Tag: cloud
-
Ephemeral data environments in Azure, leveraging the cloud
Our test data infrastructure solution, Tonic Ephemeral, streamlines data provisioning to eliminate lags in your testing workflows. Today, we’re going to look at the expanded benefits you can reap when deploying Ephemeral self-hosted in Azure. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/01/ephemeral-data-environments-in-azure-leveraging-the-cloud/
-
Cloud Attackers Exploit Max-Critical Aviatrix RCE Flaw
The security vulnerability tracked as CVE-2024-50603, which rates 10 out of 10 on the CVSS scale, enables unauthenticated remote code execution on affected systems, which cyberattackers are using to plant malware. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/cloud-attackers-exploit-max-critical-aviatrix-rce-flaw
-
Hackers Exploit Aviatrix Controller Vulnerability to Deploy Backdoors and Crypto Miners
A recently disclosed critical security flaw impacting the Aviatrix Controller cloud networking platform has come under active exploitation in the wild to deploy backdoors and cryptocurrency miners.Cloud security firm Wiz said it’s currently responding to “multiple incidents” involving the weaponization of CVE-2024-50603 (CVSS score: 10.0), a maximum severity bug that could result in First seen…
-
IoT und OT: Was 2025 für die Sicherheit von cyber-physischen Systemen bringt
NIS2, Effizienzgewinne durch Security und die Cloud-Verbreitung in der Industrie. Und wieder liegt ein herausforderndes Jahr hinter uns. Die geopolitische Lage insbesondere in der Ukraine und im Nahen Osten ist weiterhin angespannt, während die innenpolitische Situation in den zwei stärksten Volkswirtschaften Europas derzeit ungewiss erscheint. All dies hat auch Auswirkungen auf die Cybersecurity. Schon… First…
-
Sysdig in neuem CNAPP-Bericht von Gartner zu ‘Customers’ Choice” gekürt
Sysdig gab heute bekannt, dass Sysdig im Gartner-Peer-Insights-Bericht ‘Voice of the Customer for Cloud-Native Application Protection Platforms ” (CNAPPs) als ‘Customers’ Choice” ausgezeichnet wurde. Dies ist das Ergebnis von mehr als 100 Bewertungen in den letzten 18 Monaten, bei denen Sysdig-Kunden 2024 durchschnittlich 4,9 von 5 möglichen Sternen und eine Weiterempfehlungsrate von 99 Prozent vergaben…
-
RedCurl APT Deploys Malware via Windows Scheduled Tasks Exploitation
Researchers identified RedCurl APT group activity in Canada in late 2024, where the attackers used scheduled tasks to execute pcalua.exe to run malicious binaries and Python scripts, including the RPivot client.py script to connect to a remote server. Evidence suggests data exfiltration to cloud storage as this APT group targets various industries and aims for…
-
Microsoft took legal action against crooks who developed a tool to abuse its AI-based services
In December, Microsoft sued a group for creating tools to bypass safety measures in its cloud AI products. Microsoft filed a complaint with the Eastern District Court of Virginia against ten individuals for using stolen credentials and custom software to breach computers running Microsoft’s Azure OpenAI services to generate content for harmful purposes. >>Defendants used…
-
IBM Watsonx.ai Vulnerability Let Attackers Trigger XSS Attacks
A recently disclosed vulnerability, identified as CVE-2024-49785, has been found in IBM watsonx.ai, including its integration with IBM Cloud Pak for Data. This vulnerability exposes users to cross-site scripting (XSS) attacks, potentially compromising sensitive information. IBM Watsonx.ai Vulnerability The issue arises from improper input neutralization in the Web UI of IBM watsonx.ai. Authenticated users can exploit this flaw…
-
Advancements in Machine Identity Protections
