the complete essay will be brought together in a single PDF edition, providing the full argument in one place.

Part III: When the Maps Became the Territory

In Part II, the story turned on a crucial distinction: measuring behavior is not the same as understanding people. Part III takes that idea further, examining what happens when the platforms’ representations of the world begin to substitute for the world itself.

There is a curious tendency among successful technologies to disappear. Not physically, of course, but cognitively. Once they become sufficiently embedded in everyday life, they cease to be experienced as technologies at all. Electricity is no longer a marvel of engineering but an expectation. We do not admire the plumbing each time we turn on a tap, nor do we reflect on the extraordinary complexity of global logistics every time fresh fruit appears on supermarket shelves in the middle of winter. The greatest infrastructures become invisible because they succeed so completely that we mistake them for part of the natural order.

Advertisement

The internet reached that point sometime during the second decade of the twenty-first century. Yet something else happened along the way that proved far more consequential. As the network itself faded into the background, the platforms through which most people experienced it moved decisively into the foreground. Increasingly, users no longer spoke about “going online.” They spoke about opening an app.

That linguistic shift deserves more attention than it usually receives. Language often reveals structural change before statistics do. To “browse the web” implied movement across an open landscape whose boundaries were undefined. One followed links, discovered obscure websites, stumbled upon ideas that had not been recommended by anyone, and occasionally became gloriously lost. The experience resembled wandering through an unfamiliar city with no particular destination in mind. Serendipity was not a flaw in the architecture; it was one of its defining virtues.

Applications altered that relationship almost without anyone noticing. They replaced geography with destination. Instead of entering a network whose possibilities remained unknown, we entered environments that had already been organized on our behalf. The internet did not disappear, but it became increasingly hidden beneath layers of interface, recommendation and curation. Like passengers traveling through an airport without ever seeing the city beyond the terminal, we continued moving through digital space while encountering only the carefully managed environments that had been prepared for us.

This transformation is often described as an inevitable consequence of convenience. While accurate in its own right, this explanation offers an incomplete narrative. Convenience was certainly the language through which the platforms justified many of their design choices. Friction was treated as the great enemy of the digital age. Every additional click became an obstacle to be eliminated. Every decision that users might otherwise make for themselves could instead be anticipated by software. Recommendation replaced search. Autoplay replaced choice. Infinite scrolling replaced endings. The future, we were told, belonged to experiences so seamless that they would feel almost effortless. And they did.

Advertisement

It is difficult to criticize convenience because convenience is genuinely valuable. Few people wish to return to an internet in which finding information required memorizing obscure web addresses or navigating labyrinthine directories. The platforms did not succeed by forcing people into inferior experiences. They succeeded because, for many years, they built better ones.

Yet convenience has always carried an intellectual cost. Every technology that removes friction also removes moments of deliberation. The elevator spares us the staircase but also the awareness of distance. Satellite navigation ensures that we rarely become lost, while quietly diminishing our ability to construct mental maps of the places through which we travel. Streaming services relieve us of searching for entertainment, but in doing so they also shape the boundaries of what we are likely to discover. Every act of technological simplification transfers a small measure of agency from the individual to the system.

The internet had originally been built on a different assumption. Its underlying protocols did remarkably little. They did not decide which website deserved prominence, which ideas should travel furthest, or which communities ought to flourish. Their genius lay precisely in their restraint. They created conditions under which others could innovate without first requesting permission. The web itself functioned less like a product than like a constitutional order: a simple framework within which extraordinary diversity could emerge.

Platforms gradually adopted the opposite philosophy. They did not merely provide the rules of the game; increasingly, they became active participants in every interaction taking place within it. They selected what deserved attention, inferred what users might prefer before users themselves knew it, prioritized certain relationships over others and determined, through millions of microscopic computational decisions, the contours of everyday experience. The architecture became less constitutional than managerial.

Advertisement

There is an illuminating parallel here with the history of cities. The most enduring cities are rarely the ones that have been planned in every detail. They are those that accumulated layer upon layer of human activity over centuries, adapting continuously to changing needs without ever fully surrendering their unpredictability. One finds unexpected bookshops beside cafés, workshops hidden behind apartment blocks, public squares appropriated for demonstrations one week and festivals the next. Their vitality emerges not from perfect organization but from the freedom they grant people to appropriate space in ways that planners never anticipated.

