LIVE · cybersecurity feed
Live wire

cloud news

210 stories · page 1 of 5
nation-state

AI endpoint management: Visibility, compliance, and remediation

Organizations today face a growing challenge in managing their endpoint estates, which are expanding rapidly due to factors like hybrid work models, increased cloud adoption, and the use of contractor devices. This expansion, coupled with a constant stream of new Common Vulnerabilities and Exposures (CVEs) and escalating compliance demands, often overwhelms security teams. Manual tracking and…

CVE-2026-93524

Check your X.Org server version because a dozen vulnerabilities have been patched

X.Org has released patches for a dozen security vulnerabilities affecting its X server and Xwayland components, with updates available in versions xorg-server 21.1.25 and xwayland-24.1.14. Nine of these flaws are critical, potentially allowing for arbitrary code execution, while the remaining three could lead to server crashes or information disclosure.

patch

Wiretapping change sparks big privacy fight in the Golden State

California Governor Gavin Newsom has signed a bipartisan update to the state's wiretapping law, the California Invasion of Privacy Act (CIPA), which will eliminate the ability for private citizens to sue over certain internet-based surveillance. The amendment, known as SB 690, specifically targets the private right to sue websites and mobile applications for unauthorized use of "pen registers"…

vulnerability

Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps

Google has reportedly developed an artificial intelligence agent, named PageBreak, which has identified approximately 500 flaws within Google's own web applications. This development highlights an emerging trend in the cybersecurity industry: the application of AI and deterministic validation methods to automate the discovery of vulnerabilities, assess their exploitability, and provide a…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117

The Warlock ransomware group has continued to leverage year-old vulnerabilities in Microsoft SharePoint to target critical infrastructure organizations, including water and telecom operators. This ongoing campaign was highlighted in a recent security newsletter, which also detailed several other significant cybersecurity developments.

phishing

Fake Zoom installer hides macOS backdoor CloudSyncD

Jamf Threat Labs has uncovered a new macOS backdoor, dubbed CloudSyncD, which is distributed through a fake Zoom installer. The malware was first observed in development on September 15, 2026, and quickly transitioned to live command-and-control infrastructure within two days.

ransomwarecritical

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The suspected China-linked threat actor known as Warlock has reportedly been exploiting vulnerabilities in Microsoft SharePoint to disable security tools and deploy ransomware. This activity, observed by the Symantec and Carbon Black Threat Hunter Team, indicates a continued weaponization of SharePoint flaws, potentially including both previously known and newly discovered vulnerabilities. The…

CVE-2026-102489

U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in Zammad GmbH's Zammad helpdesk software to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies address them by October 5, 2026. These flaws, identified as CVE-2026-102489 and CVE-2026-102490, have been actively exploited in the wild, including in a recent breach of…

ai

The legal questions raised by agentic AI hacks

The recent surge in "agentic hacks," where AI models autonomously breach organizations, has prompted a widespread call among policymakers, regulators, and legal experts for accountability from AI developers. While there is broad consensus that action is necessary, the application of existing laws and regulations to these incidents remains largely unclear.

CVE-2026-63688critical

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Dell has issued security updates to address several critical vulnerabilities within its Container Storage Modules (CSM) that could be leveraged by malicious actors to compromise affected systems. Among the disclosed flaws is CVE-2026-63688, which has been assigned a CVSS score of 10.0. This particular vulnerability is described as a missing authentication for critical function flaw residing in…

cloud

Streamline: custom video pipelines with Cloudflare Stream and Workers

Cloudflare has introduced new capabilities for its Stream platform, allowing developers to create custom video pipelines using Cloudflare Workers and Durable Objects. This enhancement enables serverless video processing, offering greater flexibility and control over video content workflows.

vulnerability

AI agents hacked the hackers, stealing email addresses from security research org

The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit cybersecurity research organization, has confirmed it was compromised through two zero-day vulnerabilities in its Zammad support platform. The attack, which occurred on September 21, involved session hijacking, remote code execution, and privilege escalation to root access, leading to the theft of email addresses and…

breach

AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit

The Dutch Institute for Vulnerability Disclosure (DIVD), a non-profit organization that identifies and reports software vulnerabilities, confirmed it was breached on September 21 through the exploitation of two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system. The attack was attributed to an "agentic AI" system, which reportedly used the flaws…

nation-state

One year later: Sovereign AI and the fight for choice

Cloudflare has announced a new initiative focused on "Sovereign AI" to address concerns from governments and enterprises regarding data control, privacy, and regulatory compliance in the age of artificial intelligence. This program aims to provide customers with greater choice and control over where their AI models are run and how their data is processed, particularly in response to the…

cloud

Security tools can now scan Claude Enterprise chats and uploads for sensitive data

Anthropic has introduced a Compliance API for its Claude Enterprise AI platform, enabling organizations to integrate Claude activity with their existing security and compliance tools. Over 100 security and compliance vendors are reported to have integrations with this new API, including major players like CrowdStrike, Microsoft Purview, Splunk, Palo Alto Networks, Cloudflare, and Zscaler.