The Strategic Importance of Non-Human Identities Are we taking the necessary steps to secure our machine identities, or are we leaving our systems exposed to potential attackers? Non-Human Identities (NHIs) play a critical role in maintaining secure cloud environments. In fact, machine learning solutions for government have recognized the importance of securing machine identities within……
-
Azure networking snafu enters day 2, some services still limping
Struggling to connect to the cloud? You’re not alone First seen on theregister.com Jump to article: www.theregister.com/2025/01/10/microsoft_azure_networking_snafu/
-
Die künstliche Intelligenz wird sowohl Cyberangriffe als auch -Abwehr radikal verändern
‘Künstliche Intelligenz, Desinformation, Fachkräftemangel, die Folgen zunehmender Cloud-Adaption und Schwächen in der Softwareentwicklung eröffnen in den nächsten zwölf Monaten neue Angriffsmöglichkeiten und stellen zusätzliche Ansprüche an die Cybersicherheit. Auf den Punkt gebracht kann man sagen: KI wird sowohl Angriff als auch Abwehr weiter radikal verändern! Mit KI können Cyberkriminelle Code sehr viel einfacher generieren und…
-
Microsoft accuses group of developing tool to abuse its AI service in new lawsuit
Microsoft has taken legal action against a group the company claims intentionally developed and used tools to bypass the safety guardrails of its cloud AI products. According to a complaint filed by the company in December in the U.S. District Court for the Eastern District of Virginia, a group of 10 unnamed defendants allegedly used…
-
New Paper: “Future of SOC: Transform the ‘How’” (Paper 5)
After a long, long, long writing effort “¦ eh “¦ break, we are ready with our 5th Deloitte and Google Cloud Future of the SOC paper “Future of SOC: Transform the ‘How’.” As a reminder (and I promise you do need it; it has been years”¦), the previous 4 papers are: “New Paper: “Future of the SOC: Evolution or…
-
SonarQube for IDE: Our journey this year, and sneak peek into 2025
Tags: cloudReviewing the enhancements delivered by the SonarQube for IDE team for developers during 2024. Focusing on streamlining the UX for teams, harnessing the power of SonarQube Server and Cloud through connected mode into your IDE, and making it even easier to focus on new code. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/01/sonarqube-for-ide-our-journey-this-year-and-sneak-peek-into-2025/
-
Nokia modernisiert Sicherheitsarchitektur mit Zscaler und beschleunigt Cloud-Transformationsinitiativen
Zscaler gibt bekannt, dass sich Nokia, multinationaler Technologieführer und Pionier für Netzwerke, digitale Dienste und Anwendungen, für die Einführung der Zscaler-Zero-Trust-Exchange-Plattform entschieden hat, um seine Sicherheit, betriebliche Effizienz und Cloud-Fähigkeiten zu steigern. Die Zscaler-Plattform ist eine Cloud-native Sicherheitslösung, die User direkt mit Anwendungen und Workloads verbindet, ohne das Unternehmensnetzwerk offenzulegen. Dadurch können Unternehmen ihre Angriffsfläche…
-
Ein vielseitiger Cloud-Datenschutz wird in einer Multi-Cloud-Welt immer wichtiger
In der aktuellen Umfrage ‘2024 State of Cloud Strategy Survey” geben 79 Prozent der Befragten in Unternehmen an, dass sie Multi-Cloud im Einsatz haben oder die Implementierung von Multi-Cloud planen. Die Chancen stehen also gut, dass Multi-Cloud-Strategien weiter zunehmen werden. Die Umfrage spiegelt lediglich wider, dass sich die Speicherung und Verarbeitung von Daten in öffentlichen…
-
Sicherheitslücken in Cloud Die verborgenen Hintertüren in die Cloud
First seen on security-insider.de Jump to article: www.security-insider.de/cloud-sicherheit-hardware-schwachstellen-a-35be6925ebaacf26227be50884b82f3b/
-
Darktrace Acquires Cado Security as AI Meets Cloud Forensics
Cado Security Deal Brings Enhanced Forensics, Automation, and AI-Powered Analytics. By acquiring Cado Security, Darktrace strengthens its ability to secure multi-cloud environments. The transaction brings together Cado’s forensic capabilities with Darktrace’s AI analytics to deliver comprehensive threat detection and response to organizations in regulated industries. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/darktrace-acquires-cado-security-as-ai-meets-cloud-forensics-a-27260
-
Darktrace To Acquire Cado Security, Boosting Cloud Threat Investigation
Darktrace announced a deal to acquire cloud threat investigation startup Cado Security, following its own acquisition by private equity firm Thoma Bravo. First seen on crn.com Jump to article: www.crn.com/news/security/2025/darktrace-to-acquire-cado-security-boosting-cloud-threat-investigation
-
Navigating the Complexities of Multi-Cloud Adoption
Tags: cloudFirst seen on scworld.com Jump to article: www.scworld.com/perspective/navigating-the-complexities-of-multi-cloud-adoption
-
MSSPs Have a Role in Stopping Cloud Attacks Using Stolen Credentials
First seen on scworld.com Jump to article: www.scworld.com/news/mssps-have-a-role-in-stopping-cloud-attacks-using-stolen-credentials
-
SonicWall firewall hit with critical authentication bypass vulnerability
SonicWall is warning customers of a severe vulnerability in its SonicOS SSLVPN with high exploitability that remote attackers could use to bypass authentication.The bug is an improper authentication vulnerability in the SSL VPN authentication mechanism, according to emails sent to customers and published on SonicWall’s official subreddit.”We have identified a high (severity) firewall vulnerability that…
-
Ivanti VPN Attacks Started In Mid-December, May Have Links To China: Mandiant
Researchers at Google Cloud-owned Mandiant say that the exploitation of a critical Ivanti Connect Secure vulnerability began in December 2024 and may be connected to a China-based threat group. First seen on crn.com Jump to article: www.crn.com/news/security/2025/ivanti-vpn-attacks-started-in-mid-december-may-have-links-to-china-mandiant
-
Wiz Hires Veteran Exec Fazal Merchant As President For IPO Push
Fazal Merchant, whose prior roles included as co-CEO of Tanium and CFO of DreamWorks Animation SKG, has been hired as president and CFO of IPO-bound cloud and AI security vendor Wiz. First seen on crn.com Jump to article: www.crn.com/news/security/2025/wiz-hires-veteran-exec-fazal-merchant-as-president-for-ipo-push
-
Acht Security-Ansatzpunkte für mehr Sicherheit in der Cloud – Schlüsselstrategien für die Cloud-Security
Tags: cloudFirst seen on security-insider.de Jump to article: www.security-insider.de/-staerkung-der-cyber-resilienz-unternehmen-ki-zero-trust-automatisierung-a-3f2dd011995282d88518025f16f03831/
-
Exploitation of New Ivanti VPN Zero-Day Linked to Chinese Cyberspies
Google Cloud’s Mandiant has linked the exploitation of CVE-2025-0282, a new Ivanti VPN zero-day, to Chinese cyberspies. The post Exploitation of New Ivanti VPN Zero-Day Linked to Chinese Cyberspies appeared first on SecurityWeek. First seen on securityweek.com Jump to article: www.securityweek.com/exploitation-of-new-ivanti-vpn-zero-day-linked-to-chinese-cyberspies/
-
Spam-Schutz umgangen: 512-Bit-RSA-Key mit 8 US-Dollar in der Cloud geknackt
Derart kurze RSA-Schlüssel gelten seit Jahrzehnten als unsicher. Ein Forscherteam hat nun demonstriert, wie schnell sie sich heute knacken lassen. First seen on golem.de Jump to article: www.golem.de/news/spam-schutz-umgangen-512-bit-rsa-key-mit-8-us-dollar-in-der-cloud-geknackt-2501-192264.html

