Tag: cloud
-
Google Bets ‘Agentic Defense’ Strategy Can Outpace Attackers
Google Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/google-bets-agentic-defense-strategy-outpace-attackers
-
A hard drive reliability check on 341,263 drives, from 4TB to past 20TB
Tags: cloudLarge cloud storage operators track their hard drives every day, recording which units keep running and which ones drop off the racks. Backblaze does this at scale, and its Q1 … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/17/hard-drive-reliability-2026-4tb-20tb/
-
OAuth Client ID Spoofing Enables Stealthy Cloud Account Enumeration
Proofpoint found attackers are using OAuth client ID spoofing to stealthily enumerate Microsoft Entra ID accounts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/oauth-client-id-spoofing-enables-stealthy-cloud-account-enumeration/
-
CloudMail-Sicherheit: KnowBe4 zeigt Maßnahmen zum Schutz vor Phishing und Kontoübernahmen
Viele Unternehmen gehen davon aus, dass ihr Cloud-Anbieter E-Mail-Daten automatisch und dauerhaft schützt. Diese Annahme kann sich im Ernstfall als problematisch erweisen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/cloud-e-mail-sicherheit-knowbe4-zeigt-massnahmen-zum-schutz-vor-phishing-und-kontouebernahmen/a45770/
-
Splunk Enterprise Flaws Expose Stored Credentials and Allow Arbitrary SPL Searches
Splunk has released security updates for three vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. These vulnerabilities could potentially expose stored credential hashes, enable arbitrary Search Processing Language (SPL) searches, and allow files to be written outside of the intended application directory. The flaws, tracked as CVE-2026-20296, CVE-2026-20297, and CVE-2026-20298, were disclosed on July 15,…
-
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry.The activity allows users to enumerate user accounts and validate stolen credentials in Microsoft Entra ID environments, without ever generating a successful sign-in event that would otherwise alert defenders. And bad actors…
-
SAP warns of critical flaws in NetWeaver and Commerce Cloud
SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sap-warns-of-critical-flaws-in-netweaver-and-commerce-cloud/
-
Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read
xAI’s Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed.A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned the git bundle out of the intercepted request, and pulled…
-
Millions of Microsoft Entra Accounts Targeted in OAuth Client ID Spoofing Campaigns
Proofpoint details how attackers spoof OAuth client IDs to probe Microsoft Entra accounts, test credentials and bypass common sign-in detections at cloud scale. First seen on hackread.com Jump to article: hackread.com/microsoft-entra-accounts-oauth-client-id-spoofing/
-
Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads
xAI’s Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed.A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned the git bundle out of the intercepted request, and pulled…
-
Microsoft Entra ID authentication overhaul to start in September 2026
Microsoft will begin rolling out passkeys as the default authentication experience for Microsoft Entra ID in the public cloud on September 1, 2026. Organizations with SMS or … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/microsoft-entra-passkey-authentication/
-
SAP July 2026 Patch Day Fixes Critical NetWeaver, Approuter, and Commerce Cloud Vulnerabilities
SAP’s July 2026 Security Patch Day addresses multiple high-impact vulnerabilities across its enterprise products, including a severe memory corruption issue in the SAP NetWeaver Application Server ABAP. The most critical vulnerability, tracked as CVE-2026-44747, has a CVSS score of 9.9 and affects several SAP kernel releases used by NetWeaver AS ABAP. SAP has categorized this…
-
Jscrambler npm Breach Exposes Developers to Malware
Malware Harvested Cloud Credentials, Source Code and Deployment Tokens. Attackers used a compromised npm publishing credential to release five malicious versions of Jscrambler’s Code Integrity package, deploying a Rust-based infostealer that harvested developer, cloud and AI tool credentials while evolving its delivery methods to evade detection. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/jscrambler-npm-breach-exposes-developers-to-malware-a-32215
-
Vectra AI CEO: Network Data Drives Predictive Security
Hitesh Sheth: Cloud, SaaS, Data Center Visibility Boosts Enterprise Risk Assessment. Vectra AI CEO Hitesh Sheth says comprehensive network observability provides the most reliable foundation for predictive cybersecurity because it spans cloud, SaaS and on-premises infrastructure while offering telemetry that attackers are far less able to manipulate than endpoint logs. First seen on govinfosecurity.com Jump…
-
KI-gestützte Bot-Abwehr ersetzt CAPTCHAs durch kontinuierliche Verhaltensanalyse
Cloudflare hebt die Bot-Abwehr auf eine neue Stufe. Mit <> präsentiert der Connectivity-Cloud-Anbieter eine neue Sicherheitslösung, die automatisierte Angriffe anhand des Nutzerverhaltens erkennt und dabei vollständig auf klassische CAPTCHAs verzichten kann. Statt einzelne Anfragen zu prüfen, analysiert Precursor das Verhalten von Besuchern während einer kompletten Sitzung und soll so auch hochentwickelte KI-Bots und automatisierte […]…
-
Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens
Internet-wide reconnaissance is expanding beyond conventional application targets to include Model Context Protocol (MCP) services, AI assistant configuration files, and locally exposed LLM endpoints. A 14-day review of Apache and ModSecurity logs from a small, low-traffic shared host found roughly 200 requests tied to AI-agent reconnaissance, alongside routine WordPress, .env, Git, and Spring Boot Actuator…
