Tag: cloud security
345 articles

Azure Exfiltration Campaign Exposes 3.6 Million Records
A shocking data breach has hit major players like McDonald's and Gap Inc., with a hacker claiming to have made off with a staggering 3.6 million Azure account records, including 1.7 million sensitive employee records from McDonald's alone. The breach exposes names, emails, addresses, and more, serving as a stark reminder that traditional security perimeters just aren't enough.

Hackers Exploit MFA Gaps with 155x Surge in Password Spraying Attacks
Hackers are taking advantage of weaknesses in multi-factor authentication, launching a staggering 155 times more password spraying attacks in the first half of 2026. These attacks aren't about fancy new tools, but rather exploiting old authentication paths that slip past security defenses.

Attackers Exploit MLflow Flaw to Steal Cloud Credentials
A newly discovered vulnerability in MLflow, CVE-2026-64849, with a near-perfect CVSS score of 9.3 is being exploited by attackers to infiltrate cloud metadata services and steal sensitive credentials. This critical flaw allows hackers to issue unauthorized requests and extract confidential data, putting your cloud security at risk.

Microsoft Copilot Flaws Expose One-Click Data Exfiltration Risk
Researchers uncovered a set of flaws in Microsoft Copilot, dubbed CoSnitch, that could allow attackers to exploit a user's session with just one click, potentially leading to data exfiltration. A single crafted link could trigger actions inside a signed-in user's assistant session, putting sensitive information at risk.

Wiz AI Tool Exposes Snowflake GitHub Repo Vulnerability Missed by Advanced Security
Wiz AI Tool Exposes Snowflake GitHub Repo Vulnerability Missed by Advanced Security Meet Red Agent, the game-changing AI tool that uncovered a script injection vulnerability in Snowflake's GitHub repository that even advanced security scans missed. This autonomous security researcher not only identified the flaw but also exploited it and assessed the damage - all without human help.

TWINLOOT Exploits Microsoft Services to Steal Credentials
Meet TWINLOOT, a sneaky Python implant that hides its command-and-control infrastructure inside trusted Microsoft services, making it super hard to detect. It uses SharePoint Online and Microsoft Teams to operate undetected, even leveraging a victim's own Edge browser to blend in.

Microsoft Copilot Exposes Vulnerability to Meta-Hacking
Researchers at Varonis Threat Labs uncovered a vulnerability in Microsoft Copilot, cleverly manipulating it to reveal its own weaknesses and craft a working attack, which they've dubbed CoSnitch. This surprising exploit was responsibly disclosed to Microsoft, which plans to issue a patch.

Salesforce, ServiceNow Portals Targeted in Ongoing Data Scraping Campaign
A single virtual private server has been secretly siphoning off sensitive records from Salesforce and ServiceNow customer portals since March 2025, according to recent research by Reco. This ongoing data scraping campaign, dubbed City Forum, has been quietly pulling data from multiple targets across various sectors.

Azure Breach Exposes 3.6 Million Records from Top Companies
A threat actor known as TheHatman is selling employee data from top companies like McDonald's and Tata Consultancy Services, allegedly stolen from Microsoft Azure tenants using compromised credentials. The stolen records total 3.6 million, with McDonald's alone accounting for 1.7 million employee records.

Wiz Exposes GitHub Actions Flaw in Snowflake Repository
Researchers at Wiz uncovered a vulnerability in Snowflake's GitHub repository, where a flawed GitHub Actions workflow exposed a sensitive Jira API token, putting internal credentials at risk. This security gap allowed attackers to potentially execute commands using a crafted GitHub issue.

Azure Breach Exposes Millions of Employee Records at Top Firms
A threat actor known as TheHatman is peddling a staggering 1.7 million employee records from McDonald's, along with millions more from other top firms, allegedly stolen from Microsoft Azure environments. The breach, which Hudson Rock deems highly authentic, has left giants like Vodafone, Tata Consultancy Services, and IHG Hotels & Resorts vulnerable.

SAP Exploits Maximum-Severity Commerce Cloud Flaw in Active Attacks
SAP Commerce Cloud has a critical vulnerability, known as CVE-2026-58231, that allows unauthenticated attackers to wreak havoc by executing arbitrary code and compromising internal components. This maximum-severity flaw, scoring a perfect 10.0 on the CVSS scale, stems from weak authorization checks and input validation.

