Tag: cloud security
345 articles

Dropbox Breach Exposes 5,000 Accounts via Lenovo Login Flaw
A security lapse in a legacy Lenovo login integration left around 5,000 Dropbox accounts vulnerable to hackers, who exploited an email verification flaw to gain unauthorized access. Dropbox has since notified affected users and confirmed the breach to reporters.

Microsoft Defender mistakenly targets Google search links
Microsoft Defender for Office 365's Safe Links feature has mistakenly flagged Google search links as malicious, blocking users from accessing legitimate search results. This faulty security classification is currently preventing users from opening harmless links.

FBI Warns of Sophisticated Phishing Campaign Targeting High-Profile Individuals
Beware of a sneaky phishing scam that's targeting high-profile individuals, using a clever tactic to gain long-term access to their cloud accounts without needing their passwords. This sophisticated attack convinces victims to grant a malicious app permission to their accounts, allowing hackers to stay logged in for good.

METR Exposes $600K API Credit Theft After Weeks of Undetected Breach
A shocking $600,000 theft of API credits went undetected for weeks, leaving a nonprofit reeling - here's how a brief security lapse led to the massive breach. Attackers exploited a vulnerable API key, draining credits from METR's public models account in just a few short weeks.

Langflow vulnerability exploited to harvest OpenAI, AWS keys
Attackers are actively exploiting a critical vulnerability in Langflow to harvest sensitive keys, including OpenAI and AWS credentials, by querying environment variables and reading secret files. This severe flaw, known as CVE-2026-0768, allows hackers to execute arbitrary Python code with root privileges, putting systems at risk.

Threat Actors Exploit API Key, Drain $600,000 in AI Credits
In a shocking security breach, threat actors made off with a whopping $600,000 in AI credits after exploiting a stolen API key from AI safety research group METR over just three weeks. The incident began with a researcher inadvertently leaving a public EC2 instance exposed, despite Google authentication, due to a fail-open flaw and a "vibe-coded" app storing a sensitive API key.

Threat Actors Exploit METR API Key, Drain $600,000 in AI Credits
A staggering $600,000 in AI credits vanished in a flash when an unknown attacker exploited a stolen API key, infiltrating a publicly accessible experiment and racking up a massive bill that was thankfully waived by the model provider. The shocking breach happened after a researcher inadvertently left an EC2 instance exposed, despite having Google authentication in place.

Anthropic Exposes Gaps in AI Agent Governance with New Compliance API
Anthropic just dropped a bombshell, revealing major gaps in AI agent governance with its new Compliance API - and it's a game-changer for cloud security. By introducing local session transcripts, Anthropic is shining a light on what really happens when AI agents interact with your systems.

ServiceNow Patches Maximum-Severity Vulnerabilities
ServiceNow has released urgent security updates to fix three critical vulnerabilities in its AI Platform, and experts warn customers to act fast to secure their self-hosted instances. Apply the patches now to protect against potential malicious attacks.

Tech Giants Urge Global AI-Powered Cyber Defense Surge
The clock is ticking: over 100 tech giants, including OpenAI, Google, and Microsoft, are sounding the alarm that we must urgently boost our AI-powered cyber defenses to avoid a surge in sophisticated attacks. They're calling on us to take action now to reduce risk before it's too late.

Phishing Service NovaCookies Targets Organizations with 365 Session Theft
Meet NovaCookies, a sneaky phishing service that's stealing Microsoft 365 sessions from hundreds of organizations - and it's available for a low monthly fee of just $320. This subscription-based threat packages real-time session theft, making it a potent and affordable tool for cybercriminals.

Snowflake Tackles Identity Debt as Passwords Lose Favor
The alarming rise of identity debt has led Snowflake to take a bold stance against outdated password practices, proactively tackling the vulnerabilities that leave businesses exposed. By phasing out password authentication, Snowflake is revolutionizing identity debt management and setting a new standard for secure data protection.

