HackMyIP

Cloud Security News

115 stories tagged Cloud Security

← All cybersecurity news

2026-08-14Dark Reading
Cyera's $1B Oasis Security Buy Redefines AI Agent Access Control

Cyera has announced a $1 billion acquisition of Oasis Security, signaling one of the largest deals in the data security space this year and a clear bet that the next frontier of...

AI SecurityCloud SecurityAuthentication
Read More → Use Tool →
2026-08-14SecurityWeek
Beacon CRM Breach Exposes Data of 1,000+ UK Charities

Beacon, a UK-based customer relationship management (CRM) provider serving the non-profit sector, has disclosed that a data breach impacting more than 1,000 charities stemmed from ...

Data BreachCloud SecuritySupply Chain
Read More → Use Tool →
2026-08-14SecurityWeek
Google Cloud Outlines Post-Quantum Cryptography Roadmap Targeting 2029

Google Cloud has published an updated roadmap for migrating its infrastructure to post-quantum cryptography (PQC), targeting full readiness by 2029 with some work extending into th...

EncryptionCloud SecurityRegulation
Read More → Use Tool →
2026-08-13Dark Reading
Critical VMware vCenter Flaw CVE-2026-59310 Exploited in Global Campaign

Security teams across the globe are scrambling to contain active exploitation of CVE-2026-59310, a critical vulnerability in VMware vCenter Server that threat actors began weaponiz...

VulnerabilityCloud SecurityThreat Intel
Read More → Use Tool →
2026-08-13SecurityWeek
21 Cybersecurity M&A Deals Reshape Industry in July 2026

Twenty-one cybersecurity-related merger and acquisition deals were announced in July 2026, signaling continued consolidation across identity protection, AI-driven detection, and ne...

Cloud SecurityAI SecurityAuthentication
Read More → Use Tool →
2026-08-13SecurityWeek
Team8 Raises $365M to Fuel AI-Native Cybersecurity Ventures

Israeli venture capital firm Team8 has closed $365 million in fresh capital, bringing its total assets under management to roughly $2 billion since its 2014 founding. According to ...

AI SecurityCloud Security
Read More → Use Tool →
2026-08-12The Hacker News
SAP Patches Critical Commerce Cloud Flaw Enabling Remote Code Execution

SAP has rolled out emergency patches for a maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter) that could allow unauthenticated attackers to execute arbitrary c...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-08-12Dark Reading
How Walmart Scaled Security Operations Through Trust and Innovation

Walmart, the world's largest retailer by revenue, has overhauled its security operations center (SOC) by leaning into a culture-first model that prioritizes psychological safety, t...

Incident ResponseThreat IntelCloud Security
Read More → Use Tool →
2026-08-12The Hacker News
Adobe Fixes Three CVSS 10.0 Flaws in ColdFusion & Campaign Classic

Adobe has rolled out emergency patches addressing multiple critical security vulnerabilities across ColdFusion, Commerce, and Campaign Classic that could allow attackers to execute...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-08-11SecurityWeek
Adobe Patches Critical ColdFusion, Campaign Classic Flaws – Update Now

Adobe released security updates on Tuesday addressing more than 50 vulnerabilities across its product portfolio, including critical-severity flaws in ColdFusion, Campaign Classic, ...

VulnerabilityCloud Security
Read More → Use Tool →
2026-08-07The Hacker News
UNC6671 Vishing Attacks Hijack Personal Phones to Steal SaaS Data

A financially motivated threat cluster tracked as UNC6671 has intensified its voice phishing (vishing) operations against enterprise employees in financial services, private equity...

PhishingThreat IntelCloud Security
Read More → Use Tool →
2026-08-07The Hacker News
CVE-2026-64564: 18-Year Linux SCTP Flaw Enables Root & Container Escape

A critical 18-year-old use-after-free vulnerability in the Linux kernel's SCTP networking stack, dubbed "SCTPhantom" and tracked as CVE-2026-64564, can grant local users root privi...

VulnerabilityCloud Security
Read More → Use Tool →
2026-08-06KrebsOnSecurity
Canadian Hacker Pleads Guilty in $2.5M Snowflake Data Breach Extortion

Connor Riley Moucka, of Kitchener, Ontario, has pleaded guilty to computer fraud and conspiracy charges stemming from a massive 2024 extortion campaign that compromised more than 1...

Data BreachCloud SecurityAuthentication
Read More → Use Tool →
2026-08-06The Hacker News
Zapscape KVM Flaw Lets L1 Guests Escape to Linux Hosts (CVE-2026-64561)

A newly disclosed Linux kernel vulnerability dubbed Zapscape (CVE-2026-64561) could allow an attacker with kernel-level access inside an L1 guest virtual machine t...

