Tag: cloud
-
Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads
xAI’s Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not just the files a coding task needed.A researcher publishing as cereblab, testing version 0.2.93, captured one of those uploads, cloned the git bundle out of the intercepted request, and pulled…
-
Microsoft Entra ID authentication overhaul to start in September 2026
Microsoft will begin rolling out passkeys as the default authentication experience for Microsoft Entra ID in the public cloud on September 1, 2026. Organizations with SMS or … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/microsoft-entra-passkey-authentication/
-
SAP July 2026 Patch Day Fixes Critical NetWeaver, Approuter, and Commerce Cloud Vulnerabilities
SAP’s July 2026 Security Patch Day addresses multiple high-impact vulnerabilities across its enterprise products, including a severe memory corruption issue in the SAP NetWeaver Application Server ABAP. The most critical vulnerability, tracked as CVE-2026-44747, has a CVSS score of 9.9 and affects several SAP kernel releases used by NetWeaver AS ABAP. SAP has categorized this…
-
Jscrambler npm Breach Exposes Developers to Malware
Malware Harvested Cloud Credentials, Source Code and Deployment Tokens. Attackers used a compromised npm publishing credential to release five malicious versions of Jscrambler’s Code Integrity package, deploying a Rust-based infostealer that harvested developer, cloud and AI tool credentials while evolving its delivery methods to evade detection. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/jscrambler-npm-breach-exposes-developers-to-malware-a-32215
-
Vectra AI CEO: Network Data Drives Predictive Security
Hitesh Sheth: Cloud, SaaS, Data Center Visibility Boosts Enterprise Risk Assessment. Vectra AI CEO Hitesh Sheth says comprehensive network observability provides the most reliable foundation for predictive cybersecurity because it spans cloud, SaaS and on-premises infrastructure while offering telemetry that attackers are far less able to manipulate than endpoint logs. First seen on govinfosecurity.com Jump…
-
KI-gestützte Bot-Abwehr ersetzt CAPTCHAs durch kontinuierliche Verhaltensanalyse
Cloudflare hebt die Bot-Abwehr auf eine neue Stufe. Mit <> präsentiert der Connectivity-Cloud-Anbieter eine neue Sicherheitslösung, die automatisierte Angriffe anhand des Nutzerverhaltens erkennt und dabei vollständig auf klassische CAPTCHAs verzichten kann. Statt einzelne Anfragen zu prüfen, analysiert Precursor das Verhalten von Besuchern während einer kompletten Sitzung und soll so auch hochentwickelte KI-Bots und automatisierte […]…
-
Attackers Combine MCP Recon With Cloud Metadata SSRF to Steal Service Account Tokens
Internet-wide reconnaissance is expanding beyond conventional application targets to include Model Context Protocol (MCP) services, AI assistant configuration files, and locally exposed LLM endpoints. A 14-day review of Apache and ModSecurity logs from a small, low-traffic shared host found roughly 200 requests tied to AI-agent reconnaissance, alongside routine WordPress, .env, Git, and Spring Boot Actuator…
-
Novel OAuth Client ID Spoofing Technique Targets Cloud Environments
New research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/novel-spoofing-technique-targets/
-
Fake OAuth client IDs are helping attackers slip past sign-in logs
Attackers running account enumeration against Microsoft cloud tenants have added a step that keeps their probing out of the usual telemetry. They spoof the OAuth client ID, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/entra-id-oauth-client-id-spoofing/
-
Cloud-Abhängigkeit als KRITIS-Risiko Revival der Datensicherung vor Ort
Regulatorischer Druck zwingt KRITIS”‘Betreiber zu echter Resilienz: Das neue KRITIS”‘Dachgesetz und NIS2 verlangen nachweisbare Widerstandsfähigkeit, dokumentierte Risikoanalysen und belastbare Wiederanlaufkonzepte. Backup, Archivierung und Notfallwiederherstellung werden zu prüfbaren Pflichtdisziplinen nicht zu optionalen IT”‘Projekten. Souveränitätslücke zwischen Anspruch und Realität: 85″¯% der Unternehmen halten Deutschland für zu abhängig von US”‘Clouds, während 91″¯% eigentlich europäische Anbieter bevorzugen. Gleichzeitig… First…
