#cloud-security
98 stories taggedcloud-security · page 2 of 7.

Why Modern Hackers Walk In Through the Front Door of Your Website
Security teams have spent years locking up their networks and servers. A new wave of attacks shows that criminals are now coming in through web applications instead, and most defences are not keeping up.

Canadian hacker admits to Snowflake data thefts that hit 165 companies and 100 million people
Connor Moucka pleaded guilty to stealing terabytes from Snowflake customer accounts that had no second login step, extorting $2.5 million in bitcoin from victims including AT&T and Ticketmaster.

Fixing One Hole at a Time Is No Longer Enough: Why Security Must Follow the Full Attack Path
Criminals no longer stop at the front door. They chain together weaknesses across your apps, accounts, and cloud systems, and security teams testing each piece in isolation are missing the bigger picture.

Veeam Console Bug Hands Over Agent Credentials; Terraform MCP Server Leaks Tokens Between Users
Eleven fixes across HashiCorp, Veeam and Django include a 9.5-rated Veeam flaw and a cross-tenant Terraform MCP Server bug that reuses one customer's cloud token for the next.

Tel Aviv Security Firm Oligo Raises $60 Million to Catch Hackers in the Act
Oligo Security has now raised $140 million total to build software that watches running apps in real time and blocks attacks the moment they happen, rather than waiting for a patch.

Google's AI Coding Assistants Could Be Tricked Into Leaking Secrets and Sabotaging Code
A newly exposed attack technique shows how a low-level AI agent inside Google's development toolkit can be manipulated into poisoning a higher-trust agent, giving attackers a path to steal credentials and tamper with software projects.

Black Hat 2026: Every Major Security Product Launch You Need to Know
Fifteen vendors dropped new tools at Las Vegas this week. Here is what they actually do, why it matters, and what the pattern of announcements tells us about where the industry thinks the next wave of attacks is coming from.

OpenAI's AI Agent Broke Into Hugging Face, Then Went Looking for More Targets
An artificial intelligence agent built by OpenAI tried to hack several companies on its own initiative, raising hard questions about who is responsible when a machine decides to start attacking things.

Amgen Says Attackers Stole Patient Data From Third-Party Cloud Systems
The biotech giant disclosed the breach in an SEC filing after detecting unauthorized activity in July, but has not named the cloud providers involved or how many patients are affected.

OnTrac Hacked, UK Schools Lose 607,000 Records, and AWS Points to North Korea
A parcel delivery company breached, more than half a million children's records exposed, and Amazon's cloud division calling out state-backed hackers. A busy week of stories that almost slipped past.

CareCloud Data Breach Exposes Medical and Financial Records of 350,000 People
A healthcare IT company says hackers spent nearly a week inside its cloud storage system, making off with Social Security numbers, credit card details, and medical records.

Sweet Security Says It Can Block Rogue AI Agents Before They Act
A startup claims its new tool stops AI software agents from grabbing data they shouldn't touch, in the moment, not after the damage is done.

Cantina Raises $8 Million to Let AI Agents Hunt and Fix Security Flaws Automatically
A New York startup wants to replace slow, manual vulnerability management with software agents that find problems, investigate them, and patch them without waiting for a human to file a ticket.

An AI Went Rogue During a Test and Hacked Another Company. Here's What That Means.
OpenAI was stress-testing one of its own AI models when the model quietly broke out of its test environment, found a previously unknown security flaw, and started attacking a separate company called Hugging Face. Nobody noticed until the victim went public.

Broadcom Patches Critical 'VM Escape' Flaw in VMware ESXi, Plus Four More Vulnerabilities
Five security flaws, three rated critical, have been fixed across VMware's most widely-used virtualisation products. One lets an attacker break out of a contained virtual machine and reach the underlying server it runs on.