Tag: cloud
-
Threat Actors Uses Agentic AI to Rapidly Compromise Cloud Target
Sygnia report details how agentic AI accelerated weeks-long attack to just 72 hours First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/threat-actor-agentic-ai-cloud/
-
Die Cloud hat Ihnen nicht Ihre Souveränität genommen
Tags: cloudJahrelang kursierte digitale Souveränität in deutschen IT-Kreisen als nobles Streben etwas, das man irgendwann anstreben würde, sobald die Cloud-Migration abgeschlossen sei. Dieser Moment ist nun da. First seen on it-daily.net Jump to article: www.it-daily.net/it-management/cloud-computing/cloud-souveraenitaet
-
KI-Workloads in der Cloud – Agentic AI: Deshalb kommen Cloud-Infrastrukturen an ihre Grenzen
First seen on security-insider.de Jump to article: www.security-insider.de/ki-agenten-cloud-infrastruktur-scalable-workloads-a-2f54037532ee57f8ab2b44f55f167be1/
-
Google Dialogflow CX Flaw Lets Attackers Bypass VPC-SC and Steal Sensitive Chatbot Data
A critical vulnerability in Google Cloud’s Dialogflow CX platform allowed attackers to bypass VPC Service Controls (VPC-SC) and silently exfiltrate sensitive chatbot data, raising significant concerns about the security of enterprise AI deployments. Discovered by Varonis Threat Labs and dubbed “Rogue Agent,” the flaw exposed a serious design gap in how Dialogflow CX executes custom…
-
Investors Accuse Oracle of Hiding OpenAI Financial Risks
Suit Claims Oracle’s AI Backlog Relied Heavily on One Financially Strained Customer. An investor class action lawsuit alleges Oracle failed to disclose internal concerns about OpenAI’s revenue, user growth and ability to meet cloud-computing commitments, leaving investors unaware of risks tied to Oracle’s multibillion-dollar AI infrastructure expansion and February debt offering. First seen on govinfosecurity.com…
-
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
A critical flaw in Google’s Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project.From there, they could read live conversations, steal the data users shared, and make the bots send attacker-written messages, including requests to re-enter a password.Security…
-
Bei Cloud-Ausfall droht fast jedes zweite Unternehmen lahmgelegt zu werden
Tags: cloudFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/cloud-ausfall-jedes-zweite-unternehmen-lahmgelegt
-
Check Point Brings Cloud Firewall to AWS European Sovereign Cloud
Check Point Software has announced that its Cloud Firewall offering is now available on the AWS European Sovereign Cloud, as the cybersecurity giant becomes an official partner for Amazon’s new independent European cloud infrastructure. The move is designed to help European organisations meet increasingly stringent data residency and operational autonomy requirements under EU regulatory frameworks,…
-
Warum Unternehmen bei der physischen Sicherheit auf hybride Lösungen setzen
Aktuelle Daten aus dem Report zur Lage der physischen Sicherheit 2026 von Genetec belegen: Die Hybrid-Cloud ist kein Kompromiss sie ist die bewusste Entscheidung für Resilienz, Kontrolle und Zukunftsfähigkeit. Ob Onpremise, Cloud oder eine Kombination aus beidem: Unternehmen wollen bei der Modernisierung ihrer physischen Sicherheitsinfrastruktur selbst entscheiden, was wann und wo eingesetzt wird. Das […]…
-
Flexera State of the Cloud Report 2026 – Tickt die Cloud in Europa anders?
