Tag: cloud
-
Tigera Introduces Calico Cloud Free Tier to Boost Kubernetes Observability and Security
First seen on scworld.com Jump to article: www.scworld.com/news/tigera-introduces-calico-cloud-free-tier-to-boost-kubernetes-observability-and-security
-
Operant AI Launches Open-Source Red Teaming Tool for AI and Cloud Security
First seen on scworld.com Jump to article: www.scworld.com/brief/operant-ai-launches-open-source-red-teaming-tool-for-ai-and-cloud-security
-
Russian Hackers Exploit Oracle Cloud Infrastructure to Target Scaleway Object Storage
Russian threat actors have been leveraging trusted cloud infrastructure platforms like Oracle Cloud Infrastructure (OCI) Object Storage and Scaleway Object Storage to propagate sophisticated attacks using the Lumma Stealer malware. This malware-as-a-service (MaaS) infostealer, also known as LummaC2 Stealer, targets Windows systems to siphon credentials, system data, and cryptocurrency wallets. Investigations conducted in 2025 reveal…
-
How Identity Plays a Part in 5 Stages of a Cyber Attack
Tags: access, attack, authentication, breach, cloud, computer, container, control, credentials, cyber, data, data-breach, detection, endpoint, exploit, group, iam, identity, intelligence, malicious, malware, mfa, microsoft, monitoring, password, powershell, ransomware, risk, technology, threat, tool, vulnerabilityWhile credential abuse is a primary initial access vector, identity compromise plays a key role in most stages of a cyber attack. Here’s what you need to know, and how Tenable can help. Identity compromise plays a pivotal role in how attackers move laterally through an organization. Credential abuse is the top initial access vector,…
-
Database Leak Reveals 184 Million Infostealer-Harvested Emails and Passwords
Cybersecurity researcher Jeremiah Fowler discovered a misconfigured cloud server containing a massive 184 million login credentials, likely collected… First seen on hackread.com Jump to article: hackread.com/database-leak-184-million-infostealer-emails-passwords/
-
Cisco Webex Meetings Vulnerability Enables HTTP Response Manipulation
Security researchers have uncovered a vulnerability in Cisco Webex Meetings that could allow remote attackers to manipulate HTTP responses without authentication. The cloud-based vulnerability affects the client join services component of the popular videoconferencing platform. Cisco has already addressed the issue, with no user action required for remediation. The vulnerability, reported by security researcher Matthew…
-
Dell creates one private cloud to rule them all and in the datacenter bind them
Mix Master Mike will spin up Nutanix, VMware, Red Hat on the same beastly cluster First seen on theregister.com Jump to article: www.theregister.com/2025/05/20/dell_private_cloud/
-
Secunet: BSI gibt Sina-Cloud für Verschlusssachen frei
Der Sina Cloud Security Layer ist die erste Technologie, die das Komponentenzulassungsverfahren des BSI erfolgreich durchlaufen hat. First seen on golem.de Jump to article: www.golem.de/news/secunet-bsi-gibt-sina-cloud-fuer-verschlusssachen-frei-2505-196469.html
-
SHARED INTEL QA: Visibility, not volume, reframing detection for the AI-enabled SOC
For years, network security has revolved around the perimeter: firewalls, antivirus, endpoint controls. But as attackers grow more sophisticated, and as operations scatter to the cloud, mobile, and IoT, it’s increasingly what happens inside the network that counts.”¦ (more”¦) First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/05/shared-intel-qa-visibility-not-volume-reframing-detection-for-the-ai-enabled-soc/
-
Are Your Security Spendings Justified and Effective?
Tags: cloudAre We Maximizing Our Security Investments? Organizations must justify their security spend and ensure the effective use of their budget. With growing reliance on the cloud and increased utilization of Non-Human Identities (NHIs), the question arises: are we truly getting the most out of our security measures? Exploring the Nuances of Non-Human Identities NHIs, a……
-
»manage it« TechTalk: Darum sind sichere Cloud-Umgebungen wichtig
Tags: cloudWarum ist eine sichere Cloud immanent wichtig? Die Antwort auf diese Frage wollten wir uns während der Hannover Messe 2025 von Cassian Ewert vom Sicherheitsanbieter Claroty beantworten lassen. Was er dann auch in 2 Minuten getan hat. First seen on ap-verlag.de Jump to article: ap-verlag.de/manage-it-techtalk-darum-sind-sichere-cloud-umgebungen-wichtig/95993/
-
Scammers Troll DNS Records for Abandoned Cloud Accounts
‘Hazy Hawk’ Behind a Rash of Domain Hijackings. A hacking group with apparent access to a commercial domain name system archiving service is on the hunt for misconfigured records of high-reputation organizations in order to blast links to scammy domains. It checks the CNAME field of DNS records to see if it points to an…
-
Misconfigured DNS, neglected cloud assets harnessed in Hazy Hawk domain hijacking attacks
First seen on scworld.com Jump to article: www.scworld.com/brief/misconfigured-dns-neglected-cloud-assets-harnessed-in-hazy-hawk-domain-hijacking-attacks
-
Attacks leveraging Ivanti EPMM flaws in clouds underway
First seen on scworld.com Jump to article: www.scworld.com/brief/attacks-leveraging-ivanti-epmm-flaws-in-clouds-underway
-
Google Cloud Marketplace Introduces New Revenue Models and Incentives to Boost Partner Growth
First seen on scworld.com Jump to article: www.scworld.com/news/google-cloud-marketplace-introduces-new-revenue-models-and-incentives-to-boost-partner-growth
