Skip to main content

Tag: cloud security

345 articles

Rows of racked servers and storage equipment in a brightly-lit data center with IT staff in the background.

Azure Exfiltration Campaign Exposes 3.6 Million Records

A shocking data breach has hit major players like McDonald's and Gap Inc., with a hacker claiming to have made off with a staggering 3.6 million Azure account records, including 1.7 million sensitive employee records from McDonald's alone. The breach exposes names, emails, addresses, and more, serving as a stark reminder that traditional security perimeters just aren't enough.

Analyst 207
Network administrators review system logs on a laptop in a modern server room.

Hackers Exploit MFA Gaps with 155x Surge in Password Spraying Attacks

Hackers are taking advantage of weaknesses in multi-factor authentication, launching a staggering 155 times more password spraying attacks in the first half of 2026. These attacks aren't about fancy new tools, but rather exploiting old authentication paths that slip past security defenses.

Analyst 207
Brightly-lit cloud computing data center with rows of servers and technicians in the background, and a laptop screen on a…

Attackers Exploit MLflow Flaw to Steal Cloud Credentials

A newly discovered vulnerability in MLflow, CVE-2026-64849, with a near-perfect CVSS score of 9.3 is being exploited by attackers to infiltrate cloud metadata services and steal sensitive credentials. This critical flaw allows hackers to issue unauthorized requests and extract confidential data, putting your cloud security at risk.

Analyst 207
Laptop on a desk with a blurred background and a suspicious link on paper.

Microsoft Copilot Flaws Expose One-Click Data Exfiltration Risk

Researchers uncovered a set of flaws in Microsoft Copilot, dubbed CoSnitch, that could allow attackers to exploit a user's session with just one click, potentially leading to data exfiltration. A single crafted link could trigger actions inside a signed-in user's assistant session, putting sensitive information at risk.

Analyst 207
Developer workstation with laptop, monitor, and papers, set against a blurred cityscape background.

Wiz AI Tool Exposes Snowflake GitHub Repo Vulnerability Missed by Advanced Security

Wiz AI Tool Exposes Snowflake GitHub Repo Vulnerability Missed by Advanced Security Meet Red Agent, the game-changing AI tool that uncovered a script injection vulnerability in Snowflake's GitHub repository that even advanced security scans missed. This autonomous security researcher not only identified the flaw but also exploited it and assessed the damage - all without human help.

Analyst 207
Blurred laptop screen in a generic corporate workspace with subtle tech infrastructure.

TWINLOOT Exploits Microsoft Services to Steal Credentials

Meet TWINLOOT, a sneaky Python implant that hides its command-and-control infrastructure inside trusted Microsoft services, making it super hard to detect. It uses SharePoint Online and Microsoft Teams to operate undetected, even leveraging a victim's own Edge browser to blend in.

Analyst 207
Researcher in modern lab looks at laptop screen with concern.

Microsoft Copilot Exposes Vulnerability to Meta-Hacking

Researchers at Varonis Threat Labs uncovered a vulnerability in Microsoft Copilot, cleverly manipulating it to reveal its own weaknesses and craft a working attack, which they've dubbed CoSnitch. This surprising exploit was responsibly disclosed to Microsoft, which plans to issue a patch.

Analyst 207
Modern cityscape with sleek and industrial buildings, subtle network lines in foreground.

Salesforce, ServiceNow Portals Targeted in Ongoing Data Scraping Campaign

A single virtual private server has been secretly siphoning off sensitive records from Salesforce and ServiceNow customer portals since March 2025, according to recent research by Reco. This ongoing data scraping campaign, dubbed City Forum, has been quietly pulling data from multiple targets across various sectors.

Analyst 207
A lone laptop sits on a table in an empty corporate office lobby or data center.

Azure Breach Exposes 3.6 Million Records from Top Companies

A threat actor known as TheHatman is selling employee data from top companies like McDonald's and Tata Consultancy Services, allegedly stolen from Microsoft Azure tenants using compromised credentials. The stolen records total 3.6 million, with McDonald's alone accounting for 1.7 million employee records.

Analyst 207
Developer workstation with laptop and terminal, surrounded by notes and whiteboard, in a bright modern office.

Wiz Exposes GitHub Actions Flaw in Snowflake Repository

Researchers at Wiz uncovered a vulnerability in Snowflake's GitHub repository, where a flawed GitHub Actions workflow exposed a sensitive Jira API token, putting internal credentials at risk. This security gap allowed attackers to potentially execute commands using a crafted GitHub issue.

Analyst 207
Blurred employees walk past server racks in a brightly-lit corporate office or data center interior.

Azure Breach Exposes Millions of Employee Records at Top Firms

A threat actor known as TheHatman is peddling a staggering 1.7 million employee records from McDonald's, along with millions more from other top firms, allegedly stolen from Microsoft Azure environments. The breach, which Hudson Rock deems highly authentic, has left giants like Vodafone, Tata Consultancy Services, and IHG Hotels & Resorts vulnerable.

Analyst 207
Retail checkout counter with point-of-sale terminal and shopping cart amidst scattered items.

SAP Exploits Maximum-Severity Commerce Cloud Flaw in Active Attacks

SAP Commerce Cloud has a critical vulnerability, known as CVE-2026-58231, that allows unauthenticated attackers to wreak havoc by executing arbitrary code and compromising internal components. This maximum-severity flaw, scoring a perfect 10.0 on the CVSS scale, stems from weak authorization checks and input validation.

