Three stories today share a single thread: the identities no one is watching. A threat actor deleted Azure resources for 18 hours using service principals. Infostealers harvested AI platform credentials from 80,000 organizations. AI coding agents scattered valid secrets across files no scanner checks. Non-human identity is the attack surface of 2026 - and most teams still treat it as a configuration detail.
In the News
Storm-3168 Destroyed Azure Resources Using Compromised Service Principals
Microsoft published a detailed analysis of JADEPUFFER (Storm-3168) cloud operations from June 2026. The actor - previously known for ransomware deployments against on-premises infrastructure - pivoted to Azure and used compromised Entra ID service principals to execute bulk destruction across multiple tenants.
The tradecraft was methodical. Storm-3168 used the service principals’ existing Contributor-level permissions to enumerate resources, remove recovery locks, and then delete Storage Accounts, SQL databases, Key Vaults, and virtual machines. The entire destructive sequence ran for approximately 18 hours before any detection fired. Recovery locks - the one control designed to prevent exactly this - were removed programmatically because the compromised identity had sufficient privileges.
This is the first documented case of Storm-3168 operating entirely through workload identities in the cloud. No malware on endpoints, no lateral movement through the network. The service principal was the initial access vector, the persistence mechanism, and the tool of destruction. The operational reality: most organizations do not monitor service principal activity with the same rigor they apply to human accounts. Conditional Access policies often exempt workload identities. Behavioral baselines do not exist for most service principals because no one has defined what “normal” looks like for them.
What defenders should do: Audit every service principal in Entra ID with Contributor or Owner roles. Implement identity threat detection (ITDR) that baselines service principal behavior and alerts on anomalous resource deletion. Enforce resource locks with separate, break-glass identities that service principals cannot modify. Treat workload identities as privileged accounts - because that is exactly what they are.
80,000+ Organizations Had AI Platform Credentials Stolen
SOCRadar analyzed infostealer logs and found active credentials for ChatGPT, Claude, Copilot, and other AI platforms tied to more than 80,000 corporate domains. The stolen sessions are being sold on criminal marketplaces and used for conversation exfiltration, prompt injection through hijacked accounts, and LLMjacking - running compute-intensive tasks on someone else’s API subscription.
The root cause is shadow AI adoption. Employees create accounts on AI platforms using corporate email addresses but without SSO federation. No conditional access. No session policy. No revocation path. When an infostealer captures the browser session, the security team has no visibility - they did not provision the account and do not know it exists. The credential sprawl problem that identity teams spent a decade fighting with SaaS applications is repeating itself with AI platforms, at faster adoption velocity.
What defenders should do: Federate AI platform authentication through corporate SSO with phishing-resistant passwordless authentication (FIDO2). Deploy identity governance tools that discover shadow AI accounts. Monitor for anomalous AI platform API usage tied to corporate domains.
AI Coding Agents Leak Credentials Across the Development Surface
GitGuardian’s State of Secrets Sprawl 2026 report quantified a problem that has been growing since AI coding assistants became standard developer tools. Researchers found 24,008 unique secrets in public MCP configuration files - 2,117 of which were still valid and exploitable at the time of discovery. Claude Code-assisted commits showed a 3.2% credential leak rate, higher than baseline developer commits.
The critical finding is that repository-level secret scanning misses the majority of the problem. AI coding agents scatter credentials across agent logs, environment variables, temporary files, and shell history - locations that no production secret scanner inspects. The non-human identity lifecycle for API keys used by AI agents is essentially unmanaged: keys are created, embedded in config, and never rotated or scoped to least privilege.
What defenders should do: Extend secrets detection beyond repositories to IDE logs, agent configuration files, and developer shell history. Implement automated rotation for API keys used by AI coding agents. Enforce least-privilege scoping - an AI agent writing frontend code does not need a production database credential.
Two Citrix NetScaler Zero-Days Exploited in the Wild
Citrix confirmed active exploitation of CVE-2026-88771 (CVSS 9.5) and CVE-2026-88772 (CVSS 9.0), both unauthenticated remote code execution vulnerabilities in NetScaler ADC and Gateway. CISA added both to the Known Exploited Vulnerabilities catalog on September 27 and mandated federal agency patching by October 1.
NetScaler Gateway serves as a VPN and SSO entry point for thousands of organizations. Exploitation gives attackers a foothold upstream of every identity control - session tokens, authentication cookies, and cached credentials are all accessible from a compromised gateway. The identity implication: when the authentication gateway itself is compromised, phishing-resistant authentication and ITDR are the layers that detect the attacker using the sessions the gateway issued.
What defenders should do: Patch both CVEs immediately or take affected NetScaler instances offline. Audit sessions issued through NetScaler Gateway during the exposure window. Deploy ITDR to detect anomalous session reuse originating from gateway infrastructure.
Defender Action Items
- Audit Entra ID service principals with Contributor/Owner roles - remove unnecessary permissions and enforce resource locks with separate break-glass identities
- Federate AI platform authentication (ChatGPT, Claude, Copilot) through corporate SSO with FIDO2/passwordless enforcement
- Extend secrets scanning to MCP config files, agent logs, shell history, and environment variables in developer workstations
- Patch Citrix NetScaler ADC/Gateway to remediate CVE-2026-88771 and CVE-2026-88772 immediately - CISA KEV deadline is October 1
- Inventory all AI coding agent API keys and implement automated rotation with least-privilege scoping
Detection Queries
Service principal bulk-deletion behavior in Azure Activity Logs (KQL for Microsoft Sentinel):
AzureActivity
| where OperationNameValue has_any ("Microsoft.Resources/locks/delete", "Microsoft.Storage/storageAccounts/delete", "Microsoft.Sql/servers/delete", "Microsoft.KeyVault/vaults/delete", "Microsoft.Compute/virtualMachines/delete")
| where Authorization has "ServicePrincipal"
| summarize DeleteCount = count(), ResourceTypes = make_set(OperationNameValue), TimeRange = make_list(TimeGenerated) by Caller, SubscriptionId
| where DeleteCount > 5
| sort by DeleteCount desc
This query surfaces service principals performing multiple resource deletions across a subscription. A count threshold of 5 balances signal-to-noise - legitimate IaC teardowns will appear, but paired with the resource-lock deletion event, the pattern is high-fidelity for destructive activity. Tune the threshold based on your IaC pipeline cadence.
Related Briefs
- NetScaler Zero-Days CVE-2026-88771 and 88772 Exploited
- AI Agent Accessed a Government Portal - Was It Open?
- Roundcube Pre-Auth SQLi CVE-2026-48842 Exploited
- Check Point VPN Zero-Day - CVE-2026-85102 Pre-Auth RCE
- F5 BIG-IP APM OAuth Zero-Day - CVE-2026-94127
References
- Storm-3168: Agentic-driven cloud attacks using compromised service principals - Microsoft Security Blog
- 80,000+ organizations had AI logins stolen - BleepingComputer
- AI coding agents credential security - GitGuardian Blog
- Citrix admins warned to shut down NetScalers over 2 exploited zero-days - BleepingComputer
- OpenAI agents uploaded user images to third-party sites - BleepingComputer
- Carbonato botnet compromises Docker hosts - The Hacker News
- Anthropic Claude Marketplace launch - BleepingComputer
Subscribe to The Identity Brief
Get The Identity Brief in your inbox (Mon/Wed/Fri) - Human, machine, and AI identity security — NHI, ITDR, and the IAM market.