LIVE · cybersecurity feed
Live wire

cloud news

210 stories · page 2 of 5
vulnerability

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Manifold Security has reported the discovery of eight security vulnerabilities across seven distinct command-line AI coding agents. The core mechanism of these flaws involves a malicious Git configuration file within a repository, which can instruct the AI agent to execute an arbitrary command on the developer's machine. Four of these identified vulnerabilities remain unpatched at the time of…

cloud

Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud

Anthropic has introduced a new security framework called Enterprise Frontier Safeguards, designed to address data retention and privacy concerns for enterprise customers, particularly those in regulated industries. This framework allows organizations to maintain control over their Claude AI activity logs within their own cloud environments, using their own encryption keys and access policies.

CVE-2026-0768critical

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Threat actors are actively exploiting a critical unauthenticated remote code execution vulnerability, identified as CVE-2026-0768, in Langflow, an open-source framework for building AI applications. The attacks aim to steal credentials, tokens, and various API keys.

ransomware

Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION

A cyberattack on UK airport operator Manchester Airports Group (MAG) has led to the exposure of data belonging to 8.7 million customers across three of its airports. The breach was confirmed by MAG, though specific details about the nature of the data compromised or the exact timeline of the attack were not immediately available.

CVE-2026-76581critical

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Recent reports indicate the disclosure of five critical security flaws affecting various WordPress plugins and themes. These vulnerabilities, identified in products such as WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, collectively present risks ranging from authentication bypass to full site takeover and remote code execution (RCE). The findings highlight persistent security…

ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

A recent virtual event focused on the critical considerations for enterprises securing cloud assets, particularly in the evolving landscape shaped by artificial intelligence. The discussion aimed to equip technical professionals with insights into the unique challenges and strategies required to protect cloud environments when AI technologies are increasingly integrated into operations and…

vulnerability

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Reports indicate that attackers are actively chaining two distinct security vulnerabilities in PaperCut NG and MF to achieve unauthenticated remote code execution on vulnerable systems. The vendor has released an emergency patch to address the newly exploited flaw, which includes additional hardening measures. This attack chain reportedly allows an unauthenticated attacker to gain remote…

vulnerability

Chrome 152 Patches Over 300 Vulnerabilities

Google has released Chrome 152, an update that addresses over 300 vulnerabilities within the browser. The majority of these security flaws were identified internally by Google, leveraging artificial intelligence (AI) tools for discovery. However, the update also includes patches for high-value vulnerabilities that continue to be found by external security researchers.

nation-state

Nigeria Looks to Sovereign Cloud for Cyber, National Security

Nigeria is reportedly advancing its sovereign cloud initiative, implementing new policies around financing, procurement, and infrastructure. This strategic move is aimed at bolstering the nation's cybersecurity posture and enhancing its overall national security, while simultaneously cultivating domestic technical expertise.

vulnerability

AI vulnerability discovery scores the highest impact of 20 emerging risks

A recent survey of risk managers, auditors, and senior executives across 316 companies has identified AI-driven cyber vulnerability discovery as the most impactful emerging risk. This finding represents a significant shift from a similar survey conducted three months prior, where this particular risk was not even among the top five.

phishing

Hackers abuse npm mirrors to host phishing redirect pages

Threat actors are leveraging the npm package registry and its mirroring services to host malicious HTML pages, effectively turning these platforms into free web hosting for phishing redirects. This technique, distinct from typical supply-chain attacks that infect developer systems, uses npm as a validated storage mechanism for attacker-controlled content.

breach

TruffleHog AWS Analyze reduces remediation time on leaked AWS credentials

Truffle Security has introduced TruffleHog AWS Analyze, an expansion of its TruffleHog Enterprise platform designed to accelerate the remediation of leaked AWS credentials. This new feature enriches discovered AWS keys with detailed information on their permissions and access levels, enabling security teams to better assess risk and prioritize their response efforts.

cloud

SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules

The Supreme Court has dismissed one of two injunctions that had blocked the Trump administration's changes to U.S. Postal Service (USPS) regulations concerning mail-in ballots. The 6-3 decision, issued on August 24, 2026, found that the plaintiff states lacked standing to sue because they could not demonstrate concrete harm from the executive order.

cloud

The Cloudflare Blog – Brought to you by EmDash

Cloudflare has confirmed a security incident involving an unauthorized third party gaining access to an internal Atlassian server. The company stated that the attacker used stolen credentials to breach the system, which hosted its Confluence wiki, Jira bug-tracking system, and