CISA Red Team Exposes Defense Gap Between Water, Government Sectors
In a recent test, CISA's red team uncovered a shocking vulnerability in a government organization, breaching its defenses with ease by sending phishing emails from an internal address, then moving undetected to sensitive systems and cloud resources. The team was able to gain elevated privileges and spread laterally, exposing a significant gap in the organization's security.

Mirage2FA Campaign Targets 4,500 Firms, Bypasses Microsoft 365 2FA
Thousands of companies, including 4,532 unique organizations worldwide, have been targeted by the Mirage2FA campaign, a sneaky phishing-as-a-service toolkit that cleverly bypasses Microsoft 365's two-factor authentication. US-based companies are among the hardest hit, making up 63.7% of the victims.

Apollo Breach Exposes Sensitive Data Via Social Engineering
A recent data breach at Apollo Global Management exposed sensitive personal info, including Social Security numbers, when an unauthorized user gained cloud access for just four days, from July 6 to July 10, 2026. The breach was triggered by a social engineering attack, highlighting the importance of robust security measures.

NIST Identifies Security Gaps in Multi-Cloud Environments
NIST warns that multi-cloud environments, which use two or more cloud service providers, pose unique cybersecurity and compliance risks, despite helping organizations reduce reliance on a single provider and maintain operations during outages or cyber-attacks. A recent NIST report aims to tackle these challenges by providing a structured problem statement and shared vocabulary to inform future research and solution design.

Thousands of Leaked AWS Keys Remain Active
A recent scan by Truffle Security uncovered a staggering 9,300+ active AWS keys that were leaked online, including hundreds with full administrative rights, putting sensitive data at risk. These compromised keys were found across various public platforms, with a shocking 88% still authentic and vulnerable to exploitation.

Apollo Hit by Data Breach in Financial Sector Cyberattack Wave
Apollo Global Management recently fell victim to a data breach, with hackers gaining unauthorized access to its cloud platforms between July 6 and July 10, and sensitive personal data being compromised, discovered on August 12. The company swiftly responded to the incident, notifying law enforcement and bolstering its security protocols.

AWS Security Quarantine Policy Falls Short Against Credential Abuse
Leaking AWS credentials can lead to a staggering 99% increase in your bill - but a recent finding by Truffle Security reveals that even AWS' Quarantine Policy may not be enough to stop the damage, with hundreds of leaked root keys still active. This alarming discovery highlights the urgent need for tighter security measures to prevent credential abuse.

SynkLoader Malware Targets Microsoft Teams Users in Phishing Campaign
Beware of phishing messages on Microsoft Teams that claim to be from your IT help desk - they may be laced with SynkLoader malware, a newly discovered threat that's being spread through seemingly legitimate downloads hosted on Microsoft Azure. These attacks use a clever tactic to gain your trust, but don't be fooled!

Exposed AWS Keys Grant Attackers Full Corporate Account Control
Thousands of exposed AWS keys are still active, putting entire corporate accounts at risk of being hijacked by attackers - and a staggering 88% of re-verified keys were found to still grant access as recently as August 2026. This alarming vulnerability highlights the urgent need for tighter security measures to protect sensitive cloud data.

GitLab Flaw Exploited in Wild Days After Disclosure
In a chilling demonstration of the new reality in vulnerability exploitation, attackers began exploiting a newly disclosed GitLab flaw within minutes of its public disclosure, leaving little time for patching. This rapid reproduction and exploitation is a stark reminder that waiting for the next patch cycle may no longer be a viable defense strategy.

Microsoft Entra ID Flaw Exploited, Enables Remote Code Execution
Microsoft warns of a critical flaw in Entra ID that lets hackers execute code remotely by exploiting a deserialization vulnerability, giving them free rein to wreak havoc over the network. This maximum-severity flaw, tracked as CVE-2026-69836, has been patched, but highlights the importance of staying vigilant against remote code execution threats.

Cloudflare Workers Exposed to Remote Spectre Attack
Researchers have successfully demonstrated a remote Spectre attack on Cloudflare Workers, exfiltrating a secret JSON Web Token (JWT) at an alarming rate of 12 bits per second - roughly 360 times faster than previously shown. This chilling exploit could have devastating consequences in the wrong hands.