Google Workspace Security Must Adapt to AI-Driven Threats
The traditional attack chain is getting a makeover: instead of starting with a malicious email, attackers now use OAuth apps to breach Google Workspace, exploiting new vulnerabilities in an AI-driven threat landscape. It's time to shift from an inbox-centric to an OAuth-first security approach to stay ahead.

ShinyHunters Breach Exposes 1.6 Million RingCentral Accounts
RingCentral has confirmed that a breach, known as ShinyHunters, compromised 1.6 million of its accounts, but has since taken swift action to prevent further unauthorized activity. The company is now directly contacting affected customers and has assured that its core platform remains secure and operational.

Compromised AWS Key Exposes 1500+ UK Charities to Data Breach
Over 1,500 UK charities are reeling after a data breach at CRM provider Beacon exposed their personal information, likely due to a compromised AWS access key. This devastating cyber-attack has left countless organizations vulnerable, sparking urgent concerns about data security.

Microsoft's Shared Responsibility Model Exposes SaaS Backup Gaps
Many organizations mistakenly assume Microsoft handles data restoration, but the reality is their Shared Responsibility Model leaves SaaS backup gaps that can expose customers to data loss and ransomware attacks. Native recovery tools only address short-term data issues, not long-term cyber resilience.
Beacon Breach Exposes Charity Data After AWS Key Compromise
A security breach at Beacon compromised customer data, including attachment files, after an AWS access key was potentially exposed in public JavaScript build artifacts, allowing attackers to retrieve encrypted data in readable form. The breach, which started on July 27-28, 2026, may have resulted in a downloadable copy of the database.

Researchers Discover Context Bombing Technique to Disrupt AI Hacking Agents
Researchers have discovered a clever way to shut down AI hacking agents by inserting specially crafted prompts alongside sensitive data on Amazon Web Services, effectively triggering the model's internal safety rules and halting attacks. This innovative technique, dubbed "context bombing," has proven to be a simple yet effective defense against AI-powered hacking.

Google Docs Exposes Staging Server Credentials in Search Results
A simple Google search led to a major security slip-up when a developer stumbled upon a publicly indexed Google Doc containing sensitive staging server credentials. A careless mistake by an outside contractor had left the confidential info exposed, and a curious autocomplete suggestion revealed it all.

City-Forum Attacks Exploit Salesforce, ServiceNow Portals for Data Theft
A single IP address, 158.220.87.79, has been linked to a massive data-theft campaign targeting corporate and public portals, including Salesforce and ServiceNow, for over a year with no signs of slowing down. This persistent threat has compromised multiple organizations worldwide, spanning industries from telecom and finance to security and government.

Malicious LiteLLM Releases Expose Over 2,100 Organizations to Credential Theft
Over 2,100 organizations are at risk of credential theft due to malicious LiteLLM releases that harvested sensitive data, including environment variables, SSH keys, and cloud credentials, and sent it to an attacker-controlled domain. These compromised packages were live on PyPI for about 40 minutes on March 24, leaving a trail of potential exposure.

FedRAMP High Becomes Benchmark for Mission-Critical Government Cloud Operations
The cloud is no longer just a migration target, but the operating environment for government missions, and FedRAMP High has become the benchmark for ensuring the security and reliability of mission-critical cloud operations. FedRAMP High is now a mission requirement, not just a compliance checkbox, providing the highest level of security controls for systems where data loss could have serious consequences.

Wesco Probes Data Exfiltration After ExfilSquad Leak Claim
Wesco is investigating a cybersecurity incident involving its cloud CRM environment after a third-party group, ExfilSquad, claimed to have exfiltrated company data. The company says it has contained the issue, found no evidence of sensitive data being compromised, and continues to operate as usual.

Metabase Zero-Day Exploited in Data-Theft Attacks
Metabase Cloud was recently hit by a data-theft attack, exploiting a previously unknown security vulnerability in versions 1.58 and above, which the company has since patched and confirmed had a maximum severity rating. If you're a self-hosted customer, you'll need to update manually to protect yourself.