Shopping malls operate according to an altogether different logic. They are meticulously designed environments in which every entrance, corridor, sightline, and seating area has been carefully considered. Music, lighting, and architecture work together to produce an experience that feels spontaneous while being anything but. There is comfort in their orderliness. They are clean, efficient, and reassuringly predictable. Yet no one mistakes a shopping mall for a city. Its purpose is not to cultivate civic life but to optimize a particular set of behaviors within a privately governed space.

The analogy is imperfect, as all analogies are, but it captures something essential about the transformation of the internet. The early web invited participation because it remained fundamentally unfinished. It assumed that users would contribute to shaping it. Today’s dominant platforms present themselves as complete worlds. Participation still exists, but it takes place within boundaries established elsewhere. Users generate the content while the architecture remains firmly in corporate hands.

Perhaps this is why the language of “community” has begun to feel strangely hollow. Communities, in the classical sense, are rarely designed. They emerge through shared experience, mutual obligation, and a degree of unpredictability that no algorithm can fully reproduce. Platforms, by contrast, increasingly treat community as an engineering problem to be optimized. They recommend friendships, suggest conversations, rank relevance, suppress friction, and amplify interaction according to models whose objectives are necessarily commercial because the organizations that develop them are commercial enterprises.

Advertisement

None of this should be understood as an accusation of bad faith. Many of the engineers responsible for these systems genuinely believed they were improving people’s lives. The difficulty lies elsewhere. Every large institution eventually begins to confuse the optimization of its own internal metrics with the fulfillment of its original purpose. Universities sometimes mistake publication counts for scholarship. Hospitals occasionally confuse efficiency with care. Governments become preoccupied with administrative process rather than public service. Technology companies are no different. The indicators that make sense within an organization slowly become proxies for the world outside it. The metric is not the mission. This is the point at which the maps begin to replace the territory.

The extraordinary quantities of behavioral data collected by digital platforms produce an understandable confidence. When one can observe billions of interactions each day, it becomes tempting to believe that society itself has become legible. Human behavior appears measurable, predictable and, increasingly, governable. The platform begins to resemble reality because so much of reality passes through the platform.

Yet the map is never the territory. It captures what can be measured, not everything that matters. A map records roads but not the reasons people travel. It identifies cities without conveying the lives unfolding within them. Likewise, recommendation systems observe behavior with astonishing precision while remaining largely indifferent to experience itself. They recognize patterns without necessarily understanding meaning.

That distinction mattered little while the platforms continued solving the problems that had made them indispensable. It becomes far more consequential once they begin confronting a world that no longer resembles the one for which they were originally designed. Because societies have changed; politics has changed; and, the internet has changed. The question is whether the companies that grew powerful by interpreting one era have noticed that another has already begun.

Advertisement

Konstantinos Komaitis, PhD, is a veteran of developing and analysing Internet policy to ensure an open and global Internet.

Filed Under: behavior, big tech, metric not mission, open internet, optimization, platforms, understanding

Source link

Advertisement
Continue Reading

Tech & AI

Boox Announces the Picco, Its Smallest E-Reader Ever (2026)

Published

on

While smartphones won’t stop getting bigger, e-readers seem to be getting smaller. Boox has been at the forefront with one of the most popular small e-readers, the Boox Palma, and now it is adding an even smaller model.

Boox announced the Picco, with preorders opening today. Its screen is just under 4 inches (3.97 to be exact), making it about the size of a playing card. It’s even smaller than the Xteink X4 Pro I tested earlier this year, which has a 4.3-inch screen (but just slightly larger than the 3.7-inch Xteink X3), and considerably smaller than the upcoming Boox Palma 3’s 6.19-inch screen. I liked the size of the Xteink in my hand, but navigating the interface and getting books were challenging, so I’m excited to see another option in that smaller size from a maker with more accessible ebooks (though still not as convenient as a Kindle or Kobo with their built-in stores).