Tags: cloudFirst seen on security-insider.de Jump to article: www.security-insider.de/flexera-state-of-the-cloud-2026-hybrid-cloud-multicloud-ki-kosten-a-998078035adb29db14253a53d06d67a5/
-
16-Year-Old Januscape KVM Escape Vulnerability Lets Attackers Compromise Linux Hosts
A newly disclosed vulnerability in the Linux kernel, tracked as CVE-2026-53359 and named “Januscape,” reveals a 16-year-old flaw in KVM/x86 virtualization. This vulnerability allows guest virtual machines (VMs) to escape to the host under specific conditions, raising significant concerns for multi-tenant cloud environments. Discovered by security researcher Hyunwoo Kim, the issue lies within the shadow…
-
Unternehmen spricht von Einzelfällen: 1&1-Kunden können Cloud-App seit Monaten nicht nutzen
Tags: cloud1&1 bekommt die Anmeldeprobleme in der eigenen Cloud-App nicht behoben. Kunden müssen weiter auf Abhilfe warten. First seen on golem.de Jump to article: www.golem.de/news/unternehmen-spricht-von-einzelfaellen-1-1-kunden-koennen-cloud-app-nicht-nutzen-und-muessen-weiter-warten-2607-210573.html
-
Januscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape Attacks
Januscape: A 16-year-old Linux KVM flaw lets cloud VM tenants crash hosts and potentially escape guests. It affects Intel and AMD systems. Security researcher Hyunwoo Kim has published details of a use-after-free vulnerability in Linux’s KVM hypervisor that allows code running inside a guest virtual machine to corrupt host kernel memory. The bug, tracked as…
-
Microsoft testing new Cloud Rebuild Windows 11 recovery feature
Microsoft has begun testing the Cloud Rebuild recovery feature in the latest Windows 11 Insider Preview builds released for users in the Experimental channel. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-testing-new-cloud-rebuild-windows-11-recovery-feature/
-
Windows Device ID Helped Authorities Track Scattered Spider Hacking Group Member
Authorities used a persistent Windows Global Device ID, along with VPN telemetry and cloud service records, to connect the infrastructure used in a major extortion attack to a 19-year-old member of the Scattered Spider group, Peter Stokes. In a superseding criminal complaint filed in the Northern District of Illinois, the FBI outlines how Stokes, who…
-
Cloud-Migration ist kein Sicherheits-Audit
Ein Kommentar von André Dube, Director of Cyber Security Center bei Skaylink Wer Systeme in die Cloud hebt, macht sie schneller, skalierbarer und oft günstiger. Was dabei häufig vergessen wird: schneller, skalierbarer und günstiger gilt auch für Angreifer wenn die Daten, die migriert wurden, niemand mehr auf dem Schirm hat. Genau das ist… First seen…
-
Zero Trust: Warum das Vertrauen im Firmennetz zum Sicherheitsrisiko geworden ist
Management Summary Zero Trust ist ein strategischer Sicherheitsansatz, der implizites Vertrauen im Firmennetz durch kontinuierliche Prüfung von Identität, Gerät, Kontext und Berechtigung ersetzt. Verteilte Arbeit, Cloud- und SaaS-Nutzung sowie externe Dienstleister machen klassische Perimeter-Sicherheit zunehmend unwirksam. Moderne Angriffe zielen verstärkt auf Identitäten, gestohlene Zugangsdaten, laterale Bewegung und Schwachstellen in der Lieferkette. Zentrale Bausteine sind starke……
-
Bitkom Cloud Report 2026: Cloud-Ausfall würde jedes zweite Unternehmen lahmlegen
Tags: cloudEin Ausfall von Cloud-Diensten würde fast jedes zweite deutsche Unternehmen in die Knie zwingen. Eine aktuelle Bitkom-Studie zeigt, wie tief die Abhängigkeit inzwischen ist. First seen on golem.de Jump to article: www.golem.de/news/bitkom-cloud-report-2026-cloud-ausfall-wuerde-jedes-zweite-unternehmen-lahmlegen-2607-210560.html
-
Kontroverse über Souveränitätsstufen – EU-Souveränitätskriterien für Clouds: zu restriktiv? Zu stark?