VulnerabilityCloud Security
Read More → Use Tool →
2026-08-05The Hacker News
Veeam, Terraform MCP, Django Patch 11 Critical Flaws Including CVSS 10.0

Three major software vendors — Veeam, HashiCorp, and the Django Software Foundation — released patches on August 5, 2026, addressing 11 vulnerabilities across Terraform MCP Server,...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-08-05The Hacker News
Critical Gitea Flaw (CVE-2026-59774) Lets Attackers Read Server Files Without Login

A critical vulnerability in Gitea, the self-hosted Git platform, allows unauthenticated attackers to read any file the service account can access—no login or repository write acces...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-08-05The Hacker News
Leaked n8n API Tokens Exposed 321 Live Instances to Credential Theft

GitGuardian researchers have uncovered a significant exposure of n8n workflow automation API tokens, identifying 4,576 unique credentials across 1,255 hostnames in public GitHub co...

Data BreachVulnerabilityCloud Security
Read More → Use Tool →
2026-08-04The Hacker News
Google Deletes ADK AI Workflows After GitHub Prompt Injection Flaw

Google has removed three AI agent workflows from its Agent Development Kit (ADK) Python repository after Pillar Security demonstrated that a malicious public GitHub issue could be ...

AI SecuritySupply ChainCloud Security
Read More → Use Tool →
2026-08-04The Hacker News
Critical cPanel Flaw Lets Hosting Users Hijack Database Root Access

cPanel has shipped an emergency patch for a critical privilege-escalation vulnerability that lets authenticated hosting customers execute arbitrary SQL commands with full database-...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-08-03The Hacker News
PNLD Breach Exposes UK Police and Government Contacts on Dark Web

The Police National Legal Database (PNLD), a service that provides legal information and products to UK police forces and criminal justice organisations, has confirmed a data breac...

Data BreachPhishingCloud Security
Read More → Use Tool →
2026-08-01The Hacker News
Adobe Patches CVSS 10.0 RCE Flaw in Campaign Classic, Bridge

Adobe has rolled out emergency security updates to address a maximum-severity vulnerability in Campaign Classic (ACC), its enterprise marketing automation platform, that could allo...

VulnerabilityCloud Security
Read More → Use Tool →
2026-08-01SecurityWeek
Critical Ruby on Rails Flaw CVE-2026-66066 Enables Unauthenticated RCE

Ruby on Rails maintainers have shipped emergency patches for a critical vulnerability, tracked as CVE-2026-66066 with a CVSS score of 9.5, that could let unauthenticated attackers ...

VulnerabilityCloud Security
Read More → Use Tool →
2026-07-30The Hacker News
Azure Cosmos DB Flaw Exposed Master Key to Any Customer Database

A now-patched vulnerability in Microsoft Azure Cosmos DB could have granted attackers full read and write access to databases across customer tenants, according to cloud securit...

VulnerabilityCloud SecurityZero-Day
Read More → Use Tool →
2026-07-30The Hacker News
Check Point Launches AI Network Firewall to Close Enterprise Visibility Gap

Check Point Software Technologies has unveiled what it calls the industry's first AI Network Firewall, a new class of network security designed to inspect, detect, and govern AI-dr...

AI SecurityCloud Security
Read More → Use Tool →
2026-07-29The Hacker News
Critical Rails Vulnerability CVE-2026-66066 Exposes Server Secrets via Image Uploads

Ruby on Rails has shipped emergency patches for a critical Active Storage vulnerability, tracked as CVE-2026-66066 with a CVSS score of 9.5, that enables unauthenticated attackers ...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-07-29The Hacker News
Critical VMware Flaws Enable Auth Bypass, Code Execution, and VM Escape

Broadcom has shipped urgent security updates to address five vulnerabilities affecting VMware ESX, vCenter Server, Workstation, and Fusion, three of which carry critical severity r...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-07-28Dark Reading
Dormant Cloud Credentials: Hidden Identity Risks Exposed by NHI Hound

Security researcher Aleksandr Krasnov has spotlighted a growing blind spot in cloud environments: dormant non-human identities (NHIs) that retain trust paths long after they should...

Cloud SecurityAuthenticationVulnerability
Read More → Use Tool →
2026-07-28The Hacker News
24,650 BMCs Leak IPMI Password Hashes Before Login — CVE-2013-4784 Still Unpatched

Cybersecurity researchers at Israeli firm Lava have identified more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing the Intelligent Platform Manage...

VulnerabilityAuthenticationCloud Security
Read More → Use Tool →
2026-07-27Ars Technica
Microsoft Unveils AI Security Tools, Claims Better Performance at Lower Cost

Microsoft has rolled out a new lineup of AI-powered security products designed to help enterprise defenders detect, investigate, and respond to threats at scale. The announcement, ...

AI SecurityCloud Security
Read More → Use Tool →
2026-07-27Dark Reading
Confused Deputy Flaws Expose Admin Access in Google Cloud and Azure

A class of vulnerabilities known as 'Confused Deputy' flaws continues to plague major cloud platforms, including Google Cloud and Microsoft Azure, according to researchers tracking...