The Picco will cost $100 and is expected to ship in November. I’ll be testing it soon, but in the meantime, here are the details if you’ve been eyeing a tiny e-reader.

An E-Reader for Productivity

Boox Announces the Picco Its Smallest EReader Ever

Courtesy of Boox

The Boox Picco has a monochrome screen with a resolution of 235 pixels per inch and an adjustable front light that switches between warm- and cool-toned lighting. The microSD card slot supports up to 2 TB of flash memory storage (a 16 GB card is included). There are both a touchscreen and physical page-turning controls, thanks to the buttons on the side of the device. The case has a magnetic ring so you can attach it to the back of a smartphone, though I’ll have to see how well it fits when I test it, as I had mixed results attaching an Xteink to my phone due to both fit and magnet strength.

Advertisement
Image may contain Electronics and Remote Control

Courtesy of Boox

Boox says the Picco will have a streamlined operating system focused on reading and digital utility tools. It’s also the first in what Boox calls its Tiles lineup, which is how you’ll access ebooks on this device. You can also use web and USB-C file transfers (the Picco has Wi-Fi and Bluetooth connectivity) to get ebooks onto the Picco. The Picco also has the Pomodoro, Todo, and Countdown apps, so you can use it as both an e-reader and a productivity gadget—handy, and a bigger motivation to keep it attached to the back of your phone even when you aren’t reading.

I’m intrigued to see it in action. Boox’s most popular e-reader could become the Picco over the Palma 3, but we’ll have to wait for both devices to become available to see which is the better buy. Stay tuned for my reviews of both when they come out.


Power up with unlimited access to WIRED. Get best-in-class reporting and exclusive subscriber content that’s too important to ignore. Subscribe Today.

Source link

Advertisement
Continue Reading

Tech & AI

Discord Is Testing A Lightweight Mode To Free Up Resources While Gaming

Published

on

But a Chromium-based design means it can only be so efficient.

Discord is working on a new mode for its social platform that it says might be less resource-intensive. Screenshots of an option called Game Mode began circulating on social media over the weekend. The description shown for the Game Mode toggle states that it will “Reduce Discord’s CPU and GPU usage while a game is running.” By making the chat platform less resource-intensive, concurrently running software should be able to run more smoothly.

Today, the company confirmed on X that this experimental mode will begin rolling out to its users next week. The brief official announcement about Game Mode added that Discord is “aiming to add more resource-saving features over time.”

Discord is based on the Electron web app framework, which uses Javascript and Chromium for creating software. The open-source Chromium, which is the basis for Google’s Chrome and several other browsers, is not known as the most efficient tool for web development. A feature like Game Mode could offer some performance improvements, especially while also running a beefy AAA game on the same machine, but there may only be so far that Discord will be able to streamline on its current architecture.

Advertisement

Source link

Advertisement
Continue Reading

Tech & AI

Meta-Led Anti-Terrorism Group Faces Mass Resignation of Expert Advisers

Published

on

Six of the nine independent experts on the advisory board of the Global Internet Forum to Counter Terrorism—a consortium run by several of the biggest US tech companies—resigned on Monday, according to a letter seen by WIRED and interviews with three of the people.

The tensions between the independent advisory committee and the GIFCT date back to an email the counterterrorism and free speech experts received in July from Meta’s Nell McCarthy, a vice president overseeing content policy. For years, the group had advised the GIFCT on how to prevent platforms from becoming havens for the radical organizations and individuals blamed for some of the world’s worst mass violence.

But McCarthy wrote that while the consortium welcomed the experts’ insights on violent trends, it no longer desired their scrutiny on the effectiveness of Big Tech’s efforts to curtail violence. Meta and other leaders wanted to “refresh” the 6-year-old independent advisory committee the experts sat on, she wrote. Meta currently serves as chair of GIFCT’s operating board, giving it outsized influence over policy changes, though other companies on the panel must ultimately approve.

New additions to the rotating advisory committee had previously been elected by current members; under the plan laid out in July, they would instead be picked by tech companies. The committee would be barred from weighing in on key topics such as the consortium’s performance and making recommendations together as a group. Its role as a watchdog would be neutered, advisers believed.

