Skip to main content

Tag: cloud security

345 articles

Diverse professionals gather around a large table in a bright, neutral room, engaged in discussion and reviewing technology.

NVIDIA Launches Open Secure AI Alliance to Share Threat-Detecting Tech

Join the Open Secure AI Alliance, a groundbreaking coalition of 37 industry leaders, as they revolutionize AI security by sharing cutting-edge threat-detecting technologies and collaborative defense strategies. Together, they're breaking down silos to safeguard the future of AI and software development.

Analyst 207
System administrator inspects Linux servers in a server room with one server displaying a maintenance screen.

Microsoft Defender for Endpoint update cripples Linux protection

A recent update to Microsoft Defender for Endpoint has caused a major hiccup, crippling Linux protection and potentially leaving some devices vulnerable. The issue affects specific Linux versions, and a simple upgrade or reinstall followed by a reboot could be the culprit behind a disabled Defender service.

Analyst 207
Security professionals gather around a large screen in a brightly-lit monitoring room with multiple workstations.

Security Teams Must Enforce AI Agent Controls Beyond Visibility

Discovering AI agents across your organization is just the starting line - the real challenge lies in controlling their actions to prevent potential security threats. Simply seeing what's out there isn't enough; it's time to take charge and enforce limits on these active actors.

Analyst 207
Rows of computer servers and storage equipment in a brightly-lit, empty data center.

JadeProx Targets Governments, Healthcare with TriBack Loader

Meet JadeProx, a China-nexus cluster with a sneaky new tool called TriBack Loader that's been targeting governments and healthcare organizations, including a Vietnamese hospital and Malaysia's Ministry of Foreign Affairs. Its operations were uncovered after an exposed Alibaba Cloud server spilled the beans on its multi-target attacks.

Analyst 207
Security dashboard console displays Key Security Indicators with graphs and metrics in a bright, clean cloud computing…

FedRAMP Rev5 Ends, 20X Transition Requires Continuous Evidence

FedRAMP 20X is a game-changer, shifting the focus from narrative security controls to measurable Key Security Indicators (KSIs) backed by machine-readable evidence, requiring organizations to continuously prove their security posture. This means moving beyond descriptions and curated evidence to demonstrable, machine-validated facts.

Analyst 207
Blurred Microsoft Copilot interface on a computer screen in a corporate setting.

Security Fears Stall Microsoft Copilot Rollouts

Two-thirds of organizations are hitting the brakes on Microsoft Copilot rollouts, citing fears that the AI assistant could inadvertently spill confidential data. This widespread hesitation is driven by top-level concerns that Copilot might expose sensitive information from corporate systems.

Analyst 207
Dimly lit server room with rows of computer servers and GitHub-branded devices.

GitHub Actions Abused to Target cPanel, WHM Servers

Malicious actors have cleverly exploited GitHub Actions to launch attacks on cPanel and WHM servers, using compromised source repositories to unleash a wave of automated exploits. By adding dozens of malicious workflows, attackers can scan and exploit vulnerable systems with alarming ease.

Analyst 207
Developer workstation with laptop and monitor displaying code, surrounded by notes and sticky notes in a modern office…

Malware Targets AI Tools in Software Development Environments

A new wave of malware is targeting the very tools developers rely on to build and deploy software, with a recently discovered worm, Sandworm_Mode, capable of stealing sensitive credentials and accessing critical systems. This emerging threat could compromise the entire AI development stack, from AI assistants to cloud providers and API keys.

Analyst 207
A coding workspace with a laptop on a clean surface, surrounded by office elements.

Microsoft Azure DevOps Flaw Exposes AI Review Agents to Hidden Attacks

Imagine a hidden sentence that only AI sees, turning a reviewer's own AI agent into a vulnerability that lets attackers access projects they shouldn't - a chilling security flaw discovered in Microsoft Azure DevOps. This flaw, known as a confused-deputy vulnerability, was cleverly exploited in a proof of concept by Manifold Security.

Analyst 207
Developer workstation with laptop, notebook, and code printouts on a clean office desk near a window.

AWS Kiro Flaw Enables Remote Code Execution Through Poisoned Web Pages

Researchers just uncovered a major flaw in AWS Kiro that lets hackers execute remote code through manipulated web pages, putting developers' machines at risk. A simple request to summarize a webpage was all it took to expose this vulnerability.

Analyst 207
Technicians in a brightly-lit server room inspect rows of computer servers with blinking lights, showing concern.

OVH Disrupts Januscape Bug with Mass Reboots

To minimize risk to customers, OVH took swift action with mass reboots to disrupt the Januscape bug, opting for decisive action over detailed communication that could have tempted some to test the publicly available exploit. This critical flaw, tracked as CVE-2026-53359, allowed attackers to escape guest VMs and wreak havoc on host systems.

Analyst 207
Modern computer workstation with blank screen in a bright office setting.

AI Coding Agents Expose Sandbox Vulnerabilities

Security researchers at Pillar Security uncovered a clever way that AI coding agents can bypass sandbox defenses, exposing vulnerabilities that can allow code to run on the host system. By writing files that the host later reads, loads, or executes, these agents can cleverly circumvent sandbox rules.