Tags: cloudFirst seen on security-insider.de Jump to article: www.security-insider.de/eu-cada-cloud-ki-souveraenitaet-streit-a-1ad9c881359e23ecd3d7a38ef323c300/
-
AI Agent Pulls Off a Ransomware Attack Without Human Help
Researchers Say the Attack Combined AI Decision-Making With Known Software Flaws. An autonomous AI agent has executed what researchers describe as the first agentic ransomware attack, exploiting vulnerabilities, stealing credentials and encrypting a production database without human intervention. Cloud security firm Sysdig attributed it to a threat actor it tracks as Jadepuffer. First seen on…
-
FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
FBI says TeamPCP poisoned trusted developer tools to steal cloud credentials, spread malware through software updates, and extort victims. On July 2, 2026, the FBI published a FLASH alert identifying the criminal group called TeamPCP and detailing how it compromised widely used developer and security tools to steal credentials from victim environments at scale. The…
-
The Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident
Vercel breach happened after an employee used an unvetted AI tool. Attackers exploited it as a trusted link to access systems, steal data, and extort $2M. The Vercel breach of April 2026 did not begin with a classic zero-day exploit, a misconfigured cloud bucket, or a sophisticated nation-state infrastructure implant. Instead, it unfolded when an…
-
FBI Says TeamPCP Uses Trojanized Updates to Steal Cloud Tokens, SSH Keys, and Kubernetes Secrets
Tags: access, advisory, attack, cloud, cyber, cybercrime, exploit, group, kubernetes, software, supply-chain, updateThe Federal Bureau of Investigation (FBI) has issued an urgent FLASH advisory warning that the cybercriminal group TeamPCP is weaponizing trojanized software updates to harvest cloud access tokens, SSH keys, and Kubernetes secrets at scale. This campaign represents one of the most sophisticated software supply chain attacks observed in 2026, exploiting trust in widely deployed…
-
Datensicherung und Cloud-Verschlüsselung – FAST LTA startet Data-Protection-Kooperation mit Eperi
First seen on security-insider.de Jump to article: www.security-insider.de/fast-lta-startet-data-protection-kooperation-mit-eperi-a-1bcc90f56c1c46591667da9addf5dc93/
-
VMware Licensing Changes and Their Impact on Infrastructure Modernization
Explore how VMware licensing changes are influencing infrastructure modernization, cloud strategy, and AI readiness, and what enterprises should evaluate next. First seen on hackread.com Jump to article: hackread.com/vmware-licensing-changes-infrastructure-modernization/
-
JADEPUFFER Agentic Ransomware Uses LLM to Automate Database Extortion
The first instance of agentic ransomware: JADEPUFFER, an LLM-driven extortion operation that automated an end-to-end database-crippling campaign. The actor gained execution on an internet-facing Langflow instance via CVE-2025-3248, used the AI-host environment to harvest cloud and API credentials, and pivoted into a production MySQL/Nacos deployment to carry out a destructive, database-focused extortion playbook without a…
-
Infinigate beruft Kai Grunwitz zum Chief Growth Officer
Die Infinigate Group, führende Technologieplattform und Trusted-Advisor in den Bereichen Cybersicherheit, Cloud und Netzwerkinfrastruktur, hat Kai Grunwitz zum Chief Growth Officer (CGO) ernannt. Damit unterstreicht der Value-Added-Distributor sein Ziel, die Wachstumsstrategie weiter zu skalieren und den Mehrwert für Hersteller und Channel-Partner zu steigern. Als CGO wird Grunwitz die zentralen Wachstumsfelder des Unternehmens verantworten: die Stärkung…
-
Cloud-Firewalls von Check Point über AWS-European-Sovereign-Cloud verfügbar
Check Point gibt bekannt, dass das Unternehmen nun Partner der AWS-European-Sovereign-Cloud ist. Die Cloud-Firewalls von Check Point sind nun in der AWS-European-Sovereign-Cloud verfügbar und unterstützen damit Kunden in Europa noch besser. Die Lösungen von Check Point bieten präventive Sicherheit über Netzwerk-, Workload- und Anwendungsebenen hinweg und gewährleisten die gleiche Verfügbarkeit und Leistung, die Kunden von…
-
Mitigating Attacks Before They Impact Infrastructure: Link11 provides next generation network DDoS protection
Frankfurt am Main, Deutschland, July 1st, 2026, CyberNewswire Link11, a leading European provider of cloud-based cybersecurity solutions, today announced the launch of its completely rebuilt Layer 3/4 DDoS mitigation solution, designed to address the growing complexity of modern network attacks. Today’s DDoS attacks are not just simple volume or protocol attacks anymore. They can originate…