Cloud SecurityVulnerabilityAuthentication
Read More → Use Tool →
2026-07-27The Hacker News
n8n Patches High-Severity Sandbox Escape Allowing OS Command Execution

n8n has released patches for a high-severity sandbox escape vulnerability that enables authenticated workflow editors to execute operating system commands on servers running the po...

VulnerabilityCloud Security
Read More → Use Tool →
2026-07-27The Hacker News
GitHub Adds 3-Day Dependabot Cooldown to Block Poisoned Packages

GitHub has rolled out a new cooldown mechanism in Dependabot that forces the automated dependency-management tool to wait at least three days after a package release is published b...

Supply ChainVulnerabilityCloud Security
Read More → Use Tool →
2026-07-25The Hacker News
GitLab RCE PoC Lets Authenticated Users Run Commands on Unpatched Servers

Security researcher depthfirst published working exploit code on July 24 for a GitLab remote code execution flaw that GitLab quietly patched on June 10 without filing it as a secur...

VulnerabilityCloud Security
Read More → Use Tool →
2026-07-24The Hacker News
Critical Bing SVG Flaws Let Attackers Run Commands as SYSTEM on Microsoft Servers

Two critical command-injection vulnerabilities in Bing Images allowed specially crafted SVG files to execute arbitrary code as NT AUTHORITY\SYSTEM on Microsoft's production image-p...

VulnerabilityBug BountyCloud Security
Read More → Use Tool →
2026-07-24Dark Reading
Azure Automation Flaw Enabled Cross-Tenant Identity Takeover

Microsoft has patched a critical configuration flaw in Azure Automation that, combined with a chain of code vulnerabilities, could have allowed attackers to take over identities be...

Cloud SecurityVulnerabilityAuthentication
Read More → Use Tool →
2026-07-23The Hacker News
RefluXFS: 9-Year-Old Linux Flaw Grants Root on Default RHEL Systems

Qualys has disclosed a nine-year-old Linux kernel vulnerability, tracked as CVE-2026-64600 and nicknamed RefluXFS, that enables unprivileged local users to overwrite root-owned fil...

VulnerabilityAuthenticationCloud Security
Read More → Use Tool →
2026-07-22The Hacker News
Critical Windmill Path Traversal Bug Under Active Attack — 170 Servers Exposed

A high-severity path traversal vulnerability in the open-source Windmill developer platform is being actively exploited in the wild, according to threat intelligence from VulnCheck...

VulnerabilityAuthenticationCloud Security
Read More → Use Tool →
2026-07-22The Hacker News
Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Agents

A single invisible comment embedded in an Azure DevOps pull request can silently hijack a reviewer's AI coding agent, steering it into projects the attacker has no permission to ac...

AI SecurityVulnerabilityCloud Security
Read More → Use Tool →
2026-07-21The Hacker News
Apple Patches Hide My Email Bug That Leaked Real Addresses in Mail Logs

Apple has resolved a critical privacy flaw in its Hide My Email service that silently exposed users' real email addresses in mail transfer logs, effectively defeating the feature's...

PrivacyVulnerabilityCloud Security
Read More → Use Tool →
2026-07-21The Hacker News
Critical ServiceNow AI Sandbox Escape Flaw Actively Exploited for RCE

Threat actors are weaponizing a severe sandbox escape vulnerability in the ServiceNow AI Platform, enabling unauthenticated attackers to execute arbitrary code on vulnerable instan...

VulnerabilityAI SecurityCloud Security
Read More → Use Tool →
2026-07-21SecurityWeek
HollowGraph Malware Uses Microsoft 365 Calendar as Dead-Drop C&C Channel

HollowGraph, a newly documented malware toolkit, is leveraging a compromised Microsoft 365 account's calendar as a two-way dead-drop for command-and-control (C&C) communication, ac...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2026-07-20The Hacker News
HollowGraph Malware Uses Microsoft 365 Calendar as Espionage Dead Drop

A newly uncovered espionage implant named HollowGraph is abusing Microsoft 365 calendar infrastructure as a covert command-and-control channel, smuggling both operator instructions...

MalwareAPTCloud Security
Read More → Use Tool →
2026-07-19The Hacker News
NGINX CVE-2026-42533: Critical Heap Overflow Bug Could Enable RCE

F5 has released patches for a critical vulnerability in the NGINX web server, tracked as CVE-2026-42533, that allows remote unauthenticated attackers to trigger a heap buffer overf...

VulnerabilityCloud Security
Read More → Use Tool →
2026-07-17The Hacker News
NadMesh Botnet Pivots to Cloud Credential Theft via Exposed AI Services

Researchers at QiAnXin's XLab have documented a new Go-language botnet called NadMesh that emerged in early July 2026 and is actively scanning the public internet for exposed AI in...

