Tag: cloud
-
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.Group-IB found the server in mid-April 2026 in Alibaba Cloud’s Singapore region; it was offline by the time…
-
Stop renting storage space, this lifetime 2TB plan is yours for $59
Cloud storage costs tend to creep up over time, since most services charge monthly or annually for as long as you use them. FileJump’s Lifetime Plan skips that model entirely, offering 2TB of cloud storage for a single payment of $59 (MSRP $467). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/stop-renting-storage-space-this-lifetime-2tb-plan-is-yours-for-59/
-
Bitkom Cloud Report 2026 – 46 Prozent der deutschen Unternehmen hängen am digitalen Tropf
Tags: cloudFirst seen on security-insider.de Jump to article: www.security-insider.de/46-prozent-der-deutschen-unternehmen-haengen-am-digitalen-tropf-a-6f01c2eeacbc029e84bc0995919b8968/
-
Cloud operations become the next big role for agentic AI
Companies are using agentic AI to manage growing application environments, automate routine tasks, and support decisions. Business and IT leaders increasingly see the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/22/agentic-ai-cloud-operations-report/
-
AI is making cloud advisory predictive
First seen on scworld.com Jump to article: www.scworld.com/perspective/ai-is-making-cloud-advisory-predictive
-
NadMesh-Botnetz stiehlt Cloud-Zugänge über KI-Dienste
Das neue Go-Botnetz NadMesh sucht nach ungeschützten KI-Diensten, um AWS-Zugangsdaten und Kubernetes-Token aus den Systemen zu entwenden. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/nadmesh-botnetz-cloud-zugaenge
-
KeeperPAM strengthens privileged access management for global construction SaaS provider Asite
Keeper Security has announced that UK-based construction technology provider Asite has deployed KeeperPAM® to strengthen privileged access management, secrets governance and credential security across its global operations. The deployment, detailed in a newly published customer case study, sees Asite replace a collection of legacy privileged access and secrets management tools with Keeper’s unified, cloud-native platform…
-
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
A cloud tenant using nothing but ordinary GPU access can push a data center’s power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in.That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, the IACR’s hardware-security…
-
Hugging Face Says Autonomous AI Agents Breached Data, Credentials
Tags: access, ai, cloud, credentials, cyberattack, data, exploit, flaw, framework, infrastructure, vulnerabilityAttackers Exploited Dataset Processing Flaws to Access Internal Clusters. Hugging Face said an autonomous AI agent framework exploited dataset processing vulnerabilities to compromise internal infrastructure, harvest cloud credentials and move laterally across clusters, exposing both the rise of agentic cyberattacks and the limits of AI safety guardrails during incident response. First seen on govinfosecurity.com Jump…
-
New Continuous Runtime Security Validation service aims to strengthen fintech cyber resilience
Fintech organisations across the UK and Ireland can now access a new service designed to provide ongoing assurance over production security following a strategic partnership between Critical Cloud and Tarian Labs. The Continuous Runtime Security Validation offering helps businesses continuously verify that their security controls remain effective as cloud environments, applications and AI capabilities evolve.…
-
AWS: Airbus schickt sensible Daten in die französische Cloud
Airbus verlagert kritische Systeme von Amazon Web Services zum französischen Anbieter Scaleway. First seen on golem.de Jump to article: www.golem.de/news/aws-airbus-schickt-sensible-daten-in-die-franzoesische-cloud-2607-211034.html
-
Citrix Secure Access Client Flaw Lets Low-Privileged Windows Users Gain SYSTEM Privileges
Cloud Software Group has issued a High-severity security bulletin (CTX696734) disclosing two vulnerabilities in the Citrix Secure Access Client for Windows and the Citrix Endpoint Analysis Client for Windows. The more serious of the two, tracked as CVE-2026-53565, allows a standard, low-privileged user on a local system to escalate privileges and gain full SYSTEM access,…
-
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys.A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and…
-
Amazon fixing bug that billed some AWS customers billions of dollars
Tags: cloudSome Amazon customers logged on Friday to a surprise bill estimate claiming that they owed the tech and cloud giant billions in fees. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/17/amazon-fixing-bug-that-billed-some-aws-customers-billions-of-dollars/
-
Amazon fixing bug that billed some AWS customers billions of dollars
Tags: cloudSome Amazon customers logged on Friday to a surprise bill estimate claiming that they owed the tech and cloud giant billions in fees. First seen on techcrunch.com Jump to article: techcrunch.com/2026/07/17/amazon-fixing-bug-that-billed-some-aws-customers-billions-of-dollars/
-
Cybersicherheit als KI-natives Verteidigungssystem
