#cloud-security
127 stories taggedcloud-security · page 8 of 9.

One Person, 72 Hours, One Wrecked AWS Account: How AI Handed a Lone Criminal the Keys to a Global Enterprise
Incident-response firm Sygnia says a single attacker used AI to tear through a major cloud environment at a pace that would normally require a full criminal crew. The unnamed victim was extorted.

The 13 security certifications paying the biggest salary premiums right now
New data from Foote Partners ranks the credentials that translate most directly into a bigger pay cheque, from a $165 Microsoft exam to a portfolio qualification that can cost tens of thousands of dollars.

Google Chatbot Flaw Let Attackers Hijack Other Bots and Read User Chats
A bug in Google Dialogflow CX, patched after a Varonis report, could have let one rogue chatbot spy on and puppet others sharing the same cloud project.

A 16-Year-Old Flaw in Linux's Virtual Machine Engine Lets Guests Break Into Their Host
Januscape (CVE-2026-53359) sits in shared code used on both Intel and AMD servers, and a public demo already crashes the host machine.

The Automation Nobody Reviewed: How AI-Built Workflows Are Quietly Leaking Enterprise Data
A developer asked an AI to speed up a document approval process. It worked perfectly and exposed sensitive HR files to hundreds of colleagues. This is happening across businesses right now.

How One HR Giant Cut Its Security Bill by $250,000 — by Deleting Data It Never Needed
Vensure Employer Solutions was drowning in its own security logs. AI-assisted filtering cut costs, halved response times, and proved that collecting less can mean detecting more.

AI-Generated Code Is Outpacing Your Audit Process
CISOs are discovering that traditional software audits weren't built for a world where a developer can generate 500 lines of Go in forty seconds. The checklist needs to change now.

Unpatched Argo CD Flaw Turns Your GitOps Engine Into a Deployment Backdoor
A gRPC endpoint that skips authentication, network policies off by default, and Redis credentials sitting in the environment. Synacktiv's research shows how one compromised pod can become a supply-chain pivot.

The 2026 Vendor Survey Nobody Asked For, Except The Findings Actually Track
The Bitdefender Cybersecurity Assessment polled 1,200 practitioners and concluded awareness is up and resilience is flat. Anyone running production already knew that.

Detection Engineering Grew Up. Most Security Stacks Didn't.
Behavior-based, CI/CD-integrated detection logic is eating vendor-supplied rules. What's actually driving the shift, and what teams still get wrong.

Azure CLI Under Sustained IPv6 Password Spray; 78 Tenants Breached
Automated spray campaign from a single ASN burned through 81 million auth attempts in two weeks, hitting az login endpoints from an unusual IPv6 range.

Bash Shell Tricks From the '90s Are Breaking AI Coding Agents Wide Open
Old-school shell injection techniques can bypass safeguards in most open-source AI coding agents, and a poisoned repo is all it takes to start the chain.

Compliance Theatre Has a Reckoning Coming. FedRAMP 20x Is the Opening Act.
Most SOC 2 and ISO 27001 reports audit a curated version of history, not operational reality. A federal cloud-security overhaul is forcing the question nobody wanted to answer: does passing audits actually mean anything?

AI-SPM Is Now a Real Category. Here's Why Your Organization Probably Needs It.
More than half of enterprise AI agents run without security oversight or logging. A maturing class of AI security posture management tools exists to fix that, if you know what to look for.

Dify AI Platform Carried Multi-Tenant Flaws Exposing Private Chats and Internal APIs
Cross-tenant data leakage vulnerabilities in Dify's cloud service let attackers read other users' conversations, preview documents, and probe internal API endpoints.