Advertisement

In their resignation letter, the departing members of the committee wrote that their appeals against the plan had been “ignored” and that, in turn, they had “lost confidence in the GIFCT’s ability to deliver effectively on its founding mission” to prevent terrorists from exploiting online services. “We all know that a body that cannot scrutinise, take a position, or evaluate is not an advisory body at all,” the letter stated. “It is decoration and accountability theatre.”

Meta deferred comment on the resignations to the GIFCT. An unsigned statement sent to WIRED by a GIFCT spokesperson on behalf of the consortium’s leadership and the Meta-chaired operating board says the proposed changes have been “informed by several rounds of feedback” and are not yet final. They came out of discussions on “how to more effectively engage civil society and governments for substantive input” as “multi-stakeholderism is a core principle” for the GIFCT.

The consortium has about 35 members; other long-time board members include Microsoft and YouTube. A small staff alerts members to violent content, helps them exchange threat intelligence, and commissions research on countering extremism. While the coordination has helped some platforms combat problematic content, critics believe the group isn’t living up to its potential.

A WIRED investigation in 2024 uncovered several issues with GIFCT, including Meta delaying TikTok’s membership bid and poor relations between the companies at the helm and the unpaid independent advisory body. It also revealed failures in the tip-sharing database the consortium oversees to coordinate takedowns of problematic content.

Advertisement

The dismantling of the advisory group threatens to deteriorate the organization’s work further at a time when balancing free expression and online safety has become more challenging. Generative AI tools have simplified content creation but imposed limited guardrails.

Extremist content, including some that is now AI-generated, that promotes organizations such as Islamic State remains a persistent issue. Newer nihilistic collectives have turned to AI-supported scams such as sexploitation to coerce young victims into carrying out violence and abuse. Several AI chatbots have been accused of facilitating violence.

“A Shame”

The experts who resigned include university researchers and representatives of civil society organizations. They had agreed with McCarthy on the need for changes to improve the results of the decade-old anti-terrorism consortium. But they believe the proposal, which could be finalized soon, amounts to a step backward.

“There won’t be critical voices raising concerns about what GIFCT is doing or is not doing,” one of the departing experts says. “It may seem politically convenient for them to abolish the independent advisory committee, but they are going to regret it in the longer term.”

Advertisement

Source link

Continue Reading

Tech & AI

SpaceX’s Latest Starship Mission Reached Low-Earth Orbit

Published

on

The successful mission also deployed 26 of SpaceX’s latest Starlink satellites.

For its 14th flight, SpaceX’s Starship powered by its Super Heavy megarocket has entered low-Earth orbit for the first time. SpaceX kicked off this major undertaking early Monday morning but had to deal with some hiccups on the way, including losing one of its six Raptor engines. Ultimately, SpaceX decided to push on with the mission and successfully reached orbit albeit with some compromise.

SpaceX originally planned to have Starship orbit Earth six times over a span of nearly 10 hours for the Flight 14 mission. With one of the engines offline, the plan changed to only spend approximately three hours in orbit before reentering the Earth’s atmosphere and landing in the Pacific Ocean. As part of the same mission, SpaceX managed to deploy 26 of its Starlink V3 satellites into orbit. SpaceX said that its Starlink team has made contact with all newly-deployed 26 satellites in orbit, which will eventually be used to improve Internet speeds for customers. While previous Starship missions also carried several V3 satellites, they only remained in suborbital space and served as test flights to see if the new satellites would connect to the existing Starlink constellation.

While Starship’s flight 14 marked a major milestone of reaching orbit, the mission also served as a test of the reusability of its Super Heavy rocket. After providing the necessary boost to Starship, Super Heavy landed in the Gulf of Mexico, where it will eventually be retrieved, but not by a launch tower‘s “chopsticks” as previously demonstrated.

Advertisement

Source link

Advertisement
Continue Reading

Tech & AI

Jet Megatextures Demo For ESP32-S3

Published

on

Mipmapping is a good way to add a lot more detail to a 3D scene without overburdening the rendering hardware with detail that won’t be seen by the user. This level-of-detail rendering technique was demonstrated on the N64 console hardware a few years ago by [James Lambert] with [Michael Biggins], also known as [PhonicUK], now demonstrating it on the ESP32-S3 using his own Jet rendering engine.

