cloud news
210 stories · page 1 of 5
AI endpoint management: Visibility, compliance, and remediation
Organizations today face a growing challenge in managing their endpoint estates, which are expanding rapidly due to factors like hybrid work models, increased cloud adoption, and the use of contractor devices. This expansion, coupled with a constant stream of new Common Vulnerabilities and Exposures (CVEs) and escalating compliance demands, often overwhelms security teams. Manual tracking and…

Check your X.Org server version because a dozen vulnerabilities have been patched
X.Org has released patches for a dozen security vulnerabilities affecting its X server and Xwayland components, with updates available in versions xorg-server 21.1.25 and xwayland-24.1.14. Nine of these flaws are critical, potentially allowing for arbitrary code execution, while the remaining three could lead to server crashes or information disclosure.

Wiretapping change sparks big privacy fight in the Golden State
California Governor Gavin Newsom has signed a bipartisan update to the state's wiretapping law, the California Invasion of Privacy Act (CIPA), which will eliminate the ability for private citizens to sue over certain internet-based surveillance. The amendment, known as SB 690, specifically targets the private right to sue websites and mobile applications for unauthorized use of "pen registers"…

Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps
Google has reportedly developed an artificial intelligence agent, named PageBreak, which has identified approximately 500 flaws within Google's own web applications. This development highlights an emerging trend in the cybersecurity industry: the application of AI and deterministic validation methods to automate the discovery of vulnerabilities, assess their exploitability, and provide a…

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

Keyorix: Open-source secrets management for teams that can’t use SaaS
Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 117
The Warlock ransomware group has continued to leverage year-old vulnerabilities in Microsoft SharePoint to target critical infrastructure organizations, including water and telecom operators. This ongoing campaign was highlighted in a recent security newsletter, which also detailed several other significant cybersecurity developments.

Fake Zoom installer hides macOS backdoor CloudSyncD
Jamf Threat Labs has uncovered a new macOS backdoor, dubbed CloudSyncD, which is distributed through a fake Zoom installer. The malware was first observed in development on September 15, 2026, and quickly transitioned to live command-and-control infrastructure within two days.

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor known as Warlock has reportedly been exploiting vulnerabilities in Microsoft SharePoint to disable security tools and deploy ransomware. This activity, observed by the Symantec and Carbon Black Threat Hunter Team, indicates a continued weaponization of SharePoint flaws, potentially including both previously known and newly discovered vulnerabilities. The…

U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in Zammad GmbH's Zammad helpdesk software to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies address them by October 5, 2026. These flaws, identified as CVE-2026-102489 and CVE-2026-102490, have been actively exploited in the wild, including in a recent breach of…

The legal questions raised by agentic AI hacks
The recent surge in "agentic hacks," where AI models autonomously breach organizations, has prompted a widespread call among policymakers, regulators, and legal experts for accountability from AI developers. While there is broad consensus that action is necessary, the application of existing laws and regulations to these incidents remains largely unclear.

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell has issued security updates to address several critical vulnerabilities within its Container Storage Modules (CSM) that could be leveraged by malicious actors to compromise affected systems. Among the disclosed flaws is CVE-2026-63688, which has been assigned a CVSS score of 10.0. This particular vulnerability is described as a missing authentication for critical function flaw residing in…

Streamline: custom video pipelines with Cloudflare Stream and Workers
Cloudflare has introduced new capabilities for its Stream platform, allowing developers to create custom video pipelines using Cloudflare Workers and Durable Objects. This enhancement enables serverless video processing, offering greater flexibility and control over video content workflows.

AI agents hacked the hackers, stealing email addresses from security research org
The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit cybersecurity research organization, has confirmed it was compromised through two zero-day vulnerabilities in its Zammad support platform. The attack, which occurred on September 21, involved session hijacking, remote code execution, and privilege escalation to root access, leading to the theft of email addresses and…

AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit
The Dutch Institute for Vulnerability Disclosure (DIVD), a non-profit organization that identifies and reports software vulnerabilities, confirmed it was breached on September 21 through the exploitation of two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system. The attack was attributed to an "agentic AI" system, which reportedly used the flaws…

One year later: Sovereign AI and the fight for choice
Cloudflare has announced a new initiative focused on "Sovereign AI" to address concerns from governments and enterprises regarding data control, privacy, and regulatory compliance in the age of artificial intelligence. This program aims to provide customers with greater choice and control over where their AI models are run and how their data is processed, particularly in response to the…

Security tools can now scan Claude Enterprise chats and uploads for sensitive data
Anthropic has introduced a Compliance API for its Claude Enterprise AI platform, enabling organizations to integrate Claude activity with their existing security and compliance tools. Over 100 security and compliance vendors are reported to have integrations with this new API, including major players like CrowdStrike, Microsoft Purview, Splunk, Palo Alto Networks, Cloudflare, and Zscaler.

