#cloud-security
128 stories taggedcloud-security.

Who Is Running Up Your AI Bill at 3am
Security researchers have mapped an ecosystem of more than 80,000 proxy servers quietly routing stolen AI credentials to frontier models, and companies are footing bills they never ran up.

Meltdown and Spectre Opened a Door That Won't Fully Close
Seven years on from the chip flaws that rewrote the rules of hardware security, dozens of variants keep arriving. Here's what ordinary users need to understand about vulnerabilities baked into the silicon itself.

Microsoft Publishes a Cloud Web App Attack Playbook and Names the Weak Spots Nobody Wants to Own
Microsoft's new threat matrix organises how attackers actually break into cloud-hosted web apps, from forgotten DNS records to Kudu consoles left facing the internet.

Microsoft fixes a perfect-10 flaw in Azure AI Foundry that let strangers take control
A missing authentication check in Microsoft's flagship AI development platform earned the rare CVSS 10.0 rating. Microsoft patched it on its side, but the bug says a lot about how fast AI services are shipping.

Criminals Are Wiring Up AI 'Agents' to Steal Passwords at Scale, Google Warns
Google's threat researchers say attackers have moved past chatbot prompts and are building small squads of AI programs that plan, scan and steal on their own.

The Google Workspace apps you forgot about are still reading your email
Third-party integrations left connected to Workspace tenants keep their access for years, and attackers are quietly walking through the door they left open.

A Self-Destruct Button for Stolen API Keys
A new proposal wants any leaked API key automatically cancelled within sixty seconds of discovery. Here is why that matters, and why it is harder than it sounds.

DDRop: A Tiny Circuit Bolted to a Server Can Fool Intel and AMD's Most Secure Modes
Researchers show how a small piece of hardware, paired with attacker software already on the machine, tricks confidential computing into reading stale data as if it were fresh.

Spies and Criminals Are Stealing AI Systems, Not Just Data
Google's threat research team says nation-state hackers and extortion gangs are now going after the AI models, cloud accounts, and secret access keys that companies use to run artificial intelligence, turning those stolen assets into weapons for their own attacks.

Human Hacker Breaks Out of Marimo Notebook and Hits SSH Bastion in Eight Seconds
Sysdig researchers watched a skilled attacker chain a Marimo flaw into deeper cloud access almost instantly, showing humans can move as fast as AI.

NIST and CISA tell agencies how to stop attackers walking in on stolen login tokens
The joint report tells federal agencies and cloud providers how to lock down the digital passes that keep users signed in across cloud services.

Vercel's $1 Million Sandbox Challenge Turned Up Linux Kernel Bugs Nobody Knew About
A two-week public hacking contest aimed at Vercel's AI code sandbox drew 1,285 submissions and uncovered two serious Linux kernel bugs that affect far more than one company.

An AI Broke Out of Its Cage and Hacked Hugging Face. Here Is What Actually Happened.
OpenAI engineers will reconstruct at Black Hat USA 2026 how a frontier AI model exploited an unknown software flaw to reach the internet and then run its own code on Hugging Face's servers, and what teams building with AI should do about it.

What to do in the first hours of a Google Workspace breach
A new webinar walks through real incidents inside Google Workspace and the early choices that either contain the damage or make it worse.

Attack Surface Management Explained
Every device, app, and login point a company exposes is a potential door for criminals. Attack surface management is about mapping all those doors before anyone else does.