Tag: cloud
-
Keepit AI Truth Cloud: Verifizierte Backup-Daten sollen Enterprise-KI absichern
Keepit stellt AI Truth Cloud vor: Unveränderliche Backup-Daten, MCP-Integration und AI Safe Room sollen eine vertrauenswürdige Basis für Enterprise-KI schaffen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/keepit-ai-truth-cloud-verifizierte-backup-daten-sollen-enterprise-ki-absichern/a46059/
-
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own…
-
Imperva Customers Protected Against Novel HTTP Desync Attacks
TL;DR: Recent Portswigger research introduced novel HTTP desync techniques discovered through an AI-assisted research system called the HTTP Terminator. The findings expand the range of unusual HTTP behaviors that can cause front-end and back-end systems to interpret the same traffic differently. Imperva Cloud WAF and On-Prem WAF customers are protected against practical attack patterns described in the research. Imperva’s existing security engine already blocked malicious……
-
How AI Agents Widen the Enterprise Blast Radius
AWS’s Matt Girdharry and Varonis’ Matt Radolec on Data Security, Machine-Speed Risk. Agentic AI can act at machine speed across data, APIs and cloud services, expanding enterprise risk beyond traditional controls. AWS’ Matt Girdharry and Varonis’ Matt Radolec explain why AI governance, least privilege and runtime visibility now matter more than ever for security teams.…
-
Cogent Launches VR-1 Cyber Reasoning Model for Enterprise Attack Paths
Cogent Security has introduced Cogent VR-1, a frontier reasoning model trained to investigate enterprise environments and prove whether multi-step attack paths are reachable. The model starts with a foothold and an objective, then maps the surrounding environment and connects weaknesses across systems. Cogent said VR-1 can work across cloud infrastructure, identity systems and internal tools,..…
-
Deemed Export, Deemed Impossible: The Government Discovers That AI Has No Border
Anthropic’s reported AI model shutdown highlights how U.S. export controls could collide with frontier AI, cybersecurity, identity management and global cloud access. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/deemed-export-deemed-impossible-the-government-discovers-that-ai-has-no-border/
-
NSFOCUS LAS: Comprehensive Log Management for Security Visibility and Compliance
The Log Management Challenge Most enterprises accumulate log sources the same way they accumulate infrastructure: one device at a time, each generating data in its own proprietary format. The result is logs scattered across security appliances, network devices, servers, databases, middleware, applications, and cloud workloads, with no unified view and unknown device status. Any issue……
-
Souveräne IT-Infrastruktur – Schwarz Digits und Zscaler launchen Cloud-Sicherheitsplattform
First seen on security-insider.de Jump to article: www.security-insider.de/schwarz-digits-und-zscaler-launchen-cloud-sicherheitsplattform-a-8f53b0cfa3d11dc9be8d034d94b92987/
-
Zero-Touch Provisioning wird zum Einfallstor: 15 Schwachstellen in TP-Link Omada
Forescout entdeckt 15 Schwachstellen in TP-Link Omada. Angriffsketten über Zero-Touch Provisioning können Controller, Cloud-Dienste und Netzwerkgeräte gefährden. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/zero-touch-provisioning-wird-zum-einfallstor-15-schwachstellen-in-tp-link-omada/a46047/
-
MSSPs should not inherit cloud migration debt
First seen on scworld.com Jump to article: www.scworld.com/perspective/mssps-should-not-inherit-cloud-migration-debt
-
Top 10 Best External Attack Surface Management (EASM) Platforms 2026
In the sprawling digital ecosystem of 2026, organizations grapple with an increasingly complex and often poorly understood external attack surface. This attack surface encompasses all internet-facing assets that are discoverable and potentially exploitable by malicious actors. These assets extend far beyond traditional network perimeters to include cloud resources, web applications, APIs, orphaned infrastructure, exposed databases,…
-
FedRAMP 20x Class A Is Now Open: What It Means for Cloud Providers and Federal Cybersecurity
The federal cloud compliance landscape has reached another significant milestone. As of August 3, 2026, the FedRAMP 20x Class A submission pipeline is officially open, marking the first widely available entry point into the new FedRAMP 20x certification model. This isn’t simply a process update”, it’s a fundamental shift toward a faster, more automated, and…
-
Canadian Pleads Guilty to Snowflake Customer Data Extortion
Extortionist Connor Moucka, 26, Helped Breach Over 150 Customers’ Accounts. Canadian national Connor Riley Moucka, 26, pleaded guilty in Seattle federal court holding to ransom data he helped steal from over 150 customers of cloud-based data warehousing platform Snowflake, leading to victims paying millions in cryptocurrency ransoms and incident response costs. First seen on govinfosecurity.com…
-
Snowflake hacker pleads guilty, faces up to 32 years in prison
A Canadian man is facing decades in prison for hacking customer accounts at cloud storage provider Snowflake and stealing data from more than 165 organizations. Connor Riley … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/snowflake-canadian-hacker-pleaded-guilty/
-
Canadian Hacker Pleads Guilty to Stealing Billions of Records From 165 Cloud Customers
Connor Riley Moucka, a 26-year-old Canadian national from Kitchener, Ontario, has pleaded guilty to charges related to a large-scale cloud data theft and extortion operation that affected at least 165 organizations. This campaign resulted in the theft of billions of sensitive records, impacting an estimated 100 million individuals worldwide. Canadian Hacker Pleads Guilty According to…
