#cloud-security
128 stories taggedcloud-security · page 4 of 9.

TWINLOOT Malware Hides Inside Microsoft's Own Cloud to Steal Passwords
A newly discovered piece of malicious software uses Microsoft SharePoint, Teams, and Edge to run its operation, making it nearly invisible to the tools most companies rely on.

Heights Finance Data Breach Hits 1.2 Million Borrowers
A consumer lender's cloud storage platform was broken into, exposing Social Security numbers, bank account details and driver's licence numbers for more than 1.2 million past and present customers.

Your Team's Slack Messages During a Breach Could Cost More Than the Breach Itself
The panicked notes, the finger-pointing threads, the 'we knew about this' one-liners: what your staff types in the first 24 hours of a cyber incident can become courtroom evidence. Here is why that matters, and what to do before the subpoena arrives.

OAuth Tokens Are Quietly Becoming the Skeleton Key to Google Workspace
Phishing gets the headlines, but stolen app tokens can open Gmail and Drive without ever tripping a login alert.

A Leaked Password Let Hackers Drain the Donor Databases of More Than 1,000 UK Charities
Beacon, a software company that helps charities manage their supporters, left an access key exposed in public code. Criminals found it, used it, and likely walked off with every record in the system.

Hackers Are Already Probing a Dangerous, Unpatched Flaw in GeoServer
A newly public security hole in popular mapping software drew hundreds of attack attempts within hours. No fix exists yet.

Ransomware Hit Colombia's Justice Ministry Five Days Before a New President Took Office
Files were encrypted, services went down, and ColCERT had warned about exactly this kind of attack the day before. What happened, and why Colombia keeps ending up in the crosshairs.

Hackers Used Guest Access to Quietly Steal Data From Salesforce and ServiceNow
A newly spotted campaign, tracked as 'City-Forum', used anonymous login features built into two widely used business platforms to map and copy out sensitive data, no stolen password required.

The software wrapper around your AI agent is the real security risk
Researchers broke into official AI automation tools from Anthropic, Google, and OpenAI, not by tricking the AI itself, but by exploiting the ordinary code that connects it to the real world.

A New Security Startup Says AI Chips Have a Blind Spot. It Wants to Fix That.
Stealthium is building tools to spot attacks hiding inside the specialised computer chips that power artificial intelligence, a corner of corporate IT that most security software cannot see.

Four Million Fake App IDs, One Blind Spot: How Hackers Are Slipping Past Microsoft Login Defences
Two criminal campaigns sent over four million spoofed application identities at Microsoft's sign-in system and barely triggered an alert. Here is what happened, who is at risk, and what security teams can do.

Open source grew up in a hurry, and the security bill is coming due
The world runs on free code written by strangers. That model is finally hitting its limits, and everyone using cloud services is exposed.

Criminals Poisoned a Python Package Downloaded 95 Million Times a Month. AI Developers Were the Target.
On 24 March 2026, attackers slipped malicious code into LiteLLM, a software tool used by AI developers worldwide. Three hours online was enough to reach tens of thousands of companies.

Microsoft and Apple Rush Out Patches for Flaws That Let Attackers In Without a Password
Several of the Microsoft bugs score a perfect 10 out of 10 for severity. Apple quietly fixed a flaw that lets someone access your screen without logging in.

AI Is Making Data Breaches More Expensive. Here's What the Numbers Actually Say.
IBM's 2026 Cost of a Data Breach report puts the average global figure at $6 million, up 35% on last year, with one in four malicious incidents now involving AI-powered techniques.