Tag: cloud
-
Warum Unternehmen bei der physischen Sicherheit auf hybride Lösungen setzen
Aktuelle Daten aus dem Report zur Lage der physischen Sicherheit 2026 von Genetec belegen: Die Hybrid-Cloud ist kein Kompromiss sie ist die bewusste Entscheidung für Resilienz, Kontrolle und Zukunftsfähigkeit. Ob Onpremise, Cloud oder eine Kombination aus beidem: Unternehmen wollen bei der Modernisierung ihrer physischen Sicherheitsinfrastruktur selbst entscheiden, was wann und wo eingesetzt wird. Das […]…
-
Flexera State of the Cloud Report 2026 – Tickt die Cloud in Europa anders?
Tags: cloudFirst seen on security-insider.de Jump to article: www.security-insider.de/flexera-state-of-the-cloud-2026-hybrid-cloud-multicloud-ki-kosten-a-998078035adb29db14253a53d06d67a5/
-
16-Year-Old Januscape KVM Escape Vulnerability Lets Attackers Compromise Linux Hosts
A newly disclosed vulnerability in the Linux kernel, tracked as CVE-2026-53359 and named “Januscape,” reveals a 16-year-old flaw in KVM/x86 virtualization. This vulnerability allows guest virtual machines (VMs) to escape to the host under specific conditions, raising significant concerns for multi-tenant cloud environments. Discovered by security researcher Hyunwoo Kim, the issue lies within the shadow…
-
Unternehmen spricht von Einzelfällen: 1&1-Kunden können Cloud-App seit Monaten nicht nutzen
Tags: cloud1&1 bekommt die Anmeldeprobleme in der eigenen Cloud-App nicht behoben. Kunden müssen weiter auf Abhilfe warten. First seen on golem.de Jump to article: www.golem.de/news/unternehmen-spricht-von-einzelfaellen-1-1-kunden-koennen-cloud-app-nicht-nutzen-und-muessen-weiter-warten-2607-210573.html
-
Januscape: 16-Year-Old Linux KVM Bug Enables Cloud VM Escape Attacks
Januscape: A 16-year-old Linux KVM flaw lets cloud VM tenants crash hosts and potentially escape guests. It affects Intel and AMD systems. Security researcher Hyunwoo Kim has published details of a use-after-free vulnerability in Linux’s KVM hypervisor that allows code running inside a guest virtual machine to corrupt host kernel memory. The bug, tracked as…
-
Microsoft testing new Cloud Rebuild Windows 11 recovery feature
Microsoft has begun testing the Cloud Rebuild recovery feature in the latest Windows 11 Insider Preview builds released for users in the Experimental channel. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-testing-new-cloud-rebuild-windows-11-recovery-feature/
-
Windows Device ID Helped Authorities Track Scattered Spider Hacking Group Member
Authorities used a persistent Windows Global Device ID, along with VPN telemetry and cloud service records, to connect the infrastructure used in a major extortion attack to a 19-year-old member of the Scattered Spider group, Peter Stokes. In a superseding criminal complaint filed in the Northern District of Illinois, the FBI outlines how Stokes, who…
-
Cloud-Migration ist kein Sicherheits-Audit
Ein Kommentar von André Dube, Director of Cyber Security Center bei Skaylink Wer Systeme in die Cloud hebt, macht sie schneller, skalierbarer und oft günstiger. Was dabei häufig vergessen wird: schneller, skalierbarer und günstiger gilt auch für Angreifer wenn die Daten, die migriert wurden, niemand mehr auf dem Schirm hat. Genau das ist… First seen…
-
Zero Trust: Warum das Vertrauen im Firmennetz zum Sicherheitsrisiko geworden ist
Management Summary Zero Trust ist ein strategischer Sicherheitsansatz, der implizites Vertrauen im Firmennetz durch kontinuierliche Prüfung von Identität, Gerät, Kontext und Berechtigung ersetzt. Verteilte Arbeit, Cloud- und SaaS-Nutzung sowie externe Dienstleister machen klassische Perimeter-Sicherheit zunehmend unwirksam. Moderne Angriffe zielen verstärkt auf Identitäten, gestohlene Zugangsdaten, laterale Bewegung und Schwachstellen in der Lieferkette. Zentrale Bausteine sind starke……
-
Bitkom Cloud Report 2026: Cloud-Ausfall würde jedes zweite Unternehmen lahmlegen
Tags: cloudEin Ausfall von Cloud-Diensten würde fast jedes zweite deutsche Unternehmen in die Knie zwingen. Eine aktuelle Bitkom-Studie zeigt, wie tief die Abhängigkeit inzwischen ist. First seen on golem.de Jump to article: www.golem.de/news/bitkom-cloud-report-2026-cloud-ausfall-wuerde-jedes-zweite-unternehmen-lahmlegen-2607-210560.html
-
Kontroverse über Souveränitätsstufen – EU-Souveränitätskriterien für Clouds: zu restriktiv? Zu stark?
