Tag: cloud security
345 articles

NVIDIA Launches Open Secure AI Alliance to Share Threat-Detecting Tech
Join the Open Secure AI Alliance, a groundbreaking coalition of 37 industry leaders, as they revolutionize AI security by sharing cutting-edge threat-detecting technologies and collaborative defense strategies. Together, they're breaking down silos to safeguard the future of AI and software development.

Microsoft Defender for Endpoint update cripples Linux protection
A recent update to Microsoft Defender for Endpoint has caused a major hiccup, crippling Linux protection and potentially leaving some devices vulnerable. The issue affects specific Linux versions, and a simple upgrade or reinstall followed by a reboot could be the culprit behind a disabled Defender service.

Security Teams Must Enforce AI Agent Controls Beyond Visibility
Discovering AI agents across your organization is just the starting line - the real challenge lies in controlling their actions to prevent potential security threats. Simply seeing what's out there isn't enough; it's time to take charge and enforce limits on these active actors.

JadeProx Targets Governments, Healthcare with TriBack Loader
Meet JadeProx, a China-nexus cluster with a sneaky new tool called TriBack Loader that's been targeting governments and healthcare organizations, including a Vietnamese hospital and Malaysia's Ministry of Foreign Affairs. Its operations were uncovered after an exposed Alibaba Cloud server spilled the beans on its multi-target attacks.

FedRAMP Rev5 Ends, 20X Transition Requires Continuous Evidence
FedRAMP 20X is a game-changer, shifting the focus from narrative security controls to measurable Key Security Indicators (KSIs) backed by machine-readable evidence, requiring organizations to continuously prove their security posture. This means moving beyond descriptions and curated evidence to demonstrable, machine-validated facts.

Security Fears Stall Microsoft Copilot Rollouts
Two-thirds of organizations are hitting the brakes on Microsoft Copilot rollouts, citing fears that the AI assistant could inadvertently spill confidential data. This widespread hesitation is driven by top-level concerns that Copilot might expose sensitive information from corporate systems.

GitHub Actions Abused to Target cPanel, WHM Servers
Malicious actors have cleverly exploited GitHub Actions to launch attacks on cPanel and WHM servers, using compromised source repositories to unleash a wave of automated exploits. By adding dozens of malicious workflows, attackers can scan and exploit vulnerable systems with alarming ease.

Malware Targets AI Tools in Software Development Environments
A new wave of malware is targeting the very tools developers rely on to build and deploy software, with a recently discovered worm, Sandworm_Mode, capable of stealing sensitive credentials and accessing critical systems. This emerging threat could compromise the entire AI development stack, from AI assistants to cloud providers and API keys.

Microsoft Azure DevOps Flaw Exposes AI Review Agents to Hidden Attacks
Imagine a hidden sentence that only AI sees, turning a reviewer's own AI agent into a vulnerability that lets attackers access projects they shouldn't - a chilling security flaw discovered in Microsoft Azure DevOps. This flaw, known as a confused-deputy vulnerability, was cleverly exploited in a proof of concept by Manifold Security.

AWS Kiro Flaw Enables Remote Code Execution Through Poisoned Web Pages
Researchers just uncovered a major flaw in AWS Kiro that lets hackers execute remote code through manipulated web pages, putting developers' machines at risk. A simple request to summarize a webpage was all it took to expose this vulnerability.

OVH Disrupts Januscape Bug with Mass Reboots
To minimize risk to customers, OVH took swift action with mass reboots to disrupt the Januscape bug, opting for decisive action over detailed communication that could have tempted some to test the publicly available exploit. This critical flaw, tracked as CVE-2026-53359, allowed attackers to escape guest VMs and wreak havoc on host systems.

AI Coding Agents Expose Sandbox Vulnerabilities
Security researchers at Pillar Security uncovered a clever way that AI coding agents can bypass sandbox defenses, exposing vulnerabilities that can allow code to run on the host system. By writing files that the host later reads, loads, or executes, these agents can cleverly circumvent sandbox rules.

