#cloud-security
128 stories taggedcloud-security · page 5 of 9.

One Developer Password Unlocked Everything: Inside a Healthcare Software Provider's Wake-Up Call
A company that thought its segmented cloud setup was secure ran a simulated attack and watched a single stolen developer credential unravel four years of layered defences in minutes.

What 300,000 Real-World Security Tests Taught One Company About AI Hacking Tools
Autonomous penetration testing has reached genuine scale. The hard lesson from running 300,000 tests isn't about finding weaknesses. It's about knowing which ones actually matter.

Criminals Are Using AI Like a Work Tool. Researchers Have the Receipts.
Two major studies show hackers using AI assistants to write malicious code, dodge safety filters, and compress attacks from weeks into hours. Cloud activity tied to this shift jumped 171 percent in the first half of 2026.

Why Modern Hackers Walk In Through the Front Door of Your Website
Security teams have spent years locking up their networks and servers. A new wave of attacks shows that criminals are now coming in through web applications instead, and most defences are not keeping up.

Canadian hacker admits to Snowflake data thefts that hit 165 companies and 100 million people
Connor Moucka pleaded guilty to stealing terabytes from Snowflake customer accounts that had no second login step, extorting $2.5 million in bitcoin from victims including AT&T and Ticketmaster.

Fixing One Hole at a Time Is No Longer Enough: Why Security Must Follow the Full Attack Path
Criminals no longer stop at the front door. They chain weaknesses across apps, accounts, and cloud systems, and security teams testing each piece in isolation are missing the bigger picture.

Veeam Console Bug Hands Over Agent Credentials; Terraform MCP Server Leaks Tokens Between Users
Eleven fixes across HashiCorp, Veeam and Django include a 9.5-rated Veeam flaw and a cross-tenant Terraform MCP Server bug that hands one customer's cloud token to the next caller.

Tel Aviv Security Firm Oligo Raises $60 Million to Catch Hackers in the Act
Oligo Security has now raised $140 million total to build software that watches running apps in real time and blocks attacks the moment they happen, rather than waiting for a patch.

Google's AI Coding Assistants Could Be Tricked Into Leaking Secrets and Sabotaging Code
A newly exposed attack technique shows how a low-level AI agent inside Google's development toolkit can be manipulated into poisoning a higher-trust agent, giving attackers a path to steal credentials and tamper with software projects.

Black Hat 2026: Every Major Security Product Launch You Need to Know
Fifteen vendors dropped new tools at Las Vegas this week. SecurityWeek's roundup captured the announcements; here is what they actually do and what the pattern tells us about where the industry thinks attacks are headed.

Amgen Says Attackers Stole Patient Data From Third-Party Cloud Systems
The biotech giant disclosed the breach in an SEC filing after detecting unauthorized activity in July, but has not named the cloud providers involved or how many patients are affected.

OnTrac Hacked, UK Schools Lose 607,000 Records, and AWS Points to North Korea
A parcel delivery company breached, more than half a million children's records exposed, and Amazon's cloud division naming state-backed hackers. Stories that almost slipped past.

CareCloud Data Breach Exposes Medical and Financial Records of 350,000 People
A healthcare IT company says hackers spent nearly a week inside its cloud storage system, making off with Social Security numbers, credit card details, and medical records.

Sweet Security Says It Can Block Rogue AI Agents Before They Act
A startup claims its new tool stops AI software agents from grabbing data they shouldn't touch, in the moment, not after the damage is done.

Cantina Raises $8 Million to Let AI Agents Hunt and Fix Security Flaws Automatically
A New York startup wants to replace slow, manual vulnerability management with software agents that find problems, investigate them, and patch them without waiting for a human to file a ticket.