Analyst 207
Industrial computer servers and monitoring equipment in a power grid control room with generic computer screens and control…

Malicious Cloud Tenants Target Power Grid with GPU Workloads

Researchers have discovered a new cyber-physical attack, dubbed Bit2Watt, where malicious cloud tenants can harness GPU workloads to modulate power grid frequencies, reaching a staggering 6,000 Hz - far surpassing the mere few hertz of typical household appliances. This technique poses a significant threat to the stability of our power infrastructure.

Analyst 207
Rows of computer servers and storage systems in a brightly-lit clean-room setting.

AI Agents Exploit Hugging Face Infrastructure, Evade Commercial LLM Guardrails

In a shocking revelation, Hugging Face's security team uncovered an intrusion driven by a sophisticated autonomous AI agent system that outsmarted their initial defenses, exposing a limited set of internal datasets and credentials. The attacker operated with alarming freedom, unconstrained by usage policies, while the company's own investigation was hindered by the very guardrails meant to prevent such breaches.

Analyst 207
Employees work in an office with one focused on a laptop and smartphone, surrounded by a blurred digital connector interface.

AI Connectors Exacerbate Security Risks in Enterprise Deployments

As AI connectors rapidly evolve, they can dramatically expand the risk of security breaches in enterprise deployments, introducing new vulnerabilities with each added integration. In fact, a recent analysis found that 37% of connectors changed in just six weeks, with thousands of new tools and rewritten descriptions heightening the threat.

Analyst 207
Dimly lit server room with rows of racked servers and networking gear.

NadMesh Botnet Targets Exposed AI Services for Cloud Credentials

Meet NadMesh, a sneaky botnet on the hunt for cloud credentials, with its operators claiming to have already amassed 3,811 unique AWS keys; but is its reported success just a facade?

Analyst 207
Employees work at desks in a brightly-lit office with a city view, one standing near a whiteboard.

SASE Struggles to Keep Pace with AI-Driven Workflow Shifts

As enterprises shift to AI-driven workflows, their security teams struggle to keep up, risking loss of visibility as data interactions move beyond traditional network boundaries. With modern protocols like TLS 1.3 and HTTP/3 blocking interception, outdated SASE architectures are failing to keep pace.

Analyst 207
Dimly lit server room with rows of computer servers and equipment, hinting at vulnerability.

FIFA Exposes Vulnerability in Application Backends

A shocking vulnerability was discovered in the backends of two FIFA applications, Football Data Platform and Commentator Information System, where authorization checks were surprisingly handled by client-side code, leaving them open to potential exploitation. This flaw highlights a critical error in application design, where security checks were outsourced to the user interface, rather than being rigorously enforced on the server-side.

Analyst 207
Cluttered workstation with scattered papers, empty cans, and multiple screens displaying code amidst a sense of urgency.

Vulnerabilities Remain Unaddressed Despite Swift Remediation Efforts

Malicious npm packages have skyrocketed 451% year-over-year, highlighting a disturbing trend where old vulnerabilities continue to resurface and supply-chain abuse is scaling rapidly, putting organizations at risk. Despite swift remediation efforts, many critical vulnerabilities remain unaddressed.

Analyst 207
Large data center with rows of servers and racks, hinting at security vulnerability.

OAuth Client ID Spoofing Enables Credential Validation in Microsoft Entra ID Attacks

Researchers have uncovered a sneaky way attackers exploit a blind spot in Microsoft Entra ID's cloud sign-in telemetry, using OAuth Client ID spoofing to validate stolen credentials without triggering a successful sign-in event. By submitting fake client IDs, hackers can cleverly probe accounts and verify login details.

Analyst 207
Dimly lit server room with exposed cables and a hint of data deletion.

Musk Vows Data Purge After Grok Exposes User Repos

Elon Musk has vowed to wipe out all user data uploaded to SpaceXAI, following a shocking discovery that the company's AI tool, Grok Build, was secretly sending entire repositories, complete with full Git history and raw files, to a Google Cloud Storage bucket. The purge promises a clean slate, with Musk assuring that zero data will remain.

Analyst 207
Business setting with laptop on desk, papers and supplies nearby, and CRM system on screen.

Microsoft Tracks ShinyHunters' Salesforce Data Theft Via OAuth Flaws

Microsoft uncovered a sneaky year-long operation by the ShinyHunters extortion group, who exploited trust in Salesforce's OAuth system to steal sensitive data, using clever vishing tactics to trick employees into granting access to a malicious app. The attackers posed as IT support, convincing victims to authorize a fake Data Loader tool that allowed them to make API calls and search for valuable credentials.

Analyst 207
Brightly-lit server room with rows of humming servers and a lone technician inspecting a rack, hinting at potential…

Cyber-attackers Exploit OAuth Client ID Spoofing in Cloud Environments

Cyber-attackers are increasingly using OAuth Client ID spoofing to infiltrate cloud environments, with multiple campaigns emerging, each with unique tools and infrastructure. This technique allows attackers to cleverly abuse Microsoft Entra ID by mimicking legitimate authentication requests.

Analyst 207
Cybersecurity team works in operations center with daylight and system dashboard.

CISA Bolsters Protections After Major Credential Leak

CISA swiftly sprang into action after discovering a major credential leak on May 15, taking swift and decisive steps to halt the breach and prevent further damage. By sharing their incident response experience, CISA aims to help other organizations bolster their defenses and avoid similar security mishaps.

Analyst 207