Although level-of-detail rendering really speeds things up, it does also require far larger texture sizes, with [James]’s N64 demo taking up 40 MB of a 64 MB cartridge. To fit it on an ESP32-S3 with 16 MB of PSRAM and no SD card expansion or such the textures were further compressed to use 8-bit indexing, resulting in a mere 5.01 MB of textures.

There’s a demonstration video over on the associated Reddit thread, which shows the camera moving through the scene. Even if not as exciting as the Wipeout port by [Michael] that we previously covered, it does make clear that even without a proper 3D GPU the ESP32-S3 is already a pretty capable gaming machine that can go toe-to-toe with some 1990s consoles.

Advertisement

Source link

Advertisement
Continue Reading

Tech & AI

These Extremists Are Running for Election in November

Published

on

There are five weeks left until the midterm elections, and extremism is on the ballot in much of the US. A WIRED review of candidates running for statewide and federal positions in November, along with exclusive data on candidates running for state-level positions, reveals hundreds of Republican candidates who openly express virulently hateful ideologies, share racist content online, have close ties to white supremacist and antisemitic figures, and are members of far-right groups online. President Donald Trump and his administration have openly embraced, endorsed and defended many of these candidates.

At a local level, over 500 candidates running for state legislator positions in November are members of far-right groups on Facebook that promote militias, gun rights, and Christian nationalism, according to data collected by the Institute for Research and Education on Human Rights and shared with WIRED.

While many extremist candidates—such as groyper James Fishback and antisemitic influencer Dan Bilzerian— didn’t make it through GOP primaries, many made it to the general election, and a number of them are expected to win.

“The candidates are taking a page out of the Trump administration’s playbook,” Luke Baumgartner, a former research fellow at George Washington University’s Program on Extremism, tells WIRED. Baumgartner claims that many of the candidates running in November have been inspired by those in the White House. “In essence, the executive branch has handed them a permission slip to say and do what would have been unthinkable during the George W. Bush, McCain, or [Mitt] Romney eras of the GOP,” he says.

Advertisement

Extremist rhetoric has led to real world political threats. In 2025, terrorism and targeted violence incidents rose 19 percent compared to 2024, according to researchers at the University of Maryland; the US Capitol Police reported an increase in “threat assessment cases” against members of Congress for the third year in a row, with a 58 percent increase from 2024; and the US Marshals Service documented threats against almost 400 judges, a roughly 5 percent increase from the previous year.

Here are five races involving candidates who have shared extremist ideologies or have close ties to extremist figures, that WIRED is watching ahead of the November midterms.

The Texas Railroad Commissioner Race

MANSFIELD TEXAS  APRIL 15 Tarrant County Republican Party Chair Bo French speaks during a rally on Tuesday April 15 2025...

Photo-Illustration: WIRED Staff; Getty Images

Bo French, the GOP candidate for Texas Railroad Commissioner, is so extreme that Republican strategist Karl Rove has said he would vote for a Democrat rather than supporting a “bigot.”

Source link

Advertisement
Continue Reading

Tech & AI

Detachable mop heads and top-tier cleaning make the affordable Roborock Qrevo 2 Pro a dream for mixed floors

Published

on

Why you can trust TechRadar


We spend hours testing every product or service we review, so you can be sure you’re buying the best. Find out more about how we test.

Roborock Qvero 2 Pro: 30-second review

The Qrevo 2 Pro is the latest robot vacuum and mop combo cleaner from Roborock and includes detachable mop plates to help ensure it doesn’t get carpets wet while cleaning.

Cleaning performance is a match for some of the most expensive options on the market with its mopping being as good as I have ever tested making it a fantastic pick for the price.

Advertisement

Source link

Continue Reading

Tech & AI

New StandBy faces revealed for iPhone Duo

Published

on

The forthcoming iPhone Duo has more features than Apple has revealed, including a whole series of faces for its StandBy mode. Here’s what to eventually look for.