MalwareAI SecurityCloud Security
Read More → Use Tool →
2026-07-17Dark Reading
Google Cloud Integrates Wiz Into Agentic AI Defense Platform

Google Cloud is rolling out an 'agentic defense' strategy that folds key capabilities from its Wiz acquisition into a unified platform designed to automate threat detection and rem...

AI SecurityCloud SecurityThreat Intel
Read More → Use Tool →
2026-07-16The Hacker News
Critical Unpatched Shark Vacuum Flaw Lets Attackers Seize Devices Region-Wide

A serious unpatched vulnerability in SharkNinja robot vacuums allows attackers to extract device certificates from the hardware and use them to issue commands on other Shark vacuum...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-07-13KrebsOnSecurity
CISA GitHub Leak: Critical Lessons From Exposed AWS GovCloud Keys

When a contractor published a public GitHub repository called “Private CISA” on May 15, 2026, it exposed 844 MB of sensitive agency data—including administrative credentials to thr...

Data BreachIncident ResponseCloud Security
Read More → Use Tool →
2026-07-10The Hacker News
Progress Tells ShareFile Users to Shut Down Storage Zone Controllers Now

Progress Software has issued an urgent warning to ShareFile customers, instructing them to immediately take offline the Windows servers running their Storage Zone Controllers in re...

VulnerabilityIncident ResponseCloud Security
Read More → Use Tool →
2026-07-10The Hacker News
Unpatched XRING Flaw in XQUIC Lets Attackers Crash HTTP/3 Servers

A critical unpatched vulnerability in XQUIC—Alibaba's open-source QUIC and HTTP/3 library—allows any remote client to crash servers with a tiny burst of legitimate traffic. Dubbed ...

Zero-DayVulnerabilityCloud Security
Read More → Use Tool →
2026-07-09The Hacker News
Dormant GitHub Accounts Weaponized for Corporate Reconnaissance via API Scraping

Datadog Security Labs is sounding the alarm over a coordinated series of campaigns that systematically enumerate corporate GitHub organizations, repositories, and user accounts thr...

Supply ChainThreat IntelCloud Security
Read More → Use Tool →
2026-07-08Dark Reading
Lone Attacker Uses AI to Breach AWS Environment in 72 Hours

A single threat actor has reportedly compromised an Amazon Web Services (AWS) environment belonging to a large enterprise customer in just 72 hours, leveraging AI-driven reconnaiss...

AI SecurityCloud SecurityData Breach
Read More → Use Tool →
2026-07-08The Hacker News
GhostLock Linux Kernel Flaw Grants Root Access on Most Distros

Nebula Security has disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel use-after-free vulnerability that lets any local user escalate to full root on unpatched system...

VulnerabilityCloud SecurityBug Bounty
Read More → Use Tool →
2026-07-07Dark Reading
Google Dialogflow CX Rogue Agent Flaw Exposed Chatbot Data

Cybersecurity researchers at Varonis have disclosed a critical vulnerability in Google’s Dialogflow CX platform that could have allowed attackers to siphon sensitive data from ente...

AI SecurityVulnerabilityCloud Security
Read More → Use Tool →
2026-07-06The Hacker News
Critical Gitea Docker Flaw CVE-2026-20896 Actively Exploited Within Days

Threat actors began probing a critical security flaw in Gitea Docker images just 13 days after public disclosure, according to cloud security firm Sysdig. Tracked as CVE-2026-20896...

VulnerabilityCloud SecurityAuthentication
Read More → Use Tool →
2026-07-01The Hacker News
Unpatched Argo CD Flaw Allows Full Kubernetes Cluster Takeover

Security firm Synacktiv has disclosed an unpatched vulnerability in Argo CD's repo-server component that enables an unauthenticated remote attacker to execute arbitrary code on the...

VulnerabilityCloud SecurityZero-Day
Read More → Use Tool →
2026-07-01The Hacker News
Microsoft Accelerates Post-Quantum Cryptography Migration to 2029

Microsoft has moved up its quantum-safe security roadmap, with Azure CTO Mark Russinovich announcing that the Microsoft Quantum Safe Program (QSP) will now target a full transition...

EncryptionRegulationCloud Security
Read More → Use Tool →
2026-07-01The Hacker News
Citrix Patches Six Critical NetScaler Flaws Enabling File Reads and DoS

Citrix has released security updates for six vulnerabilities in NetScaler ADC and NetScaler Gateway that could allow attackers to read arbitrary files or trigger denial-of-service ...

VulnerabilityCloud Security
Read More → Use Tool →
2026-07-01The Hacker News
Azure CLI Password Spray Compromises 78 Microsoft Accounts in 81M+ Attempts

Cybersecurity researchers at Huntress have uncovered a massive, ongoing automated password spray campaign targeting Microsoft's Azure command-line interface (CLI), generating more ...

