cloud-security
268 articles with this tag
INFO
HIGH
LOW
CRITICAL
INFO
INFO
INFO
HIGH
CRITICAL
INFO
HIGH
CRITICAL
INFO
INFO
HIGH
INFO
MEDIUM
INFO
HIGH
INFO
INFO
INFO
CRITICAL
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
INFO
HIGH
LOW
INFO
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
INFO
HIGH
INFO
INFO
INFO
MEDIUM
HIGH
INFO
HIGH
CRITICAL
INFO
LOW
HIGH
INFO
INFO
INFO
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
INFO
MEDIUM
INFO
INFO
INFO
HIGH
MEDIUM
INFO
INFO
INFO
INFO
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
MEDIUM
LOW
HIGH
HIGH
INFO
INFO
INFO
CRITICAL
HIGH
INFO
INFO
HIGH
CRITICAL
HIGH
INFO
HIGH
HIGH
HIGH
INFO
HIGH
CRITICAL
INFO
Introducing automatic remediation policies with Cloudflare CASB
IDScan confirms breach after 153 million driver’s licenses leak on dark web
[NEU] [niedrig] Palo Alto Networks Checkov by Prisma Cloud: Mehrere Schwachstellen ermöglichen Codeausführung
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key
Akeyless adds real-time enforcement for AI agents in production
CrowdStrike Named Strongest Overall Leader in 2026 Frost Radar™: Cloud Workload Protection Platforms
Threat Matrix: Mapping threats across cloud web applications
Passkey-themed social engineering leads to identity and cloud compromise
[NEU] [hoch] Microsoft Azure, Entra und Azure CLI : Mehrere Schwachstellen
What CISOs need to know about Confidential Computing in 2026
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
[NEU] [hoch] rclone: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen
Upwind Security raises $300 million in Series C funding
Getting Agents to tell on themselves
[NEU] [hoch] Microsoft Clouddienste: Mehrere Schwachstellen
Managing identity source transition for AWS IAM Identity Center
Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
Why I Keep Private Files Off the Cloud
FBI raises alarm over deceptive phishing campaign targeting prominent people
What Cloud Control Architecture Means for Executive Risk
Risk Advisory: Cloud Logging Is Not the Same as Incident Readiness
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
[NEU] [hoch] ServiceNow Now Platform und AI Platform: Mehrere Schwachstellen
NCSC-2026-0332 [1.00] [M/H] Kwetsbaarheden verholpen in Apache CloudStack
Snowflake ends service-account passwords. Now comes the hard part
Researchers Uncover Thousands of Leaked AWS Keys
Hundreds of leaked AWS keys give full control over corporate accounts
[NEU] [mittel] VMware Tanzu Spring Cloud: Mehrere Schwachstellen
[NEU] [hoch] Microsoft Azure, Entra ID und Exchange: Mehrere Schwachstellen
Vercel offers $1 million in bounties for sandbox hacks
N-able Bug Exposes Password Vault Master Keys
AWS limits AI agents’ data access, even when manipulated
Control Plane Gaps Create Invisible Cloud Risk
Heights Finance data breach: What customers need to know
Over 1,000 Charities Hit by Beacon CRM Data Breach
RHSA-2026:54757: Important: Red Hat OpenStack Platform 16.2 security advisory
Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charities
AWS key exposed in JavaScript may have lit way to Beacon's charity data
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
Qualys Introduces Real-Time Cloud Security Posture Management (CSPM) for Faster Risk Detection and Remediation
I Found an MFA-Bypassing Phishing Attack on Microsoft 365
CBTS brings continuous penetration testing to enterprise security
2026 AWS CyberVadis report now available for due diligence on third-party suppliers
Attack Surface Management - Matt Lea - CSP #227
Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS
tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
Securing your Amazon S3 buckets: Identifying and remediating over-permissioned access
Vishing Extortion Group UNC6671 Rebrands After Making Millions
[NEU] [hoch] Microsoft Azure: Mehrere Schwachstellen
Caching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scale
Salesforce's Agentforce 360 platform approved for sensitive Defense Department data
How a software provider closed unknown paths to cloud compromise
Non-human identities are 91% of everything active in production
Cloudflare OS goes open source with a record of everything its agents read
Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today’s Most Sophisticated Threats
AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
Cloud and SaaS Environments Now Top Targets for Attackers
Amgen reports data breach impacting patient and corporate information
VU#243636: VPS.org one-click deployment templates contain multiple vulnerabilities
Microsoft almost gave away the keys to everyone’s Azure Cosmos DBs
CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability
Okta to Acquire Identity Threat Detection Firm Permiso
[NEU] [mittel] Red Hat OpenStack (Neutron): Schwachstelle ermöglicht Manipulation von Daten und Umgehen von Sicherheitsvorkehrungen
Zscaler and Schwarz Digits partner for sovereign cloud security in Europe
FortiGate 1200G brings FortiSASE Outpost to customer-controlled environments
Qualys Expands Serverless Security with Vulnerability Scanning for AWS Lambda
The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches
What the identity attack surface looks like when trust becomes the target
Cloud resilience model invalidated by systemic threats
The Cloud Shared Responsibility Model — Operationalized
How to Evaluate Cloud Detection, Response, and Resilience Platforms
How to Evaluate CNAPP and Cloud Security Control Planes
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
OVH reveals semi-secret plan to fix critical Januscape bug with mass reboots – and an Australian crash-test dummy
Malicious cloud customers can bring down the power grid
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
The Risk of Exposed Cloud Functions and How to Harden
Radware adds cloud intelligence to DefensePro X for web DDoS defense
[NEU] [mittel] Red Hat OpenShift (OpenStack Services): Mehrere Schwachstellen ermöglichen Offenlegung von Informationen
[NEU] [hoch] Microsoft Azure: Mehrere Schwachstellen
Why Cloud Detection Fails When Teams Cannot Reconstruct Control-Plane Activity
How to Build a Cloud, SaaS and AI Data Governance Program
Security Hub adds AI workload protection and multicloud support for Microsoft Azure
Google Cloud Dialogflow CX vulnerability allowed AI agent hijacking
Cybercriminals exploit OAuth client ID spoofing to bypass cloud security
Now, defenders are embracing the prompt injection, too
Why cloud security is mission-critical for federal civilian and defense agencies
Novel OAuth Client ID Spoofing Technique Targets Cloud Environments
[NEU] [hoch] Google Cloud Platform (BigQuery, Dataform, Colab Enterprise): Schwachstelle ermöglicht Privilegieneskalation
CISA Details Incident Response to Exposed AWS GovCloud Keys
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
Multiples vulnérabilités dans Microsoft Azure Linux (09 juillet 2026)
AI Gateways Offer Attackers the Keys to the Kingdom
Threat Actors Uses Agentic AI to Rapidly Compromise Cloud Target
Enforce zero data retention on Amazon Bedrock with Bedrock Projects and service control policies
CAI cloud worm gives competitors' malware the boot, then steals secrets and mines for coin
Critical Gitea Flaw Under Active Exploitation, Researchers Warn
Dawnguard launches platform to automate secure cloud architecture