-
Hybrid-Cloud: KI zwingt deutsche Unternehmen Abstriche bei der Sicherheit zu machen
First seen on datensicherheit.de Jump to article: www.datensicherheit.de/hybrid-cloud-ki-sicherheit-studie-2025
-
Flaw in Google Cloud Functions Sparks Broader Security Concerns
Patched privilege escalation flaw in Google Cloud Platform linked to wider cloud security concerns First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/flaw-google-cloud-security-concerns/
-
Cybercriminals Could Leverage Google Cloud Platform for Malicious Activities
A Research by Tenable and Cisco Talos has shed light on a critical vulnerability in Google Cloud Platform’s (GCP) Cloud Functions and Cloud Build services, revealing a potential attack vector for cybercriminals. According to Tenable, the default Cloud Build Service Account (SA) previously granted excessive permissions during the deployment of Cloud Functions, a serverless compute…
-
Hazy Hawk Targets DNS Vulnerabilities to Hijack Cloud Resources and Spread Malware
The threat actor gained attention in February 2025 after successfully hijacking a subdomain of the U.S. Centers for Disease Control and Prevention (CDC). Sophisticated threat actor dubbed >>Hazy Hawk
-
Critical VMware ESXi vCenter Flaw Allows Remote Execution of Arbitrary Commands
VMware by Broadcom has released critical security updates to address multiple severe vulnerabilities affecting its virtualization products, with evidence suggesting active exploitation in the wild. The vulnerabilities, tracked as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, affect VMware ESXi, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform products. With CVSS scores ranging from 7.1 to 9.3, these flaws…
-
Threat intelligence platform buyer’s guide: Top vendors, selection advice
Tags: ai, attack, automation, breach, cloud, computing, credentials, crowdstrike, cyber, cybersecurity, dark-web, data, data-breach, deep-fake, detection, dns, edr, email, endpoint, exploit, finance, firewall, fraud, gartner, google, group, guide, identity, incident response, infrastructure, intelligence, kubernetes, law, malicious, malware, microsoft, mitigation, monitoring, network, open-source, phishing, privacy, risk, service, siem, soar, soc, sophos, sql, supply-chain, technology, threat, tool, vpn, vulnerability, zero-dayThe Cybersecurity and Infrastructure Security Agency (CISA) found that since 2023 the majority of exploits were zero days, meaning exploiting heretofore unknown methods. And according to the latest Verizon Data Breach Investigations report (DBIR), the percentage of AI-assisted malicious emails doubled to 10% of the totals they observed over the past two years, making staying…
-
Poor DNS hygiene is leading to domain hijacking
Tags: attack, authentication, ciso, cloud, control, credentials, detection, dns, email, exploit, incident response, intelligence, threat, toolDNS hijacking comes in many forms: DNS hijacking comes in many forms. In 2019, CSO inteviewed Paul Vixie, a DNS system contributor, about the need to strengthen security. We later wrote about the problem of abandoned domain names. And things haven’t changed a lot since then. Most CISOs may be familiar with typosquatting, where “firm.com”…
-
Falsche Verarbeitung übergroßer Anfragen – Gefährliche Sicherheitslücke in der Google Cloud Platform
First seen on security-insider.de Jump to article: www.security-insider.de/sicherheitsluecke-google-cloud-schadcode-einschleusung-a-29bcaa4f0619aa77620fb7700e11c652/
-
Attack Surface Reduction for Enterprises: A Guide
Today’s enterprises have embraced digital evolution. Business deals are conducted in online spaces, contracts are signed with a keyboard, data is held in physical servers and the cloud, and client… First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/05/attack-surface-reduction-for-enterprises-a-guide/
-
Poor DNS hygiene is leading to domain hijacking: Report
Tags: attack, authentication, ciso, cloud, control, credentials, detection, dns, email, exploit, incident response, intelligence, threat, toolDNS hijacking comes in many forms: DNS hijacking comes in many forms. In 2019, CSO inteviewed Paul Vixie, a DNS system contributor, about the need to strengthen security. We later wrote about the problem of abandoned domain names. And things haven’t changed a lot since then. Most CISOs may be familiar with typosquatting, where “firm.com”…
-
‘Ongoing’ Ivanti hijack bug exploitation reaches clouds
Nothing like insecure code in security suites First seen on theregister.com Jump to article: www.theregister.com/2025/05/21/ivanti_rce_attacks_ongoing/
-
European customers report Oracle Cloud identity outage, Big Red is silent
DownDetector reported problems for about 6 hours First seen on theregister.com Jump to article: www.theregister.com/2025/05/19/oci_outage_europe/
-
Free to Choose the Right Security for Your Cloud
Is Choosing Cloud Security a Complex Task? From financial services and healthcare to DevOps and SOC teams, businesses across sectors are grappling with the complexity of managing Non-Human Identities (NHIs). NHIs, essentially machine identities, are a critical component of an organization’s cybersecurity. They play a pivotal role in reducing threats by securing both the machine……
-
Orca snaps up Opus to advance automated cloud security
Tags: cloudFirst seen on scworld.com Jump to article: www.scworld.com/brief/orca-snaps-up-opus-to-advance-automated-cloud-security