Cloud SecurityAuthenticationThreat Intel
Read More → Use Tool →
2026-06-29The Hacker News
Gamaredon APT Expands Ukraine Attacks With New Malware Arsenal

The Russian advanced persistent threat group Gamaredon maintained an aggressive focus on Ukrainian governmental and military institutions throughout 2025, mounting 35 distinct spea...

APTMalwareCloud Security
Read More → Use Tool →
2026-06-26SecurityWeek
Philip Martin Named Uber CISO After Leading Security at Coinbase

Uber has appointed Philip Martin as its new Chief Information Security Officer (CISO), tapping a seasoned security leader with deep experience in incident response, threat intellig...

Incident ResponseCloud Security
Read More → Use Tool →
2026-06-25The Hacker News
Curl 24-Year-Old Bug, Hoppscotch RCE, Cloudflare PACT: Weekly Threats

This week's threat landscape blended privacy innovation with two decades of dormant risk. Cloudflare announced a partnership with Google Chrome, Microsoft Edge, and Mozilla Firefox...

VulnerabilityPrivacyCloud Security
Read More → Use Tool →
2026-06-24The Hacker News
Cordyceps Flaws Expose 300+ GitHub Repos to CI/CD Supply-Chain Attacks

Cybersecurity researchers at Novee Security have identified a critical class of CI/CD workflow misconfiguration dubbed "Cordyceps" that exposes more than 300 high-impact GitHub rep...

Supply ChainVulnerabilityCloud Security
Read More → Use Tool →
2026-06-24The Hacker News
DoJ Seizes Huione Cloud Account in Cyber Scam Laundering Crackdown

The U.S. Department of Justice announced on Tuesday the seizure of a cloud computing account operated by subsidiaries of Cambodia-based conglomerate HuiOne Group, a network accused...

RegulationCloud SecurityThreat Intel
Read More → Use Tool →
2026-06-22The Hacker News
DifyTap: Critical Flaws in Dify Expose AI Chats Across Tenants

Cybersecurity researchers at Zafran Security have disclosed four vulnerabilities in Dify, the open-source agentic workflow platform boasting more than 146,000 GitHub stars, that co...

VulnerabilityAI SecurityCloud Security
Read More → Use Tool →
2026-06-19The Hacker News
Shadow AI: Why Access Control, Not Data Leakage, Is the Real Enterprise Threat

The enterprise AI risk landscape has fundamentally shifted. Security teams initially focused on employees pasting sensitive data into public AI tools, responding with usage policie...

AI SecurityAI ThreatsCloud Security
Read More → Use Tool →
2026-06-18The Hacker News
F5 Patches Two Critical NGINX RCE Flaws: CVE-2026-42530 & CVE-2026-42055

F5 has released emergency security updates to address two critical vulnerabilities in NGINX Open Source, both carrying a CVSS v4 score of 9.2, that could allow remote unauthenticat...

VulnerabilityCloud Security
Read More → Use Tool →
2026-06-18The Hacker News
Orphaned AI Agents: Hidden Access Risks in Enterprise Networks

When an autonomous AI agent interacts with a company's core intellectual property, most security teams cannot instantly name the person who authorized it. The rush to deploy intern...

AI SecurityAuthenticationCloud Security
Read More → Use Tool →
2026-06-18The Hacker News
SearchJack Chrome Extensions Hit 758K Users as macOS ClickFix Spreads RAT

A cluster of 23 deceptive Chrome browser extensions has been uncovered routing user searches through monetization middleware before delivering results, exposing roughly 758,000 aff...

Threat IntelMalwarePhishingPrivacyCloud Security
Read More → Use Tool →
2026-06-18BleepingComputer
F5 Patches Critical NGINX Flaws Enabling Remote Code Execution

F5 has issued out-of-band security updates to remediate two critical-severity vulnerabilities in its NGINX web server software that could allow unauthenticated remote attackers to ...

VulnerabilityCloud SecurityAPT
Read More → Use Tool →
2026-06-16The Hacker News
Google Vertex AI SDK Bug Let Attackers Hijack AI Model Uploads

A critical vulnerability in Google Cloud's Vertex AI SDK for Python allowed attackers to hijack machine learning model uploads and execute arbitrary code inside Google's serving in...

Cloud SecurityVulnerabilityAI Security
Read More → Use Tool →
2026-06-15The Hacker News
China-Linked Hackers Abuse Google Workspace Rules to Steal Defense Emails

A China-linked espionage group tracked as UNC6508 maintained undetected access to North American medical, academic, and military research networks for over a year, quietly siphonin...

APTCloud SecurityThreat Intel
Read More → Use Tool →
2026-06-10The Hacker News
Ivanti, Fortinet, SAP Patch Critical RCE and Auth Bypass Flaws

Fortinet, Ivanti, and SAP have rolled out urgent security updates addressing multiple critical vulnerabilities that could enable arbitrary code execution, authentication bypass, an...