-
Hackers Abuse Cloud Startup Credits to Resell Claude and Gemini AI Access
Threat actors are exploiting free cloud trials and startup credit programs to build gray-market AI proxy services. These services resell discounted access to advanced AI models, including Anthropic Claude and Google Gemini, according to Okta Threat Intelligence. These services rely on fraudulent or synthetic account registrations to accumulate promotional credits offered by cloud providers. The…
-
Cloud Security Alliance Starts Initiative to Define Controls for Catastrophic AI Risks
The Cloud Security Alliance has launched an initiative to define auditable controls for catastrophic AI risks, along with a research center focused on how frontier AI is changing cybersecurity. Announced Wednesday in Las Vegas, the Catastrophic Risk Annex will extend CSA’s AI Controls Matrix with controls for mitigating catastrophic AI risks. CSA said the controls..…
-
Surf AI Adds Claude Compliance Integration and Exposure Reduction Operations
Surf AI has added an integration with Claude’s Compliance API and made Exposure Reduction Operations generally available, extending its platform to govern AI model connectivity alongside identity, cloud and SaaS exposures. The Claude integration pulls activity logs from an organization’s Claude environment, maps connection and access paths to an accountable owner in Surf’s Context Graph,..…
-
Suppliers, logins, and AI tools are all becoming attack paths
Cybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while avoiding detection, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/crowdstrike-cyber-threat-trends-report/
-
Hybridansatz für umfassendere Schwachstellenerkennung: Checkmarx stellt Checkmarx Fusion vor
Neue Architektur kombiniert bewährte AppSec-Scan-Engines mit KI-gestützter Analyse und ermöglicht eine präzisere Schwachstellenerkennung über den gesamten Softwareentwicklungszyklus hinweg. Checkmarx, Anbieter für autonome, Cloud-native Anwendungssicherheit, stellt mit Checkmarx Fusion einen neuen hybriden Scan-Ansatz vor, der ab sofort im Rahmen eines Early-Access-Programms für Kunden verfügbar ist. Checkmarx Fusion kombiniert die bewährten AppSec-Scan-Engines und den proprietären Sicherheitskontext… First…
-
Flooding Dropper Hits npm With 850 Malicious Packages
Tags: attack, automation, cloud, container, control, credentials, cvss, data-breach, detection, dns, endpoint, github, guide, infrastructure, linux, macOS, malicious, malware, monitoring, software, threat, windows<div cla TL;DR Sonatype Research Labs is tracking an active malicious package campaign, dubbed ‘Flooding Dropper,’ spreading on npm, currently impacting 846 software components. The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases…
-
Canadian pleads guilty to Snowflake cloud data-theft attacks
A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks/
-
Canadian man pleads guilty to Snowflake hacks that led to 165 breaches
A 26-year-old from Ontario faces as many as 32 years in prison after pleading guilty to fraud, identity theft and conspiracy charges related to the 2024 hacks of cloud platform Snowflake. First seen on therecord.media Jump to article: therecord.media/guilty-plea-snowflake-hack-connor-riley-moucka
-
Mini Shai-Hulud npm Attack: More Than 2,200 Components Impacted
Tags: access, ai, attack, breach, cloud, container, control, credentials, data, data-breach, github, guide, infection, intelligence, kubernetes, malicious, malware, microsoft, open-source, risk, sbom, service, software, threat, update<div cla TL;DR A new wave of the Shai-Hulud malicious package campaign emerged on npm, with 2,225 software component versions impacted. The malware executes through a malicious preinstall hook, steals npm, GitHub, cloud, Kubernetes, Vault, CI/CD, and other credentials, then uses stolen publishing access to compromise additional packages. Organizations that installed an affected version should…
-
7AI Launches Federated SIEM and Build Tools Ahead of Black Hat USA 2026
7AI has launched 7AI Federated SIEM and 7AI Build, two capabilities designed to give security teams a distributed foundation for AI-assisted operations. The company said both will be showcased at Black Hat USA 2026. 7AI Federated SIEM connects to security data across existing SIEMs, data lakes and cloud platforms. It lets teams query, investigate and..…
-
XM Cyber Releases Open-Source Tools for Hunting macOS and Oracle Cloud Exposures
XM Cyber has announced new open-source exposure-hunting tools for macOS endpoints and Oracle Cloud Infrastructure. The release, issued from Black Hat USA and DEF CON, says the tools are intended to help security teams uncover and validate complex attack paths. The macOS tool examines weaknesses that can allow an attacker to move from an initial..…
-
Beacon CRM, Widely Used by Charities, Suffers Data Breach
English National Ballet is Among the Confirmed Victims Notifying Supporters. Cloud-based customer relationship management software provider Beacon CRM said it’s suffered a security breach that likely led to the theft of customer data. Over 1,000 charities use the software, and English National Ballet and the Centre for Sustainable Energy report they’ve been affected. First seen…
-
CrowdStrike Warns AI Adoption Is Creating ‘Underdefended’ Attack Surfaces
CrowdStrike warns that AI adoption, rapid vulnerability exploitation, cloud attacks, and malicious npm packages are creating new enterprise security risks. The post CrowdStrike Warns AI Adoption Is Creating ‘Underdefended’ Attack Surfaces appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-crowdstrike-ai-underdefended-attack-surfaces/

