Tag

#cloud-security

96 stories taggedcloud-security · page 6 of 7.

AI Security

Dify AI Platform Carried Multi-Tenant Flaws Exposing Private Chats and Internal APIs

Cross-tenant data leakage vulnerabilities in Dify's cloud service let attackers read other users' conversations, preview documents, and probe internal API endpoints.

2 min read
Cloud Security

AWS Continuum Wants to Close the Gap Between AI-Generated Code and AI-Fixed Vulnerabilities

Amazon's new agentic security service promises continuous discovery, triage, and remediation. In practice, it's a bet that the same AI acceleration creating your backlog can also drain it.

3 min read
Threat Intelligence

ShinyHunters Doesn't Need Malware. That's the Point.

The group's latest breaches are a reminder that stolen credentials and patience beat zero-days most days of the week.

2 min read
Vulnerabilities

Briefing: Apple Fixes Beats Bug, GCP Config Connector Flaw Enables Account Takeover, Velvet Ant's Decade in the Shadows

A Bluetooth eavesdropping patch, a quietly dangerous GCP misconfiguration vulnerability, and a threat actor that spent ten years undetected — here's what you may have missed.

2 min read
AI Security

The SOC Triangle Was Always a Lie We Accepted. AI Is Changing the Math.

Security operations have run on a structural compromise for decades — quality, consistency, or cost: pick two. That constraint is finally starting to bend.

3 min read
AI Security

SearchLeak Shows How a Single Crafted URL Can Drain Your M365 Tenant

Varonis researchers chained three weaknesses in Copilot Enterprise Search into a full data-exfiltration path. Microsoft patched it. The attack class isn't going anywhere.

3 min read
Vulnerabilities

Splunk Enterprise RCE Flaw Under Active Exploitation, CISA Gives Feds 72 Hours

CVE-2026-20253 allows unauthenticated remote code execution in Splunk Enterprise. Attackers didn't wait long.

2 min read
AI Security

Bucket Squatting in Vertex AI SDK Opened Cross-Tenant RCE Window

A staging-bucket naming flaw in two versions of Google's Vertex AI Python SDK let attackers pre-register a victim's expected bucket and swap in a malicious pickle model before the platform could retrieve the original.

2 min read
Vulnerabilities

The Exposures Defenders Will Be Cleaning Up in 2026

From memory-leak bugs like MongoBleed to forgotten admin panels, the attack surface keeps growing faster than patch cycles.

3 min read
Vulnerabilities

Oracle's June 2026 CPU: 245 Patches Across Communications, EBS, and Enterprise Manager

Oracle's second monthly Critical Patch Update ships a significant fix load. If you're running EBS or Enterprise Manager in AWS or on-prem, your change window just got scheduled for you.

2 min read
Cloud Security

TrustCloud Wants to Kill the Security Questionnaire. Here's the Pitch.

Continuous analysis of security, infrastructure, and governance data sounds compelling. Whether it replaces the questionnaire grind depends on what 'real-time' actually means at the data layer.

2 min read
AI Security

Poisoned Documents Can Freeze AI Agent Guardrails Dead in Their Tracks

Researchers found that a single malicious input can trap reasoning-based safety systems in extended thinking loops, slowing LangGraph deployments by 148x and starving co-located agents of resources.

2 min read
Identity & Access

Sovereign Cloud Gives You a Data Center. Identity Governance Gives You Control.

European enterprises spent two years and real money on sovereign cloud deployments. What they found is that data residency is the easy part — and that AI agent identities are the part nobody governed.

3 min read
Policy & Regulation

Voluntary AI Security Rules: The Industry Already Knows What That Means

Trump's AI cybersecurity executive order drew polite applause from vendors and quiet skepticism from practitioners. The gap between those two reactions is where the real story lives.

2 min read
Cloud Security

PCPJack Turns 230 Hijacked Cloud Servers Into a Stealth SMTP Relay Grid

Compromised AWS, Google Cloud, and Azure instances were quietly converted into verified mail relays and resold downstream every five minutes.

3 min read
© 2026 Threat Vectr