VulnerabilityAuthenticationCloud Security
Read More → Use Tool →
2026-06-10The Hacker News
Automated Pentest Blind Spots: What Your Security Report Is Missing

A clean penetration test report may look reassuring, but security leaders should read it as a warning sign, not a victory lap. According to Autumn Stambaugh and Can Yüceel of Picus...

VulnerabilityCloud SecurityThreat Intel
Read More → Use Tool →
2026-06-10The Hacker News
Proto6 Flaws in protobuf.js Expose Node.js Apps to RCE and DoS Attacks

Cybersecurity researchers at Cyera have disclosed six vulnerabilities in protobuf.js, a widely used JavaScript and TypeScript implementation of Google's Protocol Buffers serializat...

VulnerabilitySupply ChainCloud Security
Read More → Use Tool →
2026-06-09The Hacker News
Critical Veeam Backup RCE Flaw (CVE-2026-44963) Lets Domain Users Execute Code

Veeam has shipped an emergency patch for a critical remote code execution vulnerability in its widely deployed Backup & Replication platform. Tracked as CVE-2026-44963, the flaw ca...

VulnerabilityRansomwareCloud Security
Read More → Use Tool →
2026-06-09BleepingComputer
ServiceNow Data Breach Exposes Customer Instances via API Flaw

ServiceNow disclosed a security incident on June 9, 2026, revealing that attackers exploited an unauthenticated access flaw in a REST API endpoint to query data from hosted custome...

Data BreachVulnerabilityCloud Security
Read More → Use Tool →
2026-06-05The Hacker News
PCPJack Hijacks 230 Cloud Servers to Build Covert SMTP Relay Network

The threat actor tracked as PCPJack has compromised at least 230 cloud servers across Amazon Web Services (AWS), Google Cloud Platform, and Microsoft Azure, converting them into a ...

Cloud SecurityThreat IntelMalware
Read More → Use Tool →
2026-06-03The Hacker News
Autonomous AI Uncovers 2-Year-Old Redis RCE Flaw (CVE-2026-23479)

Redis has patched a use-after-free vulnerability in its blocking-client code that allows an authenticated user to execute arbitrary OS commands on the host running the database. Tr...

VulnerabilityCloud SecurityAI Security
Read More → Use Tool →
2026-06-03The Hacker News
IVIP: Closing the Identity Dark Matter Gap in Enterprise IAM

Enterprise identity and access management is approaching a structural breaking point. As organizations scale, identity data fragments across thousands of applications, decentralize...

AuthenticationAI SecurityCloud Security
Read More → Use Tool →
2026-06-03The Hacker News
HTTP/2 Bomb: New DoS Flaw Hits NGINX, Apache, IIS, Envoy & Cloudflare

Cybersecurity researchers at Calif have disclosed a new remote denial-of-service vulnerability dubbed "HTTP/2 Bomb" that affects five major web server platforms: NGINX, Apache HTTP...

VulnerabilityZero-DayCloud Security
Read More → Use Tool →
2026-06-02BleepingComputer
Microsoft Coreutils Brings Native Linux Commands to Windows at Build 2026

Microsoft announced at its Build 2026 developer conference the release of Coreutils for Windows, a package that delivers common Linux command-line utilities as native Windows appli...

Cloud SecuritySupply Chain
Read More → Use Tool →
2026-06-02BleepingComputer
Microsoft Exchange Online Outage Disrupts Email Delivery in North America and Germany

Microsoft is actively investigating a widespread service disruption affecting the mail flow pipeline for Exchange Online customers in North America and Germany. The incident, track...

Cloud SecurityIncident Response
Read More → Use Tool →
2026-06-01The Hacker News
MSPs Move Beyond vCISO to Security Growth Platforms in 2026

The managed service provider (MSP) cybersecurity landscape is undergoing a significant transformation as traditional vCISO platforms fail to meet the demands of modern security pra...

Cloud SecurityAI SecurityRegulation
Read More → Use Tool →
2026-05-29The Hacker News
LLM Agent Used in Post-Exploitation After Marimo CVE-2026-39987 Exploit

Sysdig researchers have documented a sophisticated cyberattack where threat actors deployed a large language model (LLM) agent to automate post-exploitation activities following th...

LLM SecurityVulnerabilityCloud Security
Read More → Use Tool →
2026-05-22The Record
FBI Warns of Kali365 Phishing Service Targeting Microsoft 365

The FBI has issued a critical advisory regarding Kali365, a Telegram-based Phishing-as-a-Service (PhaaS) platform that enables cybercriminals to compromise Microsoft 365 accounts b...

PhishingCloud SecurityAuthentication
Read More → Use Tool →
2026-05-21The Hacker News
Identity is the Attack Path: Cloud Security Risks in 2025

A threat actor recently obtained an AWS access key cached on a developer's workstation through standard browser behavior—no misconfiguration or policy violation required. This sing...