Sophos hat Sophos-Fusion vorgestellt das umfassendste KI-native Cybersicherheits-Verteidigungssystem der Branche. Es wurde entwickelt, um koordinierte Reaktionen auf Bedrohungen im KI-Zeitalter zu ermöglichen. Entwickelt für eine durch KI veränderte Bedrohungslandschaft vereint Sophos-Fusion Security-Operations, Endpunktschutz, Netzwerksicherheit, Identitäts-, E-Mail- und Cloud-Sicherheit in einem einzigen Verteidigungssystem, das Bedrohungen mit KI-Geschwindigkeit verhindert, erkennt, untersucht und darauf reagiert. Ein Cybersicherheits-Verteidigungssystem […]…
-
Cybersicherheit als KI-natives Verteidigungssystem
Sophos hat Sophos-Fusion vorgestellt das umfassendste KI-native Cybersicherheits-Verteidigungssystem der Branche. Es wurde entwickelt, um koordinierte Reaktionen auf Bedrohungen im KI-Zeitalter zu ermöglichen. Entwickelt für eine durch KI veränderte Bedrohungslandschaft vereint Sophos-Fusion Security-Operations, Endpunktschutz, Netzwerksicherheit, Identitäts-, E-Mail- und Cloud-Sicherheit in einem einzigen Verteidigungssystem, das Bedrohungen mit KI-Geschwindigkeit verhindert, erkennt, untersucht und darauf reagiert. Ein Cybersicherheits-Verteidigungssystem […]…
-
AWS Billing Bug Displays Trillion-Dollar Cost Estimates to Cloud Customers
Amazon Web Services (AWS) is currently investigating a significant billing issue affecting its Cost Explorer tool. This problem caused some cloud customers to see alarmingly inflated cost estimates, with figures reportedly reaching into the trillions of dollars. AWS Support acknowledged the issue on July 17, 2026, which has caused confusion and concern within the cloud…
-
AWS Billing Bug Displays Trillion-Dollar Cost Estimates to Cloud Customers
Amazon Web Services (AWS) is currently investigating a significant billing issue affecting its Cost Explorer tool. This problem caused some cloud customers to see alarmingly inflated cost estimates, with figures reportedly reaching into the trillions of dollars. AWS Support acknowledged the issue on July 17, 2026, which has caused confusion and concern within the cloud…
-
Google Bets ‘Agentic Defense’ Strategy Can Outpace Attackers
Google Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/google-bets-agentic-defense-strategy-outpace-attackers
-
A hard drive reliability check on 341,263 drives, from 4TB to past 20TB
Tags: cloudLarge cloud storage operators track their hard drives every day, recording which units keep running and which ones drop off the racks. Backblaze does this at scale, and its Q1 … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/17/hard-drive-reliability-2026-4tb-20tb/
-
OAuth Client ID Spoofing Enables Stealthy Cloud Account Enumeration
Proofpoint found attackers are using OAuth client ID spoofing to stealthily enumerate Microsoft Entra ID accounts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/oauth-client-id-spoofing-enables-stealthy-cloud-account-enumeration/
-
CloudMail-Sicherheit: KnowBe4 zeigt Maßnahmen zum Schutz vor Phishing und Kontoübernahmen
Viele Unternehmen gehen davon aus, dass ihr Cloud-Anbieter E-Mail-Daten automatisch und dauerhaft schützt. Diese Annahme kann sich im Ernstfall als problematisch erweisen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/cloud-e-mail-sicherheit-knowbe4-zeigt-massnahmen-zum-schutz-vor-phishing-und-kontouebernahmen/a45770/
-
Splunk Enterprise Flaws Expose Stored Credentials and Allow Arbitrary SPL Searches
Splunk has released security updates for three vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. These vulnerabilities could potentially expose stored credential hashes, enable arbitrary Search Processing Language (SPL) searches, and allow files to be written outside of the intended application directory. The flaws, tracked as CVE-2026-20296, CVE-2026-20297, and CVE-2026-20298, were disclosed on July 15,…
-
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
At least two distinct threat actors are weaponizing a novel evasion technique called OAuth client ID spoofing in cloud campaigns, while slipping past telemetry.The activity allows users to enumerate user accounts and validate stolen credentials in Microsoft Entra ID environments, without ever generating a successful sign-in event that would otherwise alert defenders. And bad actors…
-
SAP warns of critical flaws in NetWeaver and Commerce Cloud
SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sap-warns-of-critical-flaws-in-netweaver-and-commerce-cloud/
-
Grok Build Uploaded Entire Git Repositories to xAI Storage, Not Just Files It Read
xAI’s Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed.A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned the git bundle out of the intercepted request, and pulled…
-
Millions of Microsoft Entra Accounts Targeted in OAuth Client ID Spoofing Campaigns
Proofpoint details how attackers spoof OAuth client IDs to probe Microsoft Entra accounts, test credentials and bypass common sign-in detections at cloud scale. First seen on hackread.com Jump to article: hackread.com/microsoft-entra-accounts-oauth-client-id-spoofing/
-
Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads
xAI’s Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed.A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned the git bundle out of the intercepted request, and pulled…