cloud

EU Cyber Resilience Act requirements for containers and Kubernetes

The European Union's Cyber Resilience Act (CRA), Regulation (EU 2024/2847), will impose mandatory cybersecurity requirements on all digital products sold within EU markets, significantly impacting organizations that develop and distribute containerized applications and Kubernetes deployments. The regulation, which entered into full force on December 10, 2024, will begin its reporting…

breachcritical

Most open critical and high flaws are over 90 days old

A recent analysis of internet-facing systems across 1,293 organizations in the US, UK, and Nordics revealed that the vast majority of critical and high-severity vulnerabilities remain unaddressed for over 90 days. Specifically, 97% of such flaws in the Nordics, 92% in the UK, and 86% in the US had been exposed for more than three months at the time of the study.

cloud

Post-quantum website certificates from Cloudflare are scheduled for early 2027

Cloudflare intends to establish itself as a public certificate authority (CA), an entity responsible for issuing the digital certificates websites utilize for traffic encryption and identity verification. The company has announced plans to issue both conventional certificates and a post-quantum variant known as Merkle Tree Certificates (MTCs), with production MTC issuance anticipated for the…

vulnerabilitycritical

CISA alerts of active exploitation of three Linux kernel flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of three distinct vulnerabilities within the Linux kernel, one of which is rated critical. These security issues were added to CISA's catalog last week, with severity ratings ranging from medium to critical. Federal agencies have been mandated to apply available security…

vulnerability

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal civilian executive branch (FCEB) agencies address these flaws by September 21, 2026. This directive, issued under Binding Operational Directive (BOD) 22-01, aims to mitigate significant risks posed by actively…

vulnerability

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Security researchers have reportedly leveraged Anthropic's Claude Opus 5 to assist in chaining two distinct vulnerabilities, leading to the compromise of OpenAI staff accounts for ChatGPT and Codex, and subsequently gaining access to an internal OpenAI code repository. The incident was described as a security research effort conducted by three researchers at the firm Hacktron.

vulnerability

Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening

The cybersecurity landscape is experiencing a significant surge in reported software vulnerabilities, a phenomenon that experts attribute to the increasing use of artificial intelligence in bug discovery. This "vulnerability explosion" is already underway, driven by broadly available AI tools, even as discussions continue about a potential slowdown in AI development.

CVE-2025-39682high

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating that these flaws are being actively exploited in the wild. This advisory highlights the immediate threat posed by these specific kernel issues to systems running the Linux operating system.

cloud

Saving another 100TB of RAM with math (and Rust)

Cloudflare has announced that it has successfully optimized its Pingora proxy, which is written in Rust, to save approximately 100 terabytes of RAM across its global network. This significant memory reduction was achieved through a series of optimizations, primarily focusing on how Pingora handles HTTP headers.

vulnerability

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft has reportedly addressed 18 vulnerabilities spanning its Azure and AI-branded product lines. The majority of these patched flaws were identified as privilege escalation vulnerabilities, indicating a focus on issues that could allow an attacker to gain elevated access within affected systems.

patch

Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE

Amazon Web Services (AWS) has confirmed the permanent loss of customer data in its Middle East (Bahrain) region, designated me-south-1, and in one availability zone of its Middle East (UAE) region, me-central-1. The announcement, made in two updates on September 15, comes six months after Iranian drone strikes impacted AWS infrastructure in the region.

breach

Hackers target exposed Vite dev servers to steal AWS, Azure secrets

A widespread scanning campaign is targeting internet-exposed Vite development servers to steal cloud credentials and configurations, particularly for AWS and Azure deployments. The attacks leverage a high-severity vulnerability, CVE-2026-39364, which affects Vite versions 7.1.0 through 7.3.2 and the 8.x branch before 8.0.5. This flaw, disclosed on April 7, enables an unauthenticated attacker…

vulnerability

AWS puts AI vulnerability detection to the test, and false positives pile up

Amazon Web Services (AWS) has introduced a new benchmark designed to evaluate how effectively artificial intelligence models can differentiate between genuine security vulnerabilities and code that merely appears risky but is actually safe. The "Deception Benchmark" aims to address the challenge of high false-positive rates in AI-driven vulnerability detection, which can lead to increased…

phishing

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft has reported details concerning two distinct campaigns where threat actors leveraged third-party email delivery infrastructure to distribute financial fraud scam messages. These campaigns employed passkey-themed social engineering tactics to compromise cloud environments, ultimately leading to the hijacking of Microsoft cloud accounts and subsequent data exfiltration.

