Skip to main content

Cloud Security

Cloud infrastructure and application security

Rows of servers and storage units in a data center, with some cables exposed and others neatly organized.

Cloud Security Risks Diverge Sharply Across Providers

The cloud security landscape is far from equal, with a staggering 76% of AWS accounts showing exposed services, compared to just 8% on Google Cloud - a massive gap that highlights the limitations of one-size-fits-all cloud security checklists. This stark disparity underscores the need for a tailored approach to cloud security, one that takes into account the unique risks of each provider.

Analyst 207
Neutral-colored room with multiple computer screens and servers, displays blurred or empty.

NIST Identifies Security Gaps in Multi-Cloud Environments

NIST warns that multi-cloud environments, which use two or more cloud service providers, pose unique cybersecurity and compliance risks, despite helping organizations reduce reliance on a single provider and maintain operations during outages or cyber-attacks. A recent NIST report aims to tackle these challenges by providing a structured problem statement and shared vocabulary to inform future research and solution design.

Analyst 207
Server room interior with rack-mounted equipment and blurred credential symbol.

AWS Security Quarantine Policy Falls Short Against Credential Abuse

Leaking AWS credentials can lead to a staggering 99% increase in your bill - but a recent finding by Truffle Security reveals that even AWS' Quarantine Policy may not be enough to stop the damage, with hundreds of leaked root keys still active. This alarming discovery highlights the urgent need for tighter security measures to prevent credential abuse.

Analyst 207
Empty office workspace with laptop, papers, and city view, conveying shared responsibility.

Microsoft's Shared Responsibility Model Exposes SaaS Backup Gaps

Many organizations mistakenly assume Microsoft handles data restoration, but the reality is their Shared Responsibility Model leaves SaaS backup gaps that can expose customers to data loss and ransomware attacks. Native recovery tools only address short-term data issues, not long-term cyber resilience.

Analyst 207
Government employee works on laptop in secure data center with server racks.

FedRAMP High Becomes Benchmark for Mission-Critical Government Cloud Operations

The cloud is no longer just a migration target, but the operating environment for government missions, and FedRAMP High has become the benchmark for ensuring the security and reliability of mission-critical cloud operations. FedRAMP High is now a mission requirement, not just a compliance checkbox, providing the highest level of security controls for systems where data loss could have serious consequences.

Analyst 207
Rows of computer servers and storage systems in a brightly-lit cloud data center or server room with ambient lighting.

Azure Flaw Exposes Platform-Wide Key to All Databases

Microsoft patched a vulnerability in Azure Cosmos DB, dubbed CosmosEscape, which exposed a platform-wide key to all databases, but fortunately, no customer data was accessed and no action is required. The flaw was discovered by security firm Wiz, which detailed the exploit chain that could be used to take advantage of the vulnerability.

Analyst 207
Person holding laptop with cloud storage interface in a bright, minimalist home office setting.

Cloud Storage Deal Offers Lifetime 2TB Access with Encryption

Say goodbye to monthly storage fees! For just $59, you can get lifetime access to 2TB of secure cloud storage with FileJump's one-time payment plan, a whopping $408 discount off the usual price.

Analyst 207
Laptop and external hard drive on a desk with a blurred cloud storage interface nearby, indicating potential data exposure.

Grok Build Exposes Git Repositories to Unintended Storage

Elon Musk has made a bold promise to erase all user data uploaded to Grok Build before now, assuring users that their content will be completely deleted. This move comes after a researcher discovered that Grok Build was inadvertently storing entire Git repositories, including sensitive files and commit history, in a Google Cloud Storage bucket.

Analyst 207
Network operations environment with servers, routers, and cables, showing a data stream being intercepted.

Cloud Providers' Global Namespace Flaw Enables Bucket Hijacking

A newly discovered flaw in cloud providers' global namespace has been exploited in a simple yet powerful bucket hijacking technique, allowing attackers to redirect sensitive data streams into their own accounts. This alarming vulnerability affects multiple services across major cloud providers.

Analyst 207
Person working on laptop with blurred screen in a bright, minimalist space.

Cloudflare Unveils Protocol to Distinguish Legitimate Web Traffic

Cloudflare is shaking up the way we verify online traffic with a new protocol that helps websites distinguish between legitimate users and AI-powered bots. Meet PACTs, a game-changing solution that lets sites share anonymous tokens, essentially a private, shareable CAPTCHA test result.

Analyst 207
Rows of servers and storage systems in a cloud data center or server room.

Attackers Target Cloud Logging Services for Defense Evasion and Continuous Visibility

Cloud logging services, like AWS CloudTrail and Google Cloud Logging, are a treasure trove of insights into your cloud environment - but they're also a prime target for attackers looking to erase their tracks or gain continuous visibility into your operations. By manipulating these services, adversaries can create persistent blind spots that leave you vulnerable.

Analyst 207
People in IT attire gathered around a touchscreen in a modern data center.

Bolstering AI Resilience Across Cloud and Data Environments

As AI agents and copilots increasingly access, share, and store enterprise data, organisations in Australia and New Zealand face a pressing question: can they keep their data secure and recoverable in this new landscape? The integration of agentic AI and copilots is expanding data pathways, creating new operational risks that demand attention to visibility, protection, and recovery readiness.

