Back to Feed

Tag

Cloud Security

50 items tagged #cloud-security

Articles

5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours

Megalodon attack compromises 5,561 GitHub repos via malicious CI workflows in six hours.

Deleted Google API Keys Remain Active up to 23 Minutes, Study Finds

Deleted Google API keys remain active for up to 23 minutes due to eventual consistency delays.

‼️🇪🇸 Ícaro Cloud Allegedly Breached: Firewall Configs, VPN Keys, TLS Certificates, and Internal...

Ícaro Cloud breach exposes firewall configs, VPN keys, and TLS certs for 20 Spanish firms.

‼️🇺🇸 CoreWeave allegedly breached: full infrastructure access claimed against the US GPU cloud...

CoreWeave GPU cloud provider allegedly breached with full infrastructure access claimed.

Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator

Fortinet patches critical RCE flaws in FortiSandbox and FortiAuthenticator.

FutureShop Egypt Allegedly Breached Exposing Thousands of Customer, Order, and Delivery Records From the Egyptian Grocery Delivery Platform

FutureShop Egypt breached via unauthenticated API exposure, leaking 3,893 customer profiles and 5,181 orders.

Google and Amnesty International teamed up to make it harder for spyware vendors to hide

Google launches Intrusion Logging feature for Android to aid forensic detection of spyware attacks.

SAP Patches Critical S/4HANA, Commerce Vulnerabilities

SAP patches 15 critical and high-severity vulnerabilities in S/4HANA, Commerce, and other enterprise products.

Why Agentic AI Is Security's Next Blind Spot

Agentic AI systems running in production lack security team oversight and understanding, creating emerging blind spots.

OpenAI Launches Daybreak for AI-Powered Vulnerability Detection and Patch Validation

OpenAI launches Daybreak, an AI-powered platform for vulnerability detection and patch validation.

Why Changing Passwords Doesn’t End an Active Directory Breach

Password resets alone don't remove attackers from AD; cached credentials and Kerberos tickets enable persistence.

‼️🇬🇧 Arup Group allegedly breached by FulcrumSec exposing 700GB of GitHub repos and 2TB of Azur...

FulcrumSec claims breach of Arup Group exposing 700GB GitHub repos and 2TB Azure data.

Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI

Chrome extension flaw in Anthropic's Claude allows malicious plugins to hijack AI agent without permissions.

AI Firm Braintrust Prompts API Key Rotation After Data Breach

Braintrust AI platform suffers AWS account breach exposing customer API keys.

‘PCPJack’ Worm Removes TeamPCP Infections, Steals Credentials

PCPJack worm removes TeamPCP infections while stealing credentials from cloud environments.

‼️🇮🇳 Indian real estate firm allegedly being sold as Azure AD server admin access A threat act...

Threat actor offers Azure AD admin access to Indian real estate firm for sale.

After Replacing TeamPCP Malware, 'PCPJack' Steals Cloud Secrets

PCPJack malware replaces TeamPCP, targets cloud environments for credential theft.

‼️🇫🇷 Deezer allegedly leaked exposing 2.5 million Russian user records from the French music st...

Deezer allegedly breached, exposing 2.5M Russian user records.

New PCPJack worm steals credentials, cleans TeamPCP infections

PCPJack worm steals cloud credentials and removes TeamPCP infections from compromised systems.

PCPJack Credential Stealer Exploits 5 CVEs to Spread Worm-Like Across Cloud Systems

PCPJack credential stealer exploits 5 CVEs to spread worm-like across cloud infrastructure.

What PCPJack does after it wins the turf war: 🔑 Steals cloud credentials across AWS, Kubernetes,...

PCPJack malware steals cloud credentials from AWS, Kubernetes, Docker, and 30+ services.

PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale

PCPJack cloud worm evicts TeamPCP artifacts and harvests credentials from exposed infrastructure.

Threat actors are in a turf war for ownership of your infrastructure. @LabsSentinel has uncovered...

PCPJack cloud credential worm evicts rival TeamPCP in infrastructure turf war.

A DOD contractor’s API flaw exposed military course data and service member records

DOD contractor Schemata's API flaw exposed military training data and service member records for 150 days.

