Threat Brief — 2026-09-28 — Cloud principals, proxy sprawl, repo domains
Executive summary
A destructive Azure campaign attributed to JADEPUFFER demonstrates how compromised service principals can be weaponised to delete cloud resources — a reminder that machine identities remain a prime attack surface. Separately, 737 Chrome VPN extensions were revealed as a single covert proxy network, and a domain referenced by 1,700+ code repositories has been turned into an active Windows attack vector. OnePlus has escalated its unpatched root-chain story by threatening the discovering researcher with legal action, raising concerns about vulnerability disclosure suppression.
Top items
- JADEPUFFER operators used compromised Azure service principals for destructive resource deletion. Microsoft (tracking as Storm-3168) observed the threat actor orchestrating destructive actions within an Azure environment after compromising service principal credentials. This underscores the risk of over-privileged machine identities in cloud environments. (src: The Hacker News)
- 737 Chrome VPN extensions form a single covert proxy network. Shared domains, code, metrics, and internal files link hundreds of seemingly independent timer and calculator extensions to one proxy infrastructure that turned a million browsers into relay nodes. Google intervened only after background activity reached noticeable scale. (src: SecurityLab)
- Domain used by 1,700+ repositories turned malicious and began attacking Windows users. A previously benign domain referenced across a large number of code repositories has been repurposed to serve different content to different visitors — benign pages for some, malicious payloads targeting Windows for others. This is a live supply-chain risk for any project that fetched resources from the affected domain. (src: SecurityLab)
- OnePlus threatens legal action against researcher who disclosed unpatched OxygenOS root chain. This is a new development in a story first reported 2026-09-24 by The Hacker News. The flaw chain allows any installed app to escalate from the Android sandbox to system privileges; rather than patching, OnePlus has reportedly threatened the researcher with a lawsuit, raising disclosure-chilling concerns. (src: SecurityLab)
Themes
Machine-identity abuse in the cloud. JADEPUFFER's use of compromised service principals follows a well-established pattern but remains under-defended; service principals frequently hold standing privileged access with weaker monitoring than human accounts.
Benign infrastructure weaponised. Both the Chrome extension proxy network and the repurposed repository domain illustrate how trust accumulated over time — extension marketplace listings, long-standing code dependencies — can be flipped into attack infrastructure with minimal warning.
Disclosure suppression. OnePlus's legal threat against a vulnerability researcher signals that vendor response to security findings can shift from remediation to intimidation, potentially leaving critical flaws unpatched and undisclosed.