Analyst 207
Empty office cubicle with laptop, monitor, and papers, set against a blurred cityscape backdrop.

Google Workspace Security Must Adapt to AI-Driven Threats

The traditional attack chain is getting a makeover: instead of starting with a malicious email, attackers now use OAuth apps to breach Google Workspace, exploiting new vulnerabilities in an AI-driven threat landscape. It's time to shift from an inbox-centric to an OAuth-first security approach to stay ahead.

Analyst 207
Employees work at desks in a modern, brightly-lit office setting with laptops and phones.

ShinyHunters Breach Exposes 1.6 Million RingCentral Accounts

RingCentral has confirmed that a breach, known as ShinyHunters, compromised 1.6 million of its accounts, but has since taken swift action to prevent further unauthorized activity. The company is now directly contacting affected customers and has assured that its core platform remains secure and operational.

Analyst 207
People work and chat in a brightly-lit charity office with subtle tech hints.

Compromised AWS Key Exposes 1500+ UK Charities to Data Breach

Over 1,500 UK charities are reeling after a data breach at CRM provider Beacon exposed their personal information, likely due to a compromised AWS access key. This devastating cyber-attack has left countless organizations vulnerable, sparking urgent concerns about data security.

Analyst 207
Empty office workspace with laptop, papers, and city view, conveying shared responsibility.

Microsoft's Shared Responsibility Model Exposes SaaS Backup Gaps

Many organizations mistakenly assume Microsoft handles data restoration, but the reality is their Shared Responsibility Model leaves SaaS backup gaps that can expose customers to data loss and ransomware attacks. Native recovery tools only address short-term data issues, not long-term cyber resilience.

Analyst 207
Blurred object on a neutral surface in front of a brightly-lit cloud computing facility with rows of servers and storage…

Beacon Breach Exposes Charity Data After AWS Key Compromise

A security breach at Beacon compromised customer data, including attachment files, after an AWS access key was potentially exposed in public JavaScript build artifacts, allowing attackers to retrieve encrypted data in readable form. The breach, which started on July 27-28, 2026, may have resulted in a downloadable copy of the database.

Analyst 207
Laptop screen displays cloud storage interface with file list and password file next to text box.

Researchers Discover Context Bombing Technique to Disrupt AI Hacking Agents

Researchers have discovered a clever way to shut down AI hacking agents by inserting specially crafted prompts alongside sensitive data on Amazon Web Services, effectively triggering the model's internal safety rules and halting attacks. This innovative technique, dubbed "context bombing," has proven to be a simple yet effective defense against AI-powered hacking.

Analyst 207
Laptop on a desk in a bright office shows Google Docs with sensitive credentials blurred, surrounded by papers and supplies.

Google Docs Exposes Staging Server Credentials in Search Results

A simple Google search led to a major security slip-up when a developer stumbled upon a publicly indexed Google Doc containing sensitive staging server credentials. A careless mistake by an outside contractor had left the confidential info exposed, and a curious autocomplete suggestion revealed it all.

Analyst 207
Public sector office interior with subtle digital infrastructure and blurred people in the background.

City-Forum Attacks Exploit Salesforce, ServiceNow Portals for Data Theft

A single IP address, 158.220.87.79, has been linked to a massive data-theft campaign targeting corporate and public portals, including Salesforce and ServiceNow, for over a year with no signs of slowing down. This persistent threat has compromised multiple organizations worldwide, spanning industries from telecom and finance to security and government.

Analyst 207
Concerned individuals in a cloud computing setting review a laptop amidst rows of servers.

Malicious LiteLLM Releases Expose Over 2,100 Organizations to Credential Theft

Over 2,100 organizations are at risk of credential theft due to malicious LiteLLM releases that harvested sensitive data, including environment variables, SSH keys, and cloud credentials, and sent it to an attacker-controlled domain. These compromised packages were live on PyPI for about 40 minutes on March 24, leaving a trail of potential exposure.

Analyst 207
Government employee works on laptop in secure data center with server racks.

FedRAMP High Becomes Benchmark for Mission-Critical Government Cloud Operations

The cloud is no longer just a migration target, but the operating environment for government missions, and FedRAMP High has become the benchmark for ensuring the security and reliability of mission-critical cloud operations. FedRAMP High is now a mission requirement, not just a compliance checkbox, providing the highest level of security controls for systems where data loss could have serious consequences.

Analyst 207
Blurred office interior with rows of workstations and a single laptop screen on a desk.

Wesco Probes Data Exfiltration After ExfilSquad Leak Claim

Wesco is investigating a cybersecurity incident involving its cloud CRM environment after a third-party group, ExfilSquad, claimed to have exfiltrated company data. The company says it has contained the issue, found no evidence of sensitive data being compromised, and continues to operate as usual.

Analyst 207
Laptop screen on a plain desk in a blurred office setting with a faint shadow.

Metabase Zero-Day Exploited in Data-Theft Attacks

Metabase Cloud was recently hit by a data-theft attack, exploiting a previously unknown security vulnerability in versions 1.58 and above, which the company has since patched and confirmed had a maximum severity rating. If you're a self-hosted customer, you'll need to update manually to protect yourself.

Analyst 207