Cloud SecurityAuthenticationAI Security
Read More → Use Tool →
2026-05-21Dark Reading
Enterprises Boost AI Agent Identity Security Budgets as Omdia Reveals Shifting Priorities

Organizations are dramatically increasing investments in AI agent identity management as enterprise deployments accelerate, according to new research from Omdia. The study reveals ...

AI SecurityAuthenticationCloud Security
Read More → Use Tool →
2026-05-20The Hacker News
GitHub Breach: 3,800+ Repos Stolen via VS Code Extension Hack

GitHub has confirmed a significant security incident in which threat actor TeamPCP exfiltrated approximately 3,800 internal repositories after compromising an employee's device thr...

Data BreachSupply ChainCloud Security
Read More → Use Tool →
2026-05-16BleepingComputer
Microsoft Rejects Azure Backup AKS Vulnerability Report, Blocks CVE

Security researcher Justin O'Leary has disclosed a critical vulnerability in Microsoft Azure Backup for Azure Kubernetes Service (AKS) that allowed privilege escalation from a low-...

VulnerabilityCloud Security
Read More → Use Tool →
2026-05-08SecurityWeek
Braintrust Data Breach: AWS API Keys Leaked, Prompting Rotation

Braintrust, an AI infrastructure provider, disclosed on March 5 2026 that an unauthorized party had gained access to one of its Amazon Web Services (AWS) accounts. The intrusion, d...

Data BreachCloud SecurityAI Security
Read More → Use Tool →
2026-05-08SecurityWeek
PCPJack Worm Cleans TeamPCP, Steals AWS Cloud Credentials

Security researchers have identified a new self‑propagating threat, named PCPJack, that behaves like a worm while simultaneously purging systems infected by the earlier TeamPCP mal...

MalwareCloud SecurityAuthentication
Read More → Use Tool →
2026-05-08BleepingComputer
NVIDIA Confirms GeForce NOW Data Breach Affects Armenian Users

NVIDIA has officially confirmed a data breach impacting its GeForce NOW service, exposing personal information for a subset of users in Armenia. The disclosure, made in a statement...

Data BreachPrivacyCloud Security
Read More → Use Tool →
2026-05-07The Hacker News
PCPJack Credential Stealer Uses 5 CVEs to Spread Worm-Like in Cloud

Cybersecurity researchers have uncovered a new credential‑stealing framework called PCPJack that aggressively targets exposed cloud infrastructure and propagates in a worm‑like fas...

MalwareCloud SecurityVulnerability
Read More → Use Tool →
2026-05-07BleepingComputer
PCPJack Worm Targets Cloud Infrastructure, Removes TeamPCP Infections

Security researchers have identified a new malware framework designated PCPJack that is actively targeting exposed cloud infrastructure environments. The threat operates as a crede...

MalwareCloud Security
Read More → Use Tool →
2026-05-07Dark Reading
PCPJack Malware Exploits Parquet Files to Steal Cloud Secrets

Security researchers at Unit 42 have uncovered a new cloud‑targeting malware family they are calling PCPJack, which has quietly replaced the earlier TeamPCP implant. PCPJack distin...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2026-05-05The Hacker News
OAuth Token Exposure in AI Tools: Unclosed Backdoors Threaten Cloud Security

In the past twelve months, enterprises have rushed to embed AI‑powered writing assistants, workflow automations and productivity plugins into their Google Workspace and Microsoft 3...

VulnerabilityCloud SecurityAI Security
Read More → Use Tool →
2026-05-04BleepingComputer
Kaspersky: Amazon SES Phishing Evades Email Security

Kaspersky researchers identified a surge in phishing campaigns leveraging Amazon Simple Email Service (SES). Attackers abuse the trusted infrastructure by sending emails via verifi...

PhishingCloud SecurityThreat Intel
Read More → Use Tool →
2026-05-04BleepingComputer
Malicious PyTorch Lightning Package Steals AWS and Browser Credentials

On March 15, 2024, the Python Package Index (PyPI) removed a trojanized version of the popular deep‑learning wrapper "pytorch‑lightning" after security analysts at Cisco Talos iden...

MalwareSupply ChainCloud Security
Read More → Use Tool →
2026-05-04BleepingComputer
Amazon SES Phishing Surge: Evading Standard Security Filters

Amazon Simple Email Service (SES), the cloud‑based email sending platform offered by Amazon Web Services, is increasingly being weaponized by threat actors to distribute phishing e...

PhishingCloud SecurityThreat Intel
Read More → Use Tool →
2026-05-04BleepingComputer
MSPs: Strengthen Security & Backup with SaaS BCDR

Kaseya announced a live webinar titled “Why MSPs must rethink security and backup strategies” scheduled for June 15, 2026 at 2:00 PM ET. The session, hosted by Kaseya’s Product Mar...

