Tag: cloud security
259 articles

APAC Firms Scramble to Bolster Cloud Security Amid Rising Identity Risks
As APAC firms rush to adopt cloud technology, they're faced with a daunting dilemma: do they risk advancing without a plan, or delay and let identity-related risks leave them vulnerable? With identity issues already causing the majority of cloud breaches in the region, the clock is ticking to get cloud security right.

Unit 42 Research Exposes Risks in Amazon Bedrock's Multi-Agent AI Systems
Unit 42's latest research reveals a hidden threat: multi-agent AI systems on Amazon Bedrock can be vulnerable to new and alarming risks, including prompt injection attacks that practitioners can't afford to ignore. Learn how to safeguard your AI applications from these emerging threats.

Vulnerabilities Exposed in Amazon Bedrock AgentCore Sandbox
Security researchers at Unit 42 have uncovered critical vulnerabilities in Amazon Bedrock AgentCore's sandbox, revealing that a protective layer meant to separate code and services can be breached using DNS tunneling, exposing sensitive credentials in the process. This alarming discovery highlights the potential risks of slipping through the cracks of a supposedly secure system.

Kubernetes Environments Under Siege as Attacks Escalate
Kubernetes environments are under attack like never before, with threat actors exploiting identities and critical vulnerabilities to compromise cloud infrastructure - so what can organizations do to protect themselves? The warning signs are clear: it's time to take action against escalating Kubernetes attacks.

Snowflake Breach Compounds as Hackers Exploit Integrator Vulnerability
A recent breach of a SaaS integration provider has led to a Snowflake data breach, with stolen authentication tokens being used to compromise the sensitive data of over a dozen companies. This devastating chain of events highlights the urgent need for robust security measures to protect against increasingly sophisticated cyber threats.

ComfyUI Instances Enlisted in Widespread Cryptomining Botnet Campaign
A sneaky campaign is on the hunt for exposed ComfyUI instances, using them to fuel a cryptomining botnet and secretly install malicious nodes - putting unsuspecting users' systems at risk. This covert operation uses a Python scanner to scour cloud IP ranges, exploiting vulnerabilities and turning systems into cryptocurrency-mining machines.

Iranian Hackers Launch Sustained Password-Spraying Attack on Israeli Microsoft 365 Users
Iranian hackers have launched a relentless password-spraying attack on hundreds of Israeli Microsoft 365 users, sparking urgent concerns about the security of cloud inboxes in the midst of a regional conflict. This ongoing campaign, attributed to an Iran-linked threat actor, has already targeted over 300 organizations in Israel and the UAE.

Cloud Security Gaps Exposed on World Cloud Security Day
On World Cloud Security Day, it's clear that cloud security gaps are a pressing concern, but how do we measure the security of a technology that's both virtual and physical? Today's snapshot of cloud security reveals an uncertain landscape where digital protections and tangible safeguards intersect.

Securing Identities in a Decentralized Workforce
In today's decentralized workforce, the traditional network perimeter has disappeared, leaving us with a pressing question: who's responsible for securing identities when and where work happens? The shift to hybrid work has created a diffuse and distributed perimeter, where users and applications are scattered across various networks, devices, and clouds, making it harder for traditional security models to keep up.

AI Boosts Pentesting Efficiency by 40% at Amazon
Amazon's security team has achieved a game-changing 40% boost in pentesting efficiency by harnessing the power of artificial intelligence, significantly speeding up the process of identifying vulnerabilities and keeping the internet more secure. This innovative approach is a major win for productivity and a strong indicator of AI's growing role in cybersecurity.

Critical Vertex AI Vulnerability Exposes Google Cloud Data to Alarming Risks
A critical vulnerability in Google Cloud's Vertex AI platform has been uncovered, leaving sensitive data alarmingly exposed to potential breaches - can we trust the security of the platforms powering our AI-driven innovations? This security blind spot could allow malicious actors to exploit AI agents and compromise cloud environments, putting organizations at risk.