Tags: cloudFirst seen on security-insider.de Jump to article: www.security-insider.de/eu-cada-cloud-ki-souveraenitaet-streit-a-1ad9c881359e23ecd3d7a38ef323c300/
-
AI Agent Pulls Off a Ransomware Attack Without Human Help
Researchers Say the Attack Combined AI Decision-Making With Known Software Flaws. An autonomous AI agent has executed what researchers describe as the first agentic ransomware attack, exploiting vulnerabilities, stealing credentials and encrypting a production database without human intervention. Cloud security firm Sysdig attributed it to a threat actor it tracks as Jadepuffer. First seen on…
-
FBI: TeamPCP Compromised Dev Tools to Steal Cloud Credentials
FBI says TeamPCP poisoned trusted developer tools to steal cloud credentials, spread malware through software updates, and extort victims. On July 2, 2026, the FBI published a FLASH alert identifying the criminal group called TeamPCP and detailing how it compromised widely used developer and security tools to steal credentials from victim environments at scale. The…
-
The Anatomy of a Shadow AI Supply-Chain Breach: Lessons from the 2026 Vercel Incident
Vercel breach happened after an employee used an unvetted AI tool. Attackers exploited it as a trusted link to access systems, steal data, and extort $2M. The Vercel breach of April 2026 did not begin with a classic zero-day exploit, a misconfigured cloud bucket, or a sophisticated nation-state infrastructure implant. Instead, it unfolded when an…
-
FBI Says TeamPCP Uses Trojanized Updates to Steal Cloud Tokens, SSH Keys, and Kubernetes Secrets
Tags: access, advisory, attack, cloud, cyber, cybercrime, exploit, group, kubernetes, software, supply-chain, updateThe Federal Bureau of Investigation (FBI) has issued an urgent FLASH advisory warning that the cybercriminal group TeamPCP is weaponizing trojanized software updates to harvest cloud access tokens, SSH keys, and Kubernetes secrets at scale. This campaign represents one of the most sophisticated software supply chain attacks observed in 2026, exploiting trust in widely deployed…
-
Datensicherung und Cloud-Verschlüsselung – FAST LTA startet Data-Protection-Kooperation mit Eperi
First seen on security-insider.de Jump to article: www.security-insider.de/fast-lta-startet-data-protection-kooperation-mit-eperi-a-1bcc90f56c1c46591667da9addf5dc93/
-
VMware Licensing Changes and Their Impact on Infrastructure Modernization
Explore how VMware licensing changes are influencing infrastructure modernization, cloud strategy, and AI readiness, and what enterprises should evaluate next. First seen on hackread.com Jump to article: hackread.com/vmware-licensing-changes-infrastructure-modernization/
-
JADEPUFFER Agentic Ransomware Uses LLM to Automate Database Extortion
The first instance of agentic ransomware: JADEPUFFER, an LLM-driven extortion operation that automated an end-to-end database-crippling campaign. The actor gained execution on an internet-facing Langflow instance via CVE-2025-3248, used the AI-host environment to harvest cloud and API credentials, and pivoted into a production MySQL/Nacos deployment to carry out a destructive, database-focused extortion playbook without a…
-
Infinigate beruft Kai Grunwitz zum Chief Growth Officer
Die Infinigate Group, führende Technologieplattform und Trusted-Advisor in den Bereichen Cybersicherheit, Cloud und Netzwerkinfrastruktur, hat Kai Grunwitz zum Chief Growth Officer (CGO) ernannt. Damit unterstreicht der Value-Added-Distributor sein Ziel, die Wachstumsstrategie weiter zu skalieren und den Mehrwert für Hersteller und Channel-Partner zu steigern. Als CGO wird Grunwitz die zentralen Wachstumsfelder des Unternehmens verantworten: die Stärkung…
-
Cloud-Firewalls von Check Point über AWS-European-Sovereign-Cloud verfügbar
Check Point gibt bekannt, dass das Unternehmen nun Partner der AWS-European-Sovereign-Cloud ist. Die Cloud-Firewalls von Check Point sind nun in der AWS-European-Sovereign-Cloud verfügbar und unterstützen damit Kunden in Europa noch besser. Die Lösungen von Check Point bieten präventive Sicherheit über Netzwerk-, Workload- und Anwendungsebenen hinweg und gewährleisten die gleiche Verfügbarkeit und Leistung, die Kunden von…