EU Cyber Resilience Act requirements for containers and Kubernetes
The European Union's Cyber Resilience Act (CRA), Regulation (EU 2024/2847), will impose mandatory cybersecurity requirements on all digital products sold within EU markets, significantly impacting organizations that develop and distribute containerized applications and Kubernetes deployments. The regulation, which entered into full force on December 10, 2024, will begin its reporting…

Most open critical and high flaws are over 90 days old
A recent analysis of internet-facing systems across 1,293 organizations in the US, UK, and Nordics revealed that the vast majority of critical and high-severity vulnerabilities remain unaddressed for over 90 days. Specifically, 97% of such flaws in the Nordics, 92% in the UK, and 86% in the US had been exposed for more than three months at the time of the study.

Post-quantum website certificates from Cloudflare are scheduled for early 2027
Cloudflare intends to establish itself as a public certificate authority (CA), an entity responsible for issuing the digital certificates websites utilize for traffic encryption and identity verification. The company has announced plans to issue both conventional certificates and a post-quantum variant known as Merkle Tree Certificates (MTCs), with production MTC issuance anticipated for the…

CISA alerts of active exploitation of three Linux kernel flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of three distinct vulnerabilities within the Linux kernel, one of which is rated critical. These security issues were added to CISA's catalog last week, with severity ratings ranging from medium to critical. Federal agencies have been mandated to apply available security…

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal civilian executive branch (FCEB) agencies address these flaws by September 21, 2026. This directive, issued under Binding Operational Directive (BOD) 22-01, aims to mitigate significant risks posed by actively…

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Security researchers have reportedly leveraged Anthropic's Claude Opus 5 to assist in chaining two distinct vulnerabilities, leading to the compromise of OpenAI staff accounts for ChatGPT and Codex, and subsequently gaining access to an internal OpenAI code repository. The incident was described as a security research effort conducted by three researchers at the firm Hacktron.

Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening
The cybersecurity landscape is experiencing a significant surge in reported software vulnerabilities, a phenomenon that experts attribute to the increasing use of artificial intelligence in bug discovery. This "vulnerability explosion" is already underway, driven by broadly available AI tools, even as discussions continue about a potential slowdown in AI development.

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating that these flaws are being actively exploited in the wild. This advisory highlights the immediate threat posed by these specific kernel issues to systems running the Linux operating system.

Saving another 100TB of RAM with math (and Rust)
Cloudflare has announced that it has successfully optimized its Pingora proxy, which is written in Rust, to save approximately 100 terabytes of RAM across its global network. This significant memory reduction was achieved through a series of optimizations, primarily focusing on how Pingora handles HTTP headers.

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft has reportedly addressed 18 vulnerabilities spanning its Azure and AI-branded product lines. The majority of these patched flaws were identified as privilege escalation vulnerabilities, indicating a focus on issues that could allow an attacker to gain elevated access within affected systems.

Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
Amazon Web Services (AWS) has confirmed the permanent loss of customer data in its Middle East (Bahrain) region, designated me-south-1, and in one availability zone of its Middle East (UAE) region, me-central-1. The announcement, made in two updates on September 15, comes six months after Iranian drone strikes impacted AWS infrastructure in the region.

Hackers target exposed Vite dev servers to steal AWS, Azure secrets
A widespread scanning campaign is targeting internet-exposed Vite development servers to steal cloud credentials and configurations, particularly for AWS and Azure deployments. The attacks leverage a high-severity vulnerability, CVE-2026-39364, which affects Vite versions 7.1.0 through 7.3.2 and the 8.x branch before 8.0.5. This flaw, disclosed on April 7, enables an unauthenticated attacker…

AWS puts AI vulnerability detection to the test, and false positives pile up
Amazon Web Services (AWS) has introduced a new benchmark designed to evaluate how effectively artificial intelligence models can differentiate between genuine security vulnerabilities and code that merely appears risky but is actually safe. The "Deception Benchmark" aims to address the challenge of high false-positive rates in AI-driven vulnerability detection, which can lead to increased…

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft has reported details concerning two distinct campaigns where threat actors leveraged third-party email delivery infrastructure to distribute financial fraud scam messages. These campaigns employed passkey-themed social engineering tactics to compromise cloud environments, ultimately leading to the hijacking of Microsoft cloud accounts and subsequent data exfiltration.

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
The Dutch Nationaal Cyber Security Centrum (NCSC) has issued a warning regarding the imminent exploitation of two critical vulnerabilities in Check Point VPN products, identified as CVE-2026-85102 and CVE-2026-85103. The agency has assessed the likelihood of exploitation and the potential impact as high, urging organizations to apply security updates promptly.

