#cloud-security
128 stories taggedcloud-security · page 3 of 9.

Why Security Teams Are Ditching the Quarterly Scan for Something That Never Stops
A growing number of organisations are replacing old-school vulnerability scanning with a continuous approach called CTEM. The idea sounds simple. The culture change is anything but.

When Google Workspace gets breached, the door is usually already open
Most Workspace break-ins start with a tricked employee or a forgotten app connection, not a clever hack. Here is what actually happens in the first hours, and what stops the damage.

ShinyHunters dumps 12.9 million Carhartt customer records after ransom refusal
The extortion crew says it grabbed 50GB from the workwear brand's Databricks cloud analytics platform. Carhartt walked away from a $3.3 million demand, and the data is now public.

AI Security Tools Are Only as Good as the Data You Feed Them
Security teams are pouring money into AI-powered defences while quietly starving those systems of the data they need. The result is a blind spot that criminals are already walking through.

Snowflake kills passwords for service accounts. The cleanup starts now.
The cloud data giant is retiring password logins for machine accounts. Working out what those accounts actually do is the real headache.

Chip Giants Are Racing to Build Quantum-Proof Encryption Into Hardware
Intel, Nvidia, and IBM are baking next-generation encryption into silicon before quantum computers can crack today's secrets. The window to act is already closing.

Two SOCs, Same Attack: CISA Red Team Walks Through One Network, Gets Caught in the Other
CISA ran identical red team drills against a government agency and a water utility. One let the attackers roam for weeks. The other spotted them within hours.

9,300 leaked AWS keys still work, and 768 hand over full control of a company's cloud
Truffle Security tracked exposed Amazon cloud keys for four years. Most were never rotated, and 88% still logged in on the day of testing.

Microsoft Pushes 22 Security Fixes, Six Rated Maximum Severity
A batch of patches covers Microsoft's cloud and identity products, with six flaws scoring a perfect 10 out of 10 on the severity scale. Most fixes apply automatically, but one Defender vulnerability is still waiting for a patch.

Microsoft Confirms Critical Entra ID Flaw Was Exploited, Says No Customer Action Needed
Redmond patched a perfect-10 remote code execution bug in its cloud identity service and says the fix was applied on its side.

A Flaw in N-able's Passportal Handed Any Malicious Website the Keys to Every Password a Business Stored
A researcher found that Passportal's browser extension trusted every message it received without question, letting any webpage silently drain a company's entire vault of login credentials.

Airlock Digital Passes Australia's Toughest Government Security Check
The Australian application control firm has cleared an independent IRAP assessment at PROTECTED level, giving government and critical-infrastructure buyers one more piece of evidence for their due-diligence files.

Sakura Internet Says Breach May Have Exposed 1.36 Million Customer Accounts
The Japanese cloud provider, a chosen supplier for Japan's Government Cloud, found the wider intrusion while investigating a smaller hack of its rental server service.

Researchers pull a login token out of Cloudflare's edge with a browser-era ghost bug
A Spectre-style side-channel attack ran inside one Cloudflare Worker and quietly read data from another sitting on the same machine, at speeds fast enough to lift a JSON Web Token in seconds.

Hackers Are Actively Attacking MLflow and FUXA to Steal Cloud Secrets
Two open-source tools used by AI teams and factory operators are being scanned and broken into in the wild, with attackers using one flaw to grab cloud login keys.