-
Mitigating Attacks Before They Impact Infrastructure: Link11 provides next generation network DDoS protection
Frankfurt am Main, Deutschland, July 1st, 2026, CyberNewswire Link11, a leading European provider of cloud-based cybersecurity solutions, today announced the launch of its completely rebuilt Layer 3/4 DDoS mitigation solution, designed to address the growing complexity of modern network attacks. Today’s DDoS attacks are not just simple volume or protocol attacks anymore. They can originate…
-
Mitigating Attacks Before They Impact Infrastructure: Link11 provides next generation network DDoS protection
Frankfurt am Main, Deutschland, July 1st, 2026, CyberNewswire Link11, a leading European provider of cloud-based cybersecurity solutions, today announced the launch of its completely rebuilt Layer 3/4 DDoS mitigation solution, designed to address the growing complexity of modern network attacks. Today’s DDoS attacks are not just simple volume or protocol attacks anymore. They can originate…
-
Modulares Hacking-Framework kompromittiert Cloud-Dienste – PCPJack stiehlt Cloud-Zugangsdaten und verdrängt Konkurrent TeamPCP
First seen on security-insider.de Jump to article: www.security-insider.de/pcpjack-cloud-zugangsdaten-teampcp-worm-framework-a-ec0ce66f55711a11b9f3b6e88c141e81/
-
How Agentic AI Is Reshaping the Modern SOC
Agentic AI is redefining security operations by embedding intelligence across detection, investigation and response. Optiv’s Ben Spencer and Google Cloud’s Wayne Kearns explain how AI-powered SOCs strengthen defense, why human expertise is essential and how MSSPs can accelerate enterprise adoption. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/interviews/how-agentic-ai-reshaping-modern-soc-i-5554
-
SimpleHelp Flaw Exploited to Deploy Malware Targeting Windows, macOS, and Linux
A SimpleHelp authentication flaw is being exploited to deploy Djinn Stealer, a cross-platform malware targeting cloud, developer, and AI credentials. The post SimpleHelp Flaw Exploited to Deploy Malware Targeting Windows, macOS, and Linux appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-simplehelp-flaw-djinn-stealer-developer-credentials/
-
Singpass to roll out passkeys in fight against phishing scams
The passwordless feature will launch for iPhone users on 1 July 2026 with a device-bound model to avoid the security risks of cloud-synced passkeys First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366645129/Singpass-to-roll-out-passkeys-in-fight-against-phishing-scams
-
Digitale Souveränität für regulierte Organisationen
Mit <> will Omada europäischen Unternehmen die vollumfängliche Kontrolle darüber bieten, wo und wie ihre Identity-Governance bereitgestellt wird. Mit herkömmlicher Cloud-Bereitstellung sind besonders gesetzlich stark regulierte Unternehmen nicht mehr in der Lage, die Anforderungen an digitale Souveränität und regulatorische Kontrolle zu erfüllen. Omada-Identity-Sovereign wurde entwickelt, um genau diesen Bestimmungen und den damit verbundenen […] First…
-
Veraltete Software in Container-Images Die unsichtbare Angriffsfläche in deutschen Cloud-Umgebungen
Container-Technologien sind in deutschen Unternehmen längst zum Standard geworden: Laut aktuellen Marktdaten nutzen 79 % aller Unternehmen Kubernetes für das Management ihrer Cloud-Anwendungen, und Gartner prognostiziert, dass bis 2027 mehr als 90 % der Unternehmen weltweit containerisierte Anwendungen in der Produktion betreiben werden. Gleichzeitig warnen 42 % der DevOps- und Sicherheitsfachleute, dass Sicherheit die größte…
-
WSL containers now build and run Linux workloads on Windows
Containers power a large share of cloud-native applications, AI workloads, and testing and deployment pipelines. Developers working on Windows have long pulled in third-party … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/06/30/microsoft-linux-wsl-containers/