Alarming API Leak Exposes Global Bank's Cloud Credentials
A recent study has uncovered a shocking security risk, revealing that hundreds of valid API keys - essentially digital master keys - have been left exposed on the web, putting sensitive information at risk. This alarming API leak highlights the urgent need for stronger API security measures to protect our data.

Critical Cloud Breach Devastates European Commission Data
A recent cloud data breach has struck the European Commission, compromising its Amazon Web Services infrastructure and raising urgent questions about the security of even the most protected systems. What's alarming is that this breach highlights the vulnerabilities of cloud-based data, putting sensitive information at risk.

AI Assistants Exclusive Shift, Best Security Tactics
AI assistants can act as intern, coder and courier all at once—automating emails, scripts and cloud actions with near-total access. That convenience is collapsing old defenses, so organizations must rethink trusted access and adopt smarter security tactics before automation becomes an attack vector.

DoD Cloud Modernization Exclusive: Effortless Security
DoD Cloud Modernization can deliver faster decisions, resilient logistics, and stronger security—but only if we stop equating lift-and-shift with modernization. Re-architecting apps, automating defenses, and embracing DevSecOps will turn cloud promise into real protection for soldiers, allies, and critical supply chains.

CrowdStrike Stunning SGNL Deal Offers Best Identity Shield
CrowdStrike’s $740M acquisition of SGNL flips identity security from login to continuous authorization—pairing SGNL’s real‑time identity signals with CrowdStrike’s telemetry to fix identity hygiene and curb misuse by service accounts, machine IDs and AI agents. It’s a decisive bet that identity, not just authentication, is the new frontline of cyber defense.

Cybersecurity Best 2026 Predictions: Must-Have Insight
As quantum computers threaten to unlock todays encrypted data, moving to post-quantum cryptography is no longer optional but urgent. Here are five practical 2026 predictions— from large-scale rollouts and cryptographic agility to biometric trade-offs— that every technologist, policymaker and user should heed.

Cybersecurity Predictions 2026: Exclusive Best Defenses
Quantum computing is rewriting the rules of safety—post-quantum defense isn’t optional anymore as five trends, from quantum-safe cryptography to biometric and AI-driven systems, will decide who stays protected by 2026. Start building cryptographic agility and privacy-first biometric controls now to avoid “harvest now, decrypt later” surprises and stay one step ahead of attackers.

Amazon Exposes Stunning GRU Cyber Campaign, Energy Risk
Amazon Web Services says it uncovered a years‑long GRU cyber campaign that probed — and in some cases breached — Western energy and infrastructure, revealing how attackers now hide in everyday cloud tools. It’s a wake‑up call: social engineering, OAuth abuse and bespoke malware can turn our networks and power grids into espionage targets.

Private AI Compute: Exclusive, Effortless On-Device Privacy
Imagine Gemini-level AI power with your personal data locked away from prying eyes. Googles Private AI Compute promises that blend — using cryptographic and architectural controls to keep your inputs private while delivering cloud-scale performance.

AWS Targets Security Startups: Exclusive Best Bets
With just two weeks to apply, AWS Targets Security Startups fast-tracks early cloud and AI security founders into a cohort with AWS, CrowdStrike and Nvidia for mentorship, technical integration, and investor introductions. Its a rare chance to turbocharge fundraising and distribution—if youre ready to trade some independence for speed.

Google Workspace: Exclusive Guide to Best Security
Want to secure Google Workspace without turning your startup into a locked-down fortress? This guide helps first security hires prioritize real risks, fix permissive defaults, and keep teams productive while shutting the door on attackers.

Sneaky Mermaid attack: Exclusive critical Copilot leak
Researchers uncovered a Sneaky Mermaid trick that hid malicious instructions inside ordinary files to make Microsoft 365 Copilot leak tenant emails and attachments. Microsoft patched the specific vector, but the episode is a wake-up call about how AI assistants can be manipulated and why teams must shore up their digital defenses.

Security Leaders Exclusive: Critical Reasons 77% Lose Data
77% of organizations have experienced insider-related data loss in the last 18 months. Insider risk is no longer a niche IT problem—it’s an urgent, practical challenge driven by identity sprawl, cloud complexity and human pressures.