Analyst 207
Dimly lit server room with a lone laptop displaying a brightly lit AI interface.

Enterprises Lag in Securing Autonomous AI Agents

Most organizations are struggling to keep pace with the rapid evolution of autonomous AI agents, which can introduce new risks and behaviors at machine speed. As these agents increasingly handle sensitive data, enterprises face a pressing need to update their security strategies and tools to mitigate the emerging threats of shadow AI and over-permissioned agents.

Analyst 207
Modern data center interior with rows of servers and Vietnamese technicians in traditional áo dài walking through aisles.

Vietnam to Build Domestic Cloud to Bolster Data Sovereignty

Vietnam is taking a major step towards securing its digital future by building a domestic cloud infrastructure, aiming to safeguard national data and reduce reliance on foreign cloud services by 2030. This move will bolster data sovereignty, enhance cybersecurity, and drive the country's digital transformation.

Analyst 207
Security practitioners overlook threats on a large computer screen in a brightly-lit cloud data center.

Security Teams Overlook AI-Enabled Threats in Cloud Risk Management

Cyber threats are evolving at an alarming rate, with AI-enabled attackers now launching faster and more sophisticated attacks on cloud and hybrid environments. Security teams must stay vigilant against emerging threats like AI-driven phishing, malware, and credential compromise.

Analyst 207
Modern office space with employees packing up and empty chairs, surrounded by natural light and plants.

Cloudflare and Arctic Wolf Slash Staff Amid AI-Driven Overhaul

Cloudflare and Arctic Wolf are shaking things up with a major AI-driven overhaul, cutting staff to make way for a world-class, high-growth operation that's harnessing the power of artificial intelligence. This move isn't about cost-cutting, but about revolutionizing how these companies create value in the agentic AI era.

Analyst 207
Executive stands in front of large screen displaying cloud security interface in modern office setting.

WatchGuard Bolsters Cloud Security With Perimeters Acquisition

WatchGuard's acquisition of Perimeters is a strategic move to supercharge its cloud security offerings, driven by a personal endorsement from its CISO who fell in love with Perimeters' technology. This exciting purchase brings Perimeters' innovative cloud application security solutions into WatchGuard's portfolio.

Analyst 207
Modern network operations center with servers and equipment, featuring a prominent cloud firewall in the foreground.

Firewalls Evolve to Bolster Zero Trust, Cloud Security

As organisations navigate the complexities of multi-cloud estates, modern cloud firewalls are emerging as a crucial linchpin for reclaiming coherent security controls and mastering cloud networking. They're not old tech, but a vital tool for cloud architects and security pros to enforce robust, zero-trust security across multiple providers.

Analyst 207
Healthcare professionals work in a hospital setting with subtle cloud technology elements integrated into the environment.

Federal Agencies Drive Healthcare Transformation with Cloud Tech

Federal healthcare agencies face a daunting challenge: modernizing critical systems while millions of Americans rely on them - it's like changing a plane's engine mid-flight. Cloud technology is key to navigating this transformation, enabling agencies to deliver patient-centered care without interruption.

Analyst 207
Dark cityscape with cracked vault door and glowing network lines, people working on devices in background.

AI Agents Fuel Cybersecurity Breaches at Most Firms

As AI agents increasingly power business operations, they're also fueling cybersecurity breaches at most firms, leading to data exposure, operational disruption, and financial losses. The rapid rise of AI is sparking a pressing dilemma: how can organizations balance innovation with control?

Analyst 207
Abandoned server room with flickering light, broken lock, and eerie shadows.

Misconfiguration Exposes Azure AI Agent to Unauthorized Access

A single misconfiguration in Microsoft's Azure SRE Agent turned a troubleshooting tool into a live wiretap, potentially allowing outsiders to intercept sensitive conversations, commands, and credentials from other companies in real time. This alarming security flaw may have left organizations vulnerable to unauthorized access, with no digital trail to detect the breach.

Analyst 207
Fortress stands atop a hill amidst stormy sky, with shattered smartphone and laptop in foreground.

EU Awards $213M Cloud Contract to Boost Digital Sovereignty

The European Union has taken a bold step towards digital independence with a $213 million cloud contract awarded to four European providers, marking a significant shift away from US tech dominance. This strategic move is set to bolster the EU's digital sovereignty.

Analyst 207

Commvault Unveils AI Agent Monitoring to Mitigate Rogue Risks

Meet AI Protect, Commvault's game-changing solution that helps you discover, monitor, and control AI agents in your cloud - and quickly roll back their actions if something goes awry. With AI Protect, you can finally breathe easy knowing your AI agents are working for you, not against you.

Analyst 207
Dark cloudy sky with a gaping hole reveals cityscape, broken padlock and laptop screen nearby.

Cloud Breaches Persist as Detection Gaps Remain Unaddressed

Cloud security breaches continue to fly under the radar, leaving us to wonder who's left to sound the alarm. Uncover the reasons behind persistent detection gaps in cloud intrusions by exploring the insightful GovInfoSecurity webinar.

Analyst 207