Cloud Security

Your Company Uses Hundreds of Cloud Apps. Security Teams Can See Inside Almost None of Them.
Three real breaches show how misconfigured software-as-a-service tools leak customer records, private messages, and source code, all without anyone breaking down a single door.

Risk Ledger Raises £24 Million to Expand Its Supply Chain Security Network
The London firm wants more organisations checking each other's security hygiene in one shared space. Now it has the money to push into the US and build AI review tools.

Cloud Security Professionals Gather Virtually to Tackle Shared Threats
A summit for security teams wrestling with cloud and data protection brings together practitioners and vendors, here is why these conversations matter to anyone whose data lives online.

The 'Approval Gap' in Ad Tech: When Marketing Tags Smuggle in Unknown Code
A single approved script on your website can quietly pull in code from vendors your security team has never heard of. Here is why that matters.

CISA Left AWS GovCloud Keys on GitHub for Six Months, Ignored Nine Alerts
The US cyber agency's own postmortem admits it missed automated warnings, muddled its reporting channels, and took two days to rotate leaked admin credentials.

One Person, 72 Hours, One Wrecked AWS Account: How AI Handed a Lone Criminal the Keys to a Global Enterprise
Security firm Sygnia says a single attacker used artificial intelligence to tear through a major cloud environment at a pace that would normally require a full criminal crew. The unnamed victim was extorted.

GitHub's Green 'Verified' Badge Can Lie: Signed Commits Cloned Without the Key
Researchers show anyone can produce a second signed commit that matches the author, date and files of a real one, keeping GitHub's Verified stamp while changing the unique fingerprint developers rely on.

Google Chatbot Flaw Let Attackers Hijack Other Bots and Read User Chats
A bug in Google Dialogflow CX, patched after a Varonis report, could have let one rogue chatbot spy on and puppet others sharing the same cloud project.

Microsoft Begins Testing Cloud Rebuild, a Remote Reinstall Tool for Broken Windows 11 PCs
The feature, part of Microsoft's Windows Resiliency Initiative, downloads a fresh copy of Windows and drivers from the cloud even when the machine won't boot. It is available now to Insiders on the Experimental channel.

How One HR Giant Cut Its Security Bill by $250,000 — by Deleting Data It Never Needed
Vensure Employer Solutions was drowning in its own security logs. An AI-powered clean-up cut costs, halved response times, and proved that more data isn't always safer.

Microsoft Pulls Post-Quantum Deadline Forward to 2029
Azure CTO Mark Russinovich says the 'risk horizon' has moved. Redmond now wants PQC-ready systems four years ahead of the industry's 2033 target.

Detection Engineering Grew Up. Most Security Stacks Didn't.
Behavior-based, CI/CD-integrated detection logic is eating vendor-supplied rules. Here's what's actually driving the shift — and what teams still get wrong.

Azure CLI Under Sustained IPv6 Password Spray; 78 Tenants Breached
Automated spray campaign from a single ASN burned through 81 million auth attempts in two weeks, hitting az login endpoints from an unusual IPv6 range.

AWS Continuum Wants to Close the Gap Between AI-Generated Code and AI-Fixed Vulnerabilities
Amazon's new agentic security service promises continuous discovery, triage, and remediation. In practice, it's a bet that the same AI acceleration creating your backlog can also drain it.

Salesforce Cuts Klue Battlecards Tie-In After OAuth Token Compromise
The CRM giant pulled the competitive-intelligence app's integration on June 11 following a security incident that exposed connected customer data.