-
Jscrambler npm Supply Chain Attack Steals Cloud Credentials and Crypto Wallet Secrets
A malicious actor compromised the Jscrambler npm package and published several trojanized versions that included a hidden, cross-platform credential-stealing payload. The attack targeted developers, build pipelines, and CI/CD systems, where npm installations could access source code, cloud credentials, deployment tokens, and sensitive environment variables. Jscrambler npm Supply Chain Attack Socket’s Research Team detected the initial…
-
Cynative: Open-source deep research agent
Running a large language model against a live cloud account to hunt for security holes comes with an obvious hazard. An agent that holds real credentials and a mandate to poke … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/cynative-open-source-deep-research-agent/
-
99.9% of fixable AI vulnerabilities remain unpatched
Organizations build, deploy, and operate AI in the cloud, but basic cybersecurity hygiene is often sacrificed for speed, according to Orca Security’s 2026 State of AI Security … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/13/ai-infrastructure-security-risks-report/
-
AI Gateways Offer Attackers the Keys to the Kingdom
A cryptomining incident highlights how AI gateways can provide access to AI models, cloud infrastructure, and identity and access management (IAM) data. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/ai-gateways-keys-kingdom
-
UK’s largest businesses dangerously exposed to cloud outages
British businesses, particularly those in the FTSE 100, are dangerously dependent on large cloud providers, with hypothetical large-scale outages at AWS or Azure regions likely to cause major economic damage, according to the Cyber Monitoring Centre First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645540/UKs-largest-businesses-dangerously-exposed-to-cloud-outages
-
Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours
The attacker exploited AI workflows, chained cloud weaknesses, and stolen credentials to extort a large Amazon customer. First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/lone-attacker-ai-breach-aws-cloud-environment
-
Hacker Claims Accenture Breach Exposed Source Code, SSH Keys, and Azure Tokens
Accenture confirmed a breach after a hacker claimed 35GB of source code and cloud keys were stolen, raising questions for cloud and security teams. The post Hacker Claims Accenture Breach Exposed Source Code, SSH Keys, and Azure Tokens appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-accenture-breach-cloud-keys/
-
US enterprises incorporate cyber risk into larger strategic focus
The rapid adoption of AI and cloud is forcing significant shifts toward business resilience and financial impact. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/us-enterprises-cyber-risk-strategic-focus/824707/
-
Best Next-Generation Firewall (NGFW) Solutions Compared (2026): Features Pricing
Twelve firewalls, one question: which NGFW earns a place at your network edge in 2026? For mostenterprisesthe shortlist starts with Fortinet FortiGate (best price-performance) and Palo Alto Networks (deepest application control), but the right answer shifts with your size, region, and cloud strategy, and one of the twelve vendors hereisn’tan appliance at all. A […]…
-
Internet-Intelligence und Attack-Surface-Management als Basis für Exposure-Management
Die Angriffsfläche von Unternehmen wächst kontinuierlich. Cloud-Dienste, SaaS-Anwendungen, IoT-Sensoren, hybride Infrastrukturen und Remote-Work sorgen dafür, dass immer mehr Systeme direkt über das Internet erreichbar sind. Eine umfassende Transparenz mit Exposure-Management wird damit zu einer zentralen Voraussetzung für wirksame Cybersecurity. Externe Angriffspunkte bilden den Ausgangspunkt vieler erfolgreicher Angriffe. Fehlkonfigurationen, Schatten-IT, unbeabsichtigter Remote-Access und im Internet sichtbare…
