Cloud Security — Page 2

Salesforce Cuts Klue Battlecards Tie-In After OAuth Token Compromise
The CRM giant pulled the competitive-intelligence app's integration on June 11 following a security incident that exposed connected customer data.

Microsoft's Email Security Claims Under Scrutiny: Experts Weigh In
Microsoft's latest data suggests a single-vendor approach may be enough for email security, but experts urge caution.

'Pickle in the Middle': Vertex AI SDK Bug Let Outsiders Hijack Model Uploads
Unit 42 researchers describe a bucket-squatting flaw in Google's Python SDK that handed code execution inside Vertex AI's serving stack to attackers with no project access.

TrustCloud Wants to Kill the Security Questionnaire. Here's the Pitch.
Continuous analysis of security, infrastructure, and governance data sounds compelling. Whether it replaces the questionnaire grind depends on what 'real-time' actually means at the data layer.

Wazuh Cloud Pitches Managed SIEM as Answer to Analyst Burnout
The open-source XDR vendor is leaning on hosted infrastructure and AI-assisted triage to chip away at alert fatigue in hybrid environments.

PCPJack Turns 230 Hijacked Cloud Servers Into a Stealth SMTP Relay Grid
Compromised AWS, Google Cloud, and Azure instances were quietly converted into verified mail relays and resold downstream every five minutes.

AI Workloads Are Breaking the Public-Cloud Default
Cost pressure and data sensitivity are pushing enterprises back toward private infrastructure — and the provider landscape isn't standing still while they decide.

The Real Bottleneck in Network Incidents Isn't Detection — It's Everything After
Monitoring catches the spike in seconds. Then the Slack thread starts, and the clock keeps running.

IBM and Red Hat Pledge $5 Billion to Lock Down Open Source Supply Chains via Project Lightwell
The initiative targets a deceptively hard problem: patching vulnerabilities in open source dependencies without breaking production workloads that millions of systems depend on.

The Data You Don't Know You Have Is the Data That Will Burn You
DSPM tools are selling fast and consolidating faster — here's why security teams are scrambling to find the data they forgot existed.

CISA Contractor Spent Six Months Treating GitHub as a Personal Dropbox
A Nightwing employee's public 'Private-CISA' repo leaked AWS GovCloud admin keys, plaintext passwords and the agency's internal build pipeline — with secret-scanning deliberately switched off.

CISA Contractor's Public GitHub Repo Spilled GovCloud Keys for Months; Lawmakers Want Answers
An RSA private key tied to the CISA-IT GitHub organization sat in a public 'Private-CISA' repo since November 2025. The agency is still rotating credentials.