Cloud SecurityIncident ResponseRansomware
Read More → Use Tool →
2026-05-03The Hacker News
CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-31431, a critical Linux kernel privilege escalation vulnerability, to its Known Exploited Vulner...

VulnerabilityZero-DayCloud Security
Read More → Use Tool →
2026-05-02BleepingComputer
ConsentFix v3: Automated OAuth Abuse Targets Azure

Security researchers have flagged a new iteration of the consent‑phishing tool known as ConsentFix, now labeled v3, which dramatically expands the scale and automation of attacks a...

Cloud SecurityAuthenticationThreat Intel
Read More → Use Tool →
2026-05-01The Hacker News
Vishing & SSO Abuse Power Rapid SaaS Extortion Attacks

Cybersecurity researchers have identified two distinct cybercrime groups orchestrating rapid, high‑impact extortion campaigns that operate almost entirely within Software‑as‑a‑Serv...

PhishingCloud SecurityThreat Intel
Read More → Use Tool →
2026-05-01The Hacker News
Top 5 Sales Challenges Costing MSPs Cybersecurity Revenue

Managed security services are on a steep ascent, with the market expected to swell from $38.31 billion in 2025 to $69.16 billion by 2030, making cybersecurity the fastest‑growing s...

Cloud SecurityThreat Intel
Read More → Use Tool →
2026-04-30The Hacker News
DEEP#DOOR Python Backdoor Steals Browser and Cloud Credentials

Security researchers at SentinelOne and WithSecure have uncovered a sophisticated Python-based backdoor named DEEP#DOOR that leverages legitimate tunneling services to establish co...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2026-04-30Dark Reading
Oracle Red Bull Racing Powers Security with Automation

Oracle Red Bull Racing has launched a sweeping automation initiative aimed at embedding security directly into the team’s high‑velocity development pipelines. With the pit wall and...

Cloud SecurityIncident ResponseVulnerability
Read More → Use Tool →
2026-04-29The Hacker News
Exposure Management Platforms: Key Features and Common Pitfalls

Security teams across industries are increasingly discovering that traditional vulnerability management approaches fail to accurately represent organizational risk. Despite closing...

VulnerabilityThreat IntelCloud Security
Read More → Use Tool →
2026-04-28The Hacker News
Secure Data Movement: The Zero Trust Bottleneck You're Ignoring

In the rush to hybrid cloud adoption, many organizations treat data movement as a simple connectivity chore. Open a ticket, spin up an SFTP gateway, push the data across, and consi...

Data BreachCloud SecurityVulnerability
Read More → Use Tool →
2026-04-28The Hacker News
Microsoft Patches Entra ID Role Flaw Enabling Service Principal Takeover

Silverfort’s identity threat research team disclosed a critical misconfiguration in a Microsoft Entra ID administrative role designed for AI agents. The role, named “AI Service Adm...

VulnerabilityCloud Security
Read More → Use Tool →
2026-04-27Dark Reading
UNC6692 APT Deploys Snow Malware via Microsoft Teams, AWS S3

Cybersecurity researchers have identified a sophisticated campaign conducted by the threat actor UNC6692, who is combining social engineering, custom malware, and cloud infrastruct...

APTMalwareCloud Security
Read More → Use Tool →
2026-04-24Dark Reading
Glasswing Secures Code, But Your Stack Still Exposed

Glasswing’s recent announcement that it has secured the core code of its platform is a welcome step toward reducing software vulnerabilities, but security experts warn that the bro...

Supply ChainAI SecurityCloud Security
Read More → Use Tool →
2026-04-24Dark Reading
Chinese APT Exploits Outlook, Slack, Discord & file.io to Spy on Mongolia

Security researchers at Secureworks’ Counter Threat Unit (CTU) have uncovered a sophisticated espionage operation conducted by a Chinese state‑sponsored APT that targeted Mongolian...

APTCloud SecurityMalware
Read More → Use Tool →
2026-04-23Dark Reading
Zealot AI Attack Exposes Cloud Security Risks

In a live demonstration at the Dark Reading CyberStorm conference, researchers from Sentinel Labs unveiled 'Zealot', a proof‑of‑concept AI framework designed to autonomously compro...

AI ThreatsCloud Security
Read More → Use Tool →
2026-03-23KrebsOnSecurity
CanisterWorm Worm Targets Iran via Cloud Services, Wipes Data

Security researchers at SecureSphere Labs have uncovered a new file‑wiping worm they have named CanisterWorm, attributed to a financially motivated threat actor tracked under the a...

MalwareCloud SecurityThreat Intel
Read More → Use Tool →
2025-09-02Ars Technica
Google Denies Major Gmail Breach Affecting 2.5 Billion Users

Google has publicly pushed back against viral claims circulating online that all 2.5 billion Gmail accounts have been compromised in a sweeping security incident. The rumors, which...

Data BreachAuthenticationCloud Security
Read More → Use Tool →