Tag: cloud
-
ExfilSquad Targets New Victims, Shares Data via Torrents
ExfilSquad targets 13 organizations, exploiting cloud portals for data theft and using torrents to spread stolen information and amplify damage. Resecurity is tracking the activity of ExfilSquad the group announced new victims this week. ExfilSquad is a new cybercrime group that emerged in mid-2026. Instead of using ransomware, it steals data and threatens to […]…
-
LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Target
Tags: ai, attack, breach, cloud, credentials, cyber, infrastructure, malicious, pypi, software, supply-chain, theftThe March 2026 compromise of LiteLLM was more than a short-lived malicious PyPI upload. It demonstrated how an upstream breach in developer tooling can turn AI infrastructure into a high-value conduit for credential theft, cloud intrusion, and downstream software supply chain abuse. The packages were available for roughly 40 minutes before quarantine, but their brief…
-
Acht Minuten bis zur Cloud-Kompromittierung: Wie IAM-Schlüssel und KI Angriffe beschleunigen
Cloud-Angriffe in weniger als zehn Minuten: Wie kompromittierte IAM-Schlüssel, Fehlkonfigurationen und KI das Tempo von Cloud-Attacken erhöhen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/acht-minuten-bis-zur-cloud-kompromittierung-wie-iam-schluessel-und-ki-angriffe-beschleunigen/a46107/
-
Cloud- und Netzwerkprobleme: Verbindungsfehler kosten mehr als einen Arbeitstag pro Woche
Viele IT-Entscheider halten ihre Netzwerke für Cloud- und KI-Dienste geeignet. Dennoch muss viel Zeit in die Fehlerbehebung investiert werden. First seen on golem.de Jump to article: www.golem.de/news/cloud-und-netzwerkprobleme-verbindungsfehler-kosten-mehr-als-einen-arbeitstag-pro-woche-2608-211777.html
-
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Tags: attack, authentication, cloud, cryptography, data-breach, malware, mfa, passkey, password, phishing, windowsThree separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on.Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim’s machine, and used a First…
-
Browser unter Beschuss: Die unterschätzte Angriffsfläche im Unternehmen
Mitarbeiter schätzen die Flexibilität, mit verschiedenen Geräten über den Browser auf alles zuzugreifen von kollaborativen Meeting-Tools bis hin zu Cloud-Dateien. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/browser-unterschaetzte-angriffsflaeche
-
Apple Private Cloud Compute Path Traversal Flaw Lets Attackers Write Files as Root
Security researcher Drinor Selmanaj has disclosed a path traversal vulnerability (CVE-2026-20685) in Apple’s Private Cloud Compute (PCC) that allows a privileged network attacker to write attacker-controlled files as root during node boot. This flaw affects the Apple Intelligence cloud-inference infrastructure. Apple has addressed the issue in PCC Release 5E290.3 and later, rating it as an…
-
Attack Path Analysis: What Vulnerability Scanners Miss in Cloud Environments
Attack Path Analysis adds critical context to cloud security by showing how vulnerabilities, identities, permissions and misconfigurations connect into real compromise paths. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/attack-path-analysis-what-vulnerability-scanners-miss-in-cloud-environments/
-
Metabase 0-Day Flaw Exploited in Attack to Inject Arbitrary SQL and Steal Database Credentials
Tags: attack, cloud, credentials, cyber, endpoint, exploit, flaw, security-incident, sql, update, vulnerability, zero-dayMetabase has reported a critical security incident involving a zero-day vulnerability that is actively being exploited. This vulnerability affects self-hosted deployments running version 1.58 and later. According to the company, an attacker exploited this previously unknown flaw to target Metabase Cloud before the vulnerable endpoints were blocked and a patch was developed. Customers using Metabase…
-
Product showcase: Enpass Password Manager breaks away from the proprietary cloud model
Enpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information in encrypted vaults. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/product-showcase-enpass-password-manager/
-
Keepit AI Truth Cloud: Verifizierte Backup-Daten sollen Enterprise-KI absichern
Keepit stellt AI Truth Cloud vor: Unveränderliche Backup-Daten, MCP-Integration und AI Safe Room sollen eine vertrauenswürdige Basis für Enterprise-KI schaffen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/keepit-ai-truth-cloud-verifizierte-backup-daten-sollen-enterprise-ki-absichern/a46059/
-
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own…
-
Imperva Customers Protected Against Novel HTTP Desync Attacks
TL;DR: Recent Portswigger research introduced novel HTTP desync techniques discovered through an AI-assisted research system called the HTTP Terminator. The findings expand the range of unusual HTTP behaviors that can cause front-end and back-end systems to interpret the same traffic differently. Imperva Cloud WAF and On-Prem WAF customers are protected against practical attack patterns described in the research. Imperva’s existing security engine already blocked malicious……
-
How AI Agents Widen the Enterprise Blast Radius
AWS’s Matt Girdharry and Varonis’ Matt Radolec on Data Security, Machine-Speed Risk. Agentic AI can act at machine speed across data, APIs and cloud services, expanding enterprise risk beyond traditional controls. AWS’ Matt Girdharry and Varonis’ Matt Radolec explain why AI governance, least privilege and runtime visibility now matter more than ever for security teams.…