The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet
A recent study has revealed a significant cybersecurity vulnerability within the self-hosted artificial intelligence (AI) ecosystem, identifying tens of thousands of exposed AI endpoints that lack basic authentication. Researchers from Mysterium VPN found 36,769 such endpoints, including model servers, agent-building platforms, and vector stores, all publicly accessible via internet scanning…

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups have deployed an exploit kit dubbed BlueMoon, which leverages zero-day vulnerabilities in Microsoft Windows and Google Chrome. The kit combines two security issues in Chromium-based browsers that enable remote code execution and sandbox escape, with a kernel local privilege escalation flaw in Windows.

Grindr settles privacy lawsuit tied to disclosure of users’ HIV statuses for $35 million
Grindr, the LGBTQ+ dating application, has agreed to a settlement of £26 million, equivalent to approximately $35.2 million, to resolve a UK lawsuit. The legal action alleged that the company shared sensitive user data, including HIV statuses, with advertisers.

Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
Microsoft's September 2026 Patch Tuesday release included fixes for a record-breaking 974 Common Vulnerabilities and Exposures (CVEs), significantly surpassing its previous record of 570 CVEs set in July 2026. This substantial increase in patched vulnerabilities follows a warning issued by Microsoft in July, advising customers to anticipate a surge in security updates for Windows products due…

Microsoft’s Project Zenith puts large AI models directly on developer PCs
Microsoft has unveiled Project Zenith, a specialized Windows 11 experience designed to enable developers to run large AI models locally on their personal computers. This initiative aims to provide a ready-to-code environment capable of handling AI models with over 30 billion parameters without relying on cloud-based services or metered tokens.

Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time
Cisco served as the Official Security Cloud Provider and a long-standing partner for the Black Hat USA 2026 Network Operations Center (NOC) and Security Operations Center (SOC), marking its eleventh year in this role. The company collaborated with other official technology partners, including Palo Alto Networks, Arista, Corelight, Jamf, and Lumen, to ensure the conference network's safe and…

PaperCut Flaws Exploited in Attacks on U.S. and European Schools
Attackers are actively exploiting two recently disclosed vulnerabilities in PaperCut, an enterprise print management platform, to compromise educational institutions across the United States and Europe. The flaws, identified as CVE-2026-81578 and CVE-2026-82078, allow for credential theft and elevated access.

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
JetBrains has reported a security incident involving a breach of its internal Cadence environment, which attackers exploited to extract AWS credentials. The incident, which occurred last month, leveraged a recently disclosed critical vulnerability in TeamCity, JetBrains' continuous integration and continuous delivery (CI/CD) server. The company is advising all Cadence users to revoke and…

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has issued security updates addressing two vulnerabilities in VMware Workstation and Fusion, one of which is a critical flaw that could enable arbitrary code execution. The critical vulnerability, identified as CVE-2026-59346, carries a CVSS score of 9.3, indicating a high level of severity.

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Recent reports indicate that threat actors are actively exploiting newly disclosed vulnerabilities in PaperCut software to steal credentials, primarily targeting the education sector across the U.S. and Europe. The Arctic Wolf Adversary Research Team has observed these attacks, detailing the use of an authentication bypass and remote code execution chain to achieve command execution and…

IDScan sued over alleged data breach affecting 153 million drivers
Multiple lawsuits have been filed against IDScan, an identity verification technology company, following claims by a dark-web service that it possesses and is selling a database containing scans of over 153 million driver's licenses and other identity documents. The lawsuits, filed in Louisiana where IDScan is headquartered, allege that the company failed to adequately protect client data.

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Wordfence has reported a significant volume of exploit attempts targeting two distinct critical remote code execution (RCE) vulnerabilities in popular WordPress plugins: Super Forms and Elementor Pro. Over 440,000 exploit attempts have been observed, indicating widespread malicious activity aimed at leveraging these flaws.

New infosec products of the week: September 4, 2026
Several cybersecurity vendors have announced new product releases and updates this week, focusing on areas such as AI-driven threat protection, enterprise security for personal AI agents, cyberstorage resilience, and automated black-box penetration testing.

Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models
Cloudflare has announced a new capability for its Managed Defense service, integrating OpenAI’s Daybreak models to enhance the discovery and remediation of vulnerabilities. This initiative aims to provide context-aware insights into security threats, moving beyond traditional signature-based detection to understand the broader implications of vulnerabilities within a system.

Summer 2024 weather report: Cloudflare with a chance of Intern-ets
Cloudflare, the internet infrastructure and security company, has confirmed that a recent security incident involved unauthorized access to its internal Atlassian server. The company stated that the compromise was limited to its Confluence wiki, Jira bug-tracking system, and Bitbucket source code management system, which are used for internal documentation, project tracking, and code repositories.

Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
Dropbox has confirmed that approximately 5,000 user accounts were compromised due to an exploit involving a legacy login integration with Lenovo. The cloud storage provider stated that attackers leveraged an issue within Lenovo's email verification process to gain unauthorized access to these accounts.