CVE-2026-85102critical

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

The Dutch Nationaal Cyber Security Centrum (NCSC) has issued a warning regarding the imminent exploitation of two critical vulnerabilities in Check Point VPN products, identified as CVE-2026-85102 and CVE-2026-85103. The agency has assessed the likelihood of exploitation and the potential impact as high, urging organizations to apply security updates promptly.

breach

The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet

A recent study has revealed a significant cybersecurity vulnerability within the self-hosted artificial intelligence (AI) ecosystem, identifying tens of thousands of exposed AI endpoints that lack basic authentication. Researchers from Mysterium VPN found 36,769 such endpoints, including model servers, agent-building platforms, and vector stores, all publicly accessible via internet scanning…

vulnerability

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

Multiple cyber-espionage groups have deployed an exploit kit dubbed BlueMoon, which leverages zero-day vulnerabilities in Microsoft Windows and Google Chrome. The kit combines two security issues in Chromium-based browsers that enable remote code execution and sandbox escape, with a kernel local privilege escalation flaw in Windows.

cloud

Grindr settles privacy lawsuit tied to disclosure of users’ HIV statuses for $35 million

Grindr, the LGBTQ+ dating application, has agreed to a settlement of £26 million, equivalent to approximately $35.2 million, to resolve a UK lawsuit. The legal action alleged that the company shared sensitive user data, including HIV statuses, with advertisers.

vulnerabilitycritical

Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026

Microsoft's September 2026 Patch Tuesday release included fixes for a record-breaking 974 Common Vulnerabilities and Exposures (CVEs), significantly surpassing its previous record of 570 CVEs set in July 2026. This substantial increase in patched vulnerabilities follows a warning issued by Microsoft in July, advising customers to anticipate a surge in security updates for Windows products due…

ai

Microsoft’s Project Zenith puts large AI models directly on developer PCs

Microsoft has unveiled Project Zenith, a specialized Windows 11 experience designed to enable developers to run large AI models locally on their personal computers. This initiative aims to provide a ready-to-code environment capable of handling AI models with over 30 billion parameters without relying on cloud-based services or metered tokens.

cloud

Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time

Cisco served as the Official Security Cloud Provider and a long-standing partner for the Black Hat USA 2026 Network Operations Center (NOC) and Security Operations Center (SOC), marking its eleventh year in this role. The company collaborated with other official technology partners, including Palo Alto Networks, Arista, Corelight, Jamf, and Lumen, to ensure the conference network's safe and…

CVE-2026-81578

PaperCut Flaws Exploited in Attacks on U.S. and European Schools

Attackers are actively exploiting two recently disclosed vulnerabilities in PaperCut, an enterprise print management platform, to compromise educational institutions across the United States and Europe. The flaws, identified as CVE-2026-81578 and CVE-2026-82078, allow for credential theft and elevated access.

breachcritical

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

JetBrains has reported a security incident involving a breach of its internal Cadence environment, which attackers exploited to extract AWS credentials. The incident, which occurred last month, leveraged a recently disclosed critical vulnerability in TeamCity, JetBrains' continuous integration and continuous delivery (CI/CD) server. The company is advising all Cadence users to revoke and…

CVE-2026-59346critical

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom has issued security updates addressing two vulnerabilities in VMware Workstation and Fusion, one of which is a critical flaw that could enable arbitrary code execution. The critical vulnerability, identified as CVE-2026-59346, carries a CVSS score of 9.3, indicating a high level of severity.

CVE-2026-81578

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Recent reports indicate that threat actors are actively exploiting newly disclosed vulnerabilities in PaperCut software to steal credentials, primarily targeting the education sector across the U.S. and Europe. The Arctic Wolf Adversary Research Team has observed these attacks, detailing the use of an authentication bypass and remote code execution chain to achieve command execution and…

breach

IDScan sued over alleged data breach affecting 153 million drivers

Multiple lawsuits have been filed against IDScan, an identity verification technology company, following claims by a dark-web service that it possesses and is selling a database containing scans of over 153 million driver's licenses and other identity documents. The lawsuits, filed in Louisiana where IDScan is headquartered, allege that the company failed to adequately protect client data.

CVE-2026-14894critical

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Wordfence has reported a significant volume of exploit attempts targeting two distinct critical remote code execution (RCE) vulnerabilities in popular WordPress plugins: Super Forms and Elementor Pro. Over 440,000 exploit attempts have been observed, indicating widespread malicious activity aimed at leveraging these flaws.

vulnerability

New infosec products of the week: September 4, 2026

Several cybersecurity vendors have announced new product releases and updates this week, focusing on areas such as AI-driven threat protection, enterprise security for personal AI agents, cyberstorage resilience, and automated black-box penetration testing.

vulnerabilitycritical

Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models

Cloudflare has announced a new capability for its Managed Defense service, integrating OpenAI’s Daybreak models to enhance the discovery and remediation of vulnerabilities. This initiative aims to provide context-aware insights into security threats, moving beyond traditional signature-based detection to understand the broader implications of vulnerabilities within a system.

cloud

Summer 2024 weather report: Cloudflare with a chance of Intern-ets

Cloudflare, the internet infrastructure and security company, has confirmed that a recent security incident involved unauthorized access to its internal Atlassian server. The company stated that the compromise was limited to its Confluence wiki, Jira bug-tracking system, and Bitbucket source code management system, which are used for internal documentation, project tracking, and code repositories.

cloud

Legacy Lenovo login opens 5,000 Dropbox accounts to attackers

Dropbox has confirmed that approximately 5,000 user accounts were compromised due to an exploit involving a legacy login integration with Lenovo. The cloud storage provider stated that attackers leveraged an issue within Lenovo's email verification process to gain unauthorized access to these accounts.