Published: 09/30/26
Wednesday opens on a cloud wipe that took seven minutes. Microsoft says Storm-3168 used stolen Azure service principals to delete storage accounts and hunt keys. Also on the desk: an Elementor one-click admin trick, a new Spectre path to a Linux root hash, and Mandiant’s NetScaler hunt list as the federal clock ends today.
Lead Story
Someone stole an Azure service principal and wiped storage in seven minutes
JADEPUFFER, tracked by Microsoft as Storm-3168, used compromised service principals to map an Azure tenant, then delete more than 100 storage accounts in about seven minutes. Key Vaults, Function Apps, and App Services were hit too. Resource locks saved a few targets. One of the secrets had appeared in a public GitHub issue.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: Long-lived app secrets with Contributor rights are a remote wipe button.
Also Worth Your Attention
One Elementor link can create a new admin
Elementor 4.3.0 and 4.3.1 skip WordPress REST CSRF checks when elementor/v1/events/ appears in the URI. A logged-in admin who clicks a crafted link can create another administrator. Fixed in 4.3.2.
Why it matters: Page-builder admins click links all day, and the bypass reaches every REST route they can use.
Check your Elementor version →
Spectre BTR pulls a Linux root hash in minutes
VUSec’s Branch Target Reuse attack leaked root password hashes from Intel Linux hosts in three to five minutes using unprivileged local code. Kernel fixes for the related CVEs are merged. Shared hosts and CI runners go first.
Why it matters: Multi-user Linux boxes still share a branch predictor with whatever code you let run.
NetScaler federal clock ends today. Hunt the web shells
CISA’s due date for the exploited NetScaler RCEs is Wednesday. Mandiant documented WHIPSHOT and SLAPSHOT web shells, httpd.conf tricks, and setuid /bin/sh on appliances hit before the patch. Patch, then hunt.
Why it matters: A patched Gateway can still be someone else’s tunnel into the network.
Slack paste: Azure: rotate leaked service-principal secrets, lock backup storage, alert on ARM deletes; Elementor >= 4.3.2 and audit admins; Linux kernels patched for Spectre BTR; NetScaler on fixed build today + hunt WHIPSHOT/SLAPSHOT.
Go Deeper
Identity & access: IAM library · Tools & playbooks: Cybersecurity Tools · Subscribe: Daily Brief
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.