Storm-3168: Agentic-driven cloud attacks using compromised service principals
A secret got pasted into a GitHub issue, then edited out. The edit history kept it, and that was enough. Microsoft calls Storm-3168 the first documented agentic ransomware operation: 15.5 hours of recon across 300+ read operations with a compromised Azure service principal, then 100+ storage account deletion attempts inside a 7-minute window. Redacting a secret is not rotating it.