While pre-orders for iPhone Duo don’t start until October 16, and the Xcode betas still don’t show developers everything, one has found many new options coming to iOS 27 for this device.

Developer pdfu reports that the Xcode 27.1 simulator is lacking Rushmore, an app that is for displaying the new StandBy faces. But despite that, they have managed to get certain of the new faces running.

These working ones are variants on familiar clock and calendar faces as used on the iPhone‘s current StandBy mode. But code references describe several more options.

Just because something is referenced in code, it doesn’t necessarily mean that it will launch immediately. But those code references show five more faces:

  • Home Camera: up to nine camera views
  • Home Module
  • Flow
  • Fade
  • Snoopy

There are no details for Home Modular, Flow, or Fade. But the code for Flow also includes the term ResponsiveArt, which suggests that it will at least be an animated face.

Face editor

The iPhone Duo will also feature a revised editor for customizing these StandBy faces. It’s very similar to the existing one on iPhone and is perhaps more like the Apple Watch face editor.

Advertisement

Users can swipe left and right to adjust, for instance, the style of an analog clock, its numerals, light mode and dark mode, plus the color of the face and the hands.

Some of these clock faces also have room for two widgets. Then some more are digital instead of analog and there pdfu has found code references for five layouts:

  • StandBy
  • Stacked
  • Top
  • Middle
  • Bottom

The presumption is that all but the StandBy one may actually be intended for when the iPhone is opened like a book.

Developer pdfu has a strong track record for examining beta code. They confirmed that the iPhone Duo would use Touch ID, for instance, and most recently uncovered that Siri could be replaced by Claude or ChatGPT.

Advertisement

Source link

Continue Reading

Tech & AI

JadePuffer agentic AI attacks target Azure, destroy cloud resources

Published

on

JadePuffer agentic AI attacks target Azure, destroy cloud resources

The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.

The malware emerged in July, with researchers at cloud security company Sysdig highlighting that it uses AI agents to automate the entire attack chain, from reconnaissance, credential theft, and lateral movement to persistence and data encryption.

Shortly after, the company noted that JadePuffer expanded its focus to AI assets, training datasets, and vector databases, using a tool called EncForge.

Microsoft Security Research observed two JadePuffer attacks in June that mapped cloud resources, retrieved storage account keys, and deleted Azure Storage accounts.

Advertisement

The destructive stage lasted seven minutes and targeted more than 100 storage accounts, as well as Key Vaults, Function Apps, Virtual Machines, and App Services.

Although the threat actor was able to delete most of the targeted Azure Storage accounts, some remained unaffected because of Azure resource locks and storage account-level protections.

Microsoft tracks the JadePuffer threat actor as Storm-3168 and says it used two compromised service principals – security identities that enable applications, hosted services, and automated tools to authenticate to Azure and access assigned resources.

Both service principals belonged to the same tenant. One was used for reconnaissance and resource discovery, while the other “performed discovery, destructive operations, and credential collection.”

Advertisement
Timeline of observed attacks
Timeline of observed attacks
Source: Microsoft

The attacker removed backup and recovery protections (Azure Site Recovery locks), indicating an effort to make restoration more difficult.

This operational pattern could further support ransomware extortion, although Microsoft did not report anything about financial demands and didn’t confirm data theft in the observed cases.

According to the researchers, attempts to delete Azure SQL databases failed because the attacker used an unsupported API version. Attempts to remove recovery protection locks also failed.

“The parallel targeting of Azure SQL databases and storage accounts suggests an effort to broaden the destructive impact across different data services rather than concentrating on a single resource type,” Microsoft said.

Roughly half an hour after the wipe attempts, Storm-3168 returned to perform more than 30 requests for storage account keys, most of which succeeded.

Advertisement

Microsoft could not determine exactly how the initial access occurred, but noted that credentials for one service principal appeared in a public GitHub issue before the attacks.

The researchers recommend several mitigation steps and guidance for system administrators, including activating cloud workload protections, checking for secrets in public repositories, and evaluating Azure RBAC permissions against least-privilege principles.


article image

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat

Source link

Advertisement
Continue Reading

Trending

Copyright © 2025