#cloud-security
98 stories taggedcloud-security.

OAuth Tokens Are Quietly Becoming the Skeleton Key to Google Workspace
Phishing gets the headlines, but stolen app tokens can open Gmail and Drive without ever tripping a login alert.

A Leaked Password Let Hackers Drain the Donor Databases of More Than 1,000 UK Charities
Beacon, a software company that helps charities manage their supporters, left an access key exposed in public code. Criminals found it, used it, and likely walked off with every record in the system.

Hackers Are Already Probing a Dangerous, Unpatched Flaw in GeoServer
A newly public security hole in popular mapping software is drawing hundreds of attack attempts within hours. No fix exists yet.

Ransomware Hit Colombia's Justice Ministry Five Days Before a New President Took Office
Files were encrypted, services went down, and ColCERT had warned about exactly this kind of attack the day before. Here is what happened, and why Colombia keeps ending up in the crosshairs.

Hackers Used Guest Access to Quietly Steal Data From Salesforce and ServiceNow
A newly spotted campaign, tracked as 'City-Forum', used anonymous login features built into two widely used business platforms to map and copy out sensitive data, no stolen password required.

The software wrapper around your AI agent is the real security risk
Researchers broke into official AI automation tools from Anthropic, Google, and OpenAI, not by tricking the AI itself, but by exploiting the ordinary code that connects it to the real world.

A New Security Startup Says AI Chips Have a Blind Spot. It Wants to Fix That.
Stealthium is building tools to spot attacks hiding inside the specialised computer chips that power artificial intelligence, a corner of corporate IT that most security software cannot see.

Four Million Fake App IDs, One Blind Spot: How Hackers Are Slipping Past Microsoft Login Defences
Two criminal campaigns sent over four million spoofed application identities at Microsoft's sign-in system and barely triggered an alert. Here is what happened, who is at risk, and what security teams can do about it.

Open source grew up in a hurry, and the security bill is coming due
The world runs on free code written by strangers. That model is finally hitting its limits, and everyone using cloud services is exposed.

Criminals Poisoned a Python Package Downloaded 95 Million Times a Month. AI Developers Were the Target.
On 24 March 2026, attackers slipped malicious code into LiteLLM, a software tool used by AI developers worldwide. Three hours online was enough to reach tens of thousands of companies.

Microsoft and Apple Rush Out Patches for Flaws That Let Attackers In Without a Password
Several of the Microsoft bugs score a perfect 10 out of 10 for severity. Apple quietly fixed a flaw that lets someone access your screen without logging in.

AI Is Making Data Breaches More Expensive. Here's What the Numbers Actually Say.
A new IBM report puts the average global cost of a data breach at $6 million for 2026, up 35% in a year, and for the first time, AI-powered attacks account for one in four of those incidents.

One Developer Password Unlocked Everything: Inside a Healthcare Software Provider's Wake-Up Call
A company that thought its segmented cloud setup was secure ran a simulated attack and watched a single stolen developer credential unravel four years of layered defences in minutes.

What 300,000 Real-World Security Tests Taught One Company About AI Hacking Tools
Autonomous penetration testing has reached genuine scale. The hard lesson from running 300,000 tests is not about finding weaknesses. It is about knowing which ones actually matter.

Criminals Are Using AI Like a Work Tool. Researchers Have the Receipts.
Two major studies show hackers using AI assistants to write malicious code, dodge safety filters, and attack in hours rather than weeks. Cloud activity tied to this shift jumped 171 percent in the first half of 2026.