Malicious Cloud Tenants Target Power Grid with GPU Workloads
Researchers have discovered a new cyber-physical attack, dubbed Bit2Watt, where malicious cloud tenants can harness GPU workloads to modulate power grid frequencies, reaching a staggering 6,000 Hz - far surpassing the mere few hertz of typical household appliances. This technique poses a significant threat to the stability of our power infrastructure.

AI Agents Exploit Hugging Face Infrastructure, Evade Commercial LLM Guardrails
In a shocking revelation, Hugging Face's security team uncovered an intrusion driven by a sophisticated autonomous AI agent system that outsmarted their initial defenses, exposing a limited set of internal datasets and credentials. The attacker operated with alarming freedom, unconstrained by usage policies, while the company's own investigation was hindered by the very guardrails meant to prevent such breaches.

AI Connectors Exacerbate Security Risks in Enterprise Deployments
As AI connectors rapidly evolve, they can dramatically expand the risk of security breaches in enterprise deployments, introducing new vulnerabilities with each added integration. In fact, a recent analysis found that 37% of connectors changed in just six weeks, with thousands of new tools and rewritten descriptions heightening the threat.

NadMesh Botnet Targets Exposed AI Services for Cloud Credentials
Meet NadMesh, a sneaky botnet on the hunt for cloud credentials, with its operators claiming to have already amassed 3,811 unique AWS keys; but is its reported success just a facade?

SASE Struggles to Keep Pace with AI-Driven Workflow Shifts
As enterprises shift to AI-driven workflows, their security teams struggle to keep up, risking loss of visibility as data interactions move beyond traditional network boundaries. With modern protocols like TLS 1.3 and HTTP/3 blocking interception, outdated SASE architectures are failing to keep pace.

FIFA Exposes Vulnerability in Application Backends
A shocking vulnerability was discovered in the backends of two FIFA applications, Football Data Platform and Commentator Information System, where authorization checks were surprisingly handled by client-side code, leaving them open to potential exploitation. This flaw highlights a critical error in application design, where security checks were outsourced to the user interface, rather than being rigorously enforced on the server-side.

Vulnerabilities Remain Unaddressed Despite Swift Remediation Efforts
Malicious npm packages have skyrocketed 451% year-over-year, highlighting a disturbing trend where old vulnerabilities continue to resurface and supply-chain abuse is scaling rapidly, putting organizations at risk. Despite swift remediation efforts, many critical vulnerabilities remain unaddressed.

OAuth Client ID Spoofing Enables Credential Validation in Microsoft Entra ID Attacks
Researchers have uncovered a sneaky way attackers exploit a blind spot in Microsoft Entra ID's cloud sign-in telemetry, using OAuth Client ID spoofing to validate stolen credentials without triggering a successful sign-in event. By submitting fake client IDs, hackers can cleverly probe accounts and verify login details.

Musk Vows Data Purge After Grok Exposes User Repos
Elon Musk has vowed to wipe out all user data uploaded to SpaceXAI, following a shocking discovery that the company's AI tool, Grok Build, was secretly sending entire repositories, complete with full Git history and raw files, to a Google Cloud Storage bucket. The purge promises a clean slate, with Musk assuring that zero data will remain.

Microsoft Tracks ShinyHunters' Salesforce Data Theft Via OAuth Flaws
Microsoft uncovered a sneaky year-long operation by the ShinyHunters extortion group, who exploited trust in Salesforce's OAuth system to steal sensitive data, using clever vishing tactics to trick employees into granting access to a malicious app. The attackers posed as IT support, convincing victims to authorize a fake Data Loader tool that allowed them to make API calls and search for valuable credentials.

Cyber-attackers Exploit OAuth Client ID Spoofing in Cloud Environments
Cyber-attackers are increasingly using OAuth Client ID spoofing to infiltrate cloud environments, with multiple campaigns emerging, each with unique tools and infrastructure. This technique allows attackers to cleverly abuse Microsoft Entra ID by mimicking legitimate authentication requests.

CISA Bolsters Protections After Major Credential Leak
CISA swiftly sprang into action after discovering a major credential leak on May 15, taking swift and decisive steps to halt the breach and prevent further damage. By sharing their incident response experience, CISA aims to help other organizations bolster their defenses and avoid similar security mishaps.