#cloud-security
126 stories taggedcloud-security · page 6 of 9.

Your Security Team Is Flying Blind on AI. Here Is Why.
The tools built to catch hackers and bad code were designed for a world where humans made every decision. AI agents don't ask permission, and your defences weren't built to watch them.

The 'Ghost Credentials' Problem: How Forgotten Digital Keys Are Leaving Cloud Systems Wide Open
A sleeping AI agent that woke up and started making requests at odd hours led a security researcher to a sprawling mess of forgotten digital keys, and a free tool to help organisations find them before attackers do.

Infoblox Wants to Find Your Exposed Assets Before Hackers Do
The network security company is entering a crowded market with a twist: using its deep knowledge of the internet's address book to spot weaknesses rivals might miss.

Act Security Aims to Tackle Cloud Vulnerability Challenges with $60 Million in Funding
Act Security steps out of stealth to shrink the window between vulnerability discovery and exploitation, backed by $60 million and a team that's done this before.

Two Cloud Giants, Two Flaws, Zero Bug Bounties: The 'Confused Deputy' Problem That Won't Go Away
A security researcher found ways to silently hijack administrator control over both Microsoft Azure and Google Cloud infrastructure. Neither company paid a reward. One quietly fixed its flaw without saying so.

The Hackers Got Hacked: Inside the Klue Breach and What It Means for Every Business Using Cloud Software
A forgotten service account let criminals walk into a competitive-intelligence platform. Then a second criminal group stole the stolen data. The whole chain shows exactly how cloud software trust goes wrong.

A Single Default Setting in Azure Automation Could Have Let Hackers Steal Any Tenant's Cloud Identity
A researcher found that Microsoft's cloud automation service was, by default, leaving account identities visible to the public internet, giving any attacker a path to impersonate other organisations' privileged accounts.

AI Agents Are Breaking the Security Promises of Confidential Computing
A technology built to keep sensitive data locked away is running into a problem it was never designed for: AI assistants that cannot forget what they have read.

FedRAMP is scrapping the annual audit. Here's what 20X actually changes.
The old federal cloud approval process runs on PDFs and once-a-year checks. The replacement wants live proof that your controls are working, all the time.

What is zero trust? A plain-English guide
Zero trust means your network stops assuming anyone inside it is safe, and checks every user and device every single time.

When your AI helper has admin rights: the new ransomware fast lane
Enterprise AI assistants with over-broad permissions can turn a routine break-in into a company-wide ransomware event in minutes, Acronis warns.

Palo Alto Networks Is Buying Embrace to Watch How Real Users Experience Its Customers' Apps
The cybersecurity giant adds user-experience monitoring to its growing observability business, months after spending $3.35 billion on Chronosphere.

Bit2Watt: How a Regular Cloud Customer Could Wobble the Power Grid
Researchers at Zhejiang University say a paying cloud tenant with ordinary GPU access can swing a data centre's electricity draw hard enough to shake the grid, no hacking required.

HollowGraph Malware Hides Spy Commands Inside Microsoft 365 Calendar Entries
A newly identified piece of malware turns ordinary calendar appointments into a covert messaging system, letting criminals send instructions and steal files without ever touching a suspicious server.

A New Company Just Raised $100 Million to Put Guard Rails on AI Inside Big Businesses
Neo stepped out of secrecy this week with a nine-figure war chest and a pitch that enterprise AI, meaning the AI tools large companies use internally, is already running ahead of anyone's ability to control it.