-
Cogent Launches VR-1 Cyber Reasoning Model for Enterprise Attack Paths
Cogent Security has introduced Cogent VR-1, a frontier reasoning model trained to investigate enterprise environments and prove whether multi-step attack paths are reachable. The model starts with a foothold and an objective, then maps the surrounding environment and connects weaknesses across systems. Cogent said VR-1 can work across cloud infrastructure, identity systems and internal tools,..…
-
Deemed Export, Deemed Impossible: The Government Discovers That AI Has No Border
Anthropic’s reported AI model shutdown highlights how U.S. export controls could collide with frontier AI, cybersecurity, identity management and global cloud access. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/deemed-export-deemed-impossible-the-government-discovers-that-ai-has-no-border/
-
NSFOCUS LAS: Comprehensive Log Management for Security Visibility and Compliance
The Log Management Challenge Most enterprises accumulate log sources the same way they accumulate infrastructure: one device at a time, each generating data in its own proprietary format. The result is logs scattered across security appliances, network devices, servers, databases, middleware, applications, and cloud workloads, with no unified view and unknown device status. Any issue……
-
Souveräne IT-Infrastruktur – Schwarz Digits und Zscaler launchen Cloud-Sicherheitsplattform
First seen on security-insider.de Jump to article: www.security-insider.de/schwarz-digits-und-zscaler-launchen-cloud-sicherheitsplattform-a-8f53b0cfa3d11dc9be8d034d94b92987/
-
Zero-Touch Provisioning wird zum Einfallstor: 15 Schwachstellen in TP-Link Omada
Forescout entdeckt 15 Schwachstellen in TP-Link Omada. Angriffsketten über Zero-Touch Provisioning können Controller, Cloud-Dienste und Netzwerkgeräte gefährden. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/zero-touch-provisioning-wird-zum-einfallstor-15-schwachstellen-in-tp-link-omada/a46047/
-
MSSPs should not inherit cloud migration debt
First seen on scworld.com Jump to article: www.scworld.com/perspective/mssps-should-not-inherit-cloud-migration-debt
-
Top 10 Best External Attack Surface Management (EASM) Platforms 2026
In the sprawling digital ecosystem of 2026, organizations grapple with an increasingly complex and often poorly understood external attack surface. This attack surface encompasses all internet-facing assets that are discoverable and potentially exploitable by malicious actors. These assets extend far beyond traditional network perimeters to include cloud resources, web applications, APIs, orphaned infrastructure, exposed databases,…
-
Canadian Pleads Guilty to Snowflake Customer Data Extortion
Extortionist Connor Moucka, 26, Helped Breach Over 150 Customers’ Accounts. Canadian national Connor Riley Moucka, 26, pleaded guilty in Seattle federal court holding to ransom data he helped steal from over 150 customers of cloud-based data warehousing platform Snowflake, leading to victims paying millions in cryptocurrency ransoms and incident response costs. First seen on govinfosecurity.com…
-
FedRAMP 20x Class A Is Now Open: What It Means for Cloud Providers and Federal Cybersecurity
The federal cloud compliance landscape has reached another significant milestone. As of August 3, 2026, the FedRAMP 20x Class A submission pipeline is officially open, marking the first widely available entry point into the new FedRAMP 20x certification model. This isn’t simply a process update”, it’s a fundamental shift toward a faster, more automated, and…
-
Snowflake hacker pleads guilty, faces up to 32 years in prison
A Canadian man is facing decades in prison for hacking customer accounts at cloud storage provider Snowflake and stealing data from more than 165 organizations. Connor Riley … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/06/snowflake-canadian-hacker-pleaded-guilty/
-
Canadian Hacker Pleads Guilty to Stealing Billions of Records From 165 Cloud Customers
Connor Riley Moucka, a 26-year-old Canadian national from Kitchener, Ontario, has pleaded guilty to charges related to a large-scale cloud data theft and extortion operation that affected at least 165 organizations. This campaign resulted in the theft of billions of sensitive records, impacting an estimated 100 million individuals worldwide. Canadian Hacker Pleads Guilty According to…
-
Hackers Abuse Cloud Startup Credits to Resell Claude and Gemini AI Access
Threat actors are exploiting free cloud trials and startup credit programs to build gray-market AI proxy services. These services resell discounted access to advanced AI models, including Anthropic Claude and Google Gemini, according to Okta Threat Intelligence. These services rely on fraudulent or synthetic account registrations to accumulate promotional credits offered by cloud providers. The…
-
Cloud Security Alliance Starts Initiative to Define Controls for Catastrophic AI Risks
The Cloud Security Alliance has launched an initiative to define auditable controls for catastrophic AI risks, along with a research center focused on how frontier AI is changing cybersecurity. Announced Wednesday in Las Vegas, the Catastrophic Risk Annex will extend CSA’s AI Controls Matrix with controls for mitigating catastrophic AI risks. CSA said the controls..…