‼️🇧🇷 IUNGO Cloud (https://t.co/ntF9IS6ZqQ) allegedly leaked exposing 21M corporate email addres...

IUNGO Cloud breach exposes 21M corporate email addresses from Brazilian cloud-telephony operator.

Google's Android Apps Get Public Verification to Stop Supply Chain Attacks

Google expands Binary Transparency for Android to detect supply chain attacks on Google apps.

Massive “Low and Slow” DDoS Attack Hits Platform With 2.45 Billion in 5 Hours

DataDome uncovers massive 2.45B-request DDoS attack using 1.2M IPs in 5 hours

Copy Fail (CVE-2026-31431) is a critical privilege escalation in the Linux kernel's crypto subsys...

CVE-2026-31431 critical privilege escalation found in Linux kernel crypto subsystem

Microsoft Edge Stores Passwords in Process Memory, Posing Enterprise Risk

Microsoft Edge stores passwords in process memory, enabling theft via admin access.

The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed

Unmanaged OAuth tokens from AI and SaaS apps create persistent backdoors most organizations aren't monitoring.

Researchers report Amazon SES abused in phishing to evade detection

Kaspersky reports Amazon SES abuse in phishing campaigns exploiting exposed AWS credentials.

Amazon SES increasingly abused in phishing to evade detection

Amazon SES increasingly abused for phishing via exposed AWS IAM credentials.

Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities

Researchers reveal 20-year-old PostgreSQL flaws in pgcrypto at Wiz ZeroDay.Cloud event.

Exploitation of ‘Copy Fail’ Linux Vulnerability Begins

Linux kernel vulnerability CVE-2026-31431 (Copy Fail) exploited for root privilege escalation.

“Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security

Attackers exploit Amazon SES to conduct large-scale phishing campaigns bypassing email security checks.

ConsentFix v3 attacks target Azure with automated OAuth abuse

ConsentFix v3 automates OAuth phishing attacks against Azure with Pipedream integration.

CVE-2026-31431: Copy Fail vulnerability enables Linux root privilege escalation across cloud environments

CVE-2026-31431 Copy Fail vulnerability enables Linux root privilege escalation across cloud environments.

Lessons from the PocketOS Incident: When AI Agents Go Beyond Their Limits

AI agent deleted live production database and backups in 9 seconds due to over-permissioned API access.

New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials

DEEP#DOOR Python backdoor steals credentials via tunneling service and disables Windows security.

Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System

Unit 42 demonstrates autonomous multi-agent AI system attacking cloud environments via chained exploits.

Autonomous AI is a force multiplier for cloud misconfiguration exploitation. Our multi-agent pen-...

Researchers demonstrate Zealot, an autonomous AI multi-agent pen-testing system that exploits cloud misconfigurations.

Cursor AI Agent Wipes PocketOS Database and Backups in 9 Seconds

Cursor AI agent deleted PocketOS production database and backups in 9 seconds using misused root API token.

Learning from the Vercel breach: Shadow AI & OAuth sprawl

Vercel breach exposed via compromised OAuth app integration with Google Workspace.

GitHub fixes RCE flaw that gave access to millions of private repos

GitHub patches critical RCE vulnerability allowing access to millions of private repositories

Critical GitHub Vulnerability Exposed Millions of Repositories

Critical RCE vulnerability CVE-2026-3854 in GitHub exposed millions of repositories to code execution.

LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure

LiteLLM SQL injection CVE-2026-42208 exploited within 36 hours of disclosure.

Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push

Critical GitHub CVE-2026-3854 RCE flaw exploitable via git push command injection.

Microsoft Patches Entra ID Role Flaw That Enabled Service Principal Takeover

Microsoft patches Entra ID Agent ID Administrator role flaw enabling service principal takeover.

UNC6692 Combines Social Engineering, Malware, Cloud Abuse

UNC6692 threat actor deploys Snow malware via Teams and AWS S3 in multi-stage campaign.

ShinyHunters Leaks Data of Udemy, Zara, 7-Eleven in Salesforce Linked Breach

ShinyHunters leaks data from Udemy, Zara, and 7-Eleven via Salesforce and third-party cloud breaches.