-
Novel OAuth Client ID Spoofing Technique Targets Cloud Environments
New research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/novel-spoofing-technique-targets/
-
Fake OAuth client IDs are helping attackers slip past sign-in logs
Attackers running account enumeration against Microsoft cloud tenants have added a step that keeps their probing out of the usual telemetry. They spoof the OAuth client ID, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/entra-id-oauth-client-id-spoofing/
-
Cloud-Abhängigkeit als KRITIS-Risiko Revival der Datensicherung vor Ort
Regulatorischer Druck zwingt KRITIS”‘Betreiber zu echter Resilienz: Das neue KRITIS”‘Dachgesetz und NIS2 verlangen nachweisbare Widerstandsfähigkeit, dokumentierte Risikoanalysen und belastbare Wiederanlaufkonzepte. Backup, Archivierung und Notfallwiederherstellung werden zu prüfbaren Pflichtdisziplinen nicht zu optionalen IT”‘Projekten. Souveränitätslücke zwischen Anspruch und Realität: 85″¯% der Unternehmen halten Deutschland für zu abhängig von US”‘Clouds, während 91″¯% eigentlich europäische Anbieter bevorzugen. Gleichzeitig… First…
-
Jscrambler npm Supply Chain Attack Steals Cloud Credentials and Crypto Wallet Secrets
A malicious actor compromised the Jscrambler npm package and published several trojanized versions that included a hidden, cross-platform credential-stealing payload. The attack targeted developers, build pipelines, and CI/CD systems, where npm installations could access source code, cloud credentials, deployment tokens, and sensitive environment variables. Jscrambler npm Supply Chain Attack Socket’s Research Team detected the initial…
-
Cynative: Open-source deep research agent
Running a large language model against a live cloud account to hunt for security holes comes with an obvious hazard. An agent that holds real credentials and a mandate to poke … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/cynative-open-source-deep-research-agent/
-
99.9% of fixable AI vulnerabilities remain unpatched
Organizations build, deploy, and operate AI in the cloud, but basic cybersecurity hygiene is often sacrificed for speed, according to Orca Security’s 2026 State of AI Security … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/ai-infrastructure-security-risks-report/
-
AI Gateways Offer Attackers the Keys to the Kingdom
A cryptomining incident highlights how AI gateways can provide access to AI models, cloud infrastructure, and identity and access management (IAM) data. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/ai-gateways-keys-kingdom
-
UK’s largest businesses dangerously exposed to cloud outages
British businesses, particularly those in the FTSE 100, are dangerously dependent on large cloud providers, with hypothetical large-scale outages at AWS or Azure regions likely to cause major economic damage, according to the Cyber Monitoring Centre First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645540/UKs-largest-businesses-dangerously-exposed-to-cloud-outages
-
Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
The attacker exploited AI workflows, chained cloud weaknesses, and stolen credentials to extort a large Amazon customer. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/lone-attacker-ai-breach-aws-cloud-environment
-
Hacker Claims Accenture Breach Exposed Source Code, SSH Keys, and Azure Tokens
Accenture confirmed a breach after a hacker claimed 35GB of source code and cloud keys were stolen, raising questions for cloud and security teams. The post Hacker Claims Accenture Breach Exposed Source Code, SSH Keys, and Azure Tokens appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-accenture-breach-cloud-keys/
-
US enterprises incorporate cyber risk into larger strategic focus
The rapid adoption of AI and cloud is forcing significant shifts toward business resilience and financial impact. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/us-enterprises-cyber-risk-strategic-focus/824707/
-
Best Next-Generation Firewall (NGFW) Solutions Compared (2026): Features Pricing
Twelve firewalls, one question: which NGFW earns a place at your network edge in 2026? For mostenterprisesthe shortlist starts with Fortinet FortiGate (best price-performance) and Palo Alto Networks (deepest application control), but the right answer shifts with your size, region, and cloud strategy, and one of the twelve vendors hereisn’tan appliance at all. A […]…
-
Internet-Intelligence und Attack-Surface-Management als Basis für Exposure-Management
Die Angriffsfläche von Unternehmen wächst kontinuierlich. Cloud-Dienste, SaaS-Anwendungen, IoT-Sensoren, hybride Infrastrukturen und Remote-Work sorgen dafür, dass immer mehr Systeme direkt über das Internet erreichbar sind. Eine umfassende Transparenz mit Exposure-Management wird damit zu einer zentralen Voraussetzung für wirksame Cybersecurity. Externe Angriffspunkte bilden den Ausgangspunkt vieler erfolgreicher Angriffe. Fehlkonfigurationen, Schatten-IT, unbeabsichtigter Remote-Access und im Internet sichtbare…
-
Fancy Bear Uses LSB Steganography and Reflective Loading to Run C# Remote-Control Trojan
A new intrusion campaign attributed to APT”‘C”‘20 (aka Fancy Bear, APT28) demonstrates the group’s continued refinement of stealthy, fileless techniques: weaponized Office documents that deploy a COM”‘hijacking DLL. Extract shellcode hidden via LSB steganography in a PNG, and use reflective loading to run an obfuscated C# remote”‘control Trojan that communicates through the legitimate cloud storage…