-
Fancy Bear Uses LSB Steganography and Reflective Loading to Run C# Remote-Control Trojan
A new intrusion campaign attributed to APT”‘C”‘20 (aka Fancy Bear, APT28) demonstrates the group’s continued refinement of stealthy, fileless techniques: weaponized Office documents that deploy a COM”‘hijacking DLL. Extract shellcode hidden via LSB steganography in a PNG, and use reflective loading to run an obfuscated C# remote”‘control Trojan that communicates through the legitimate cloud storage…
-
Threat Actors Uses Agentic AI to Rapidly Compromise Cloud Target
Sygnia report details how agentic AI accelerated weeks-long attack to just 72 hours First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/threat-actor-agentic-ai-cloud/
-
Die Cloud hat Ihnen nicht Ihre Souveränität genommen
Tags: cloudJahrelang kursierte digitale Souveränität in deutschen IT-Kreisen als nobles Streben etwas, das man irgendwann anstreben würde, sobald die Cloud-Migration abgeschlossen sei. Dieser Moment ist nun da. First seen on it-daily.net Jump to article: www.it-daily.net/it-management/cloud-computing/cloud-souveraenitaet
-
KI-Workloads in der Cloud – Agentic AI: Deshalb kommen Cloud-Infrastrukturen an ihre Grenzen
First seen on security-insider.de Jump to article: www.security-insider.de/ki-agenten-cloud-infrastruktur-scalable-workloads-a-2f54037532ee57f8ab2b44f55f167be1/
-
Google Dialogflow CX Flaw Lets Attackers Bypass VPC-SC and Steal Sensitive Chatbot Data
A critical vulnerability in Google Cloud’s Dialogflow CX platform allowed attackers to bypass VPC Service Controls (VPC-SC) and silently exfiltrate sensitive chatbot data, raising significant concerns about the security of enterprise AI deployments. Discovered by Varonis Threat Labs and dubbed “Rogue Agent,” the flaw exposed a serious design gap in how Dialogflow CX executes custom…
-
Investors Accuse Oracle of Hiding OpenAI Financial Risks
Suit Claims Oracle’s AI Backlog Relied Heavily on One Financially Strained Customer. An investor class action lawsuit alleges Oracle failed to disclose internal concerns about OpenAI’s revenue, user growth and ability to meet cloud-computing commitments, leaving investors unaware of risks tied to Oracle’s multibillion-dollar AI infrastructure expansion and February debt offering. First seen on govinfosecurity.com…
-
Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots
A critical flaw in Google’s Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project.From there, they could read live conversations, steal the data users shared, and make the bots send attacker-written messages, including requests to re-enter a password.Security…
-
Bei Cloud-Ausfall droht fast jedes zweite Unternehmen lahmgelegt zu werden
Tags: cloudFirst seen on datensicherheit.de Jump to article: www.datensicherheit.de/cloud-ausfall-jedes-zweite-unternehmen-lahmgelegt
-
Check Point Brings Cloud Firewall to AWS European Sovereign Cloud
Check Point Software has announced that its Cloud Firewall offering is now available on the AWS European Sovereign Cloud, as the cybersecurity giant becomes an official partner for Amazon’s new independent European cloud infrastructure. The move is designed to help European organisations meet increasingly stringent data residency and operational autonomy requirements under EU regulatory frameworks,…
-
Warum Unternehmen bei der physischen Sicherheit auf hybride Lösungen setzen
Aktuelle Daten aus dem Report zur Lage der physischen Sicherheit 2026 von Genetec belegen: Die Hybrid-Cloud ist kein Kompromiss sie ist die bewusste Entscheidung für Resilienz, Kontrolle und Zukunftsfähigkeit. Ob Onpremise, Cloud oder eine Kombination aus beidem: Unternehmen wollen bei der Modernisierung ihrer physischen Sicherheitsinfrastruktur selbst entscheiden, was wann und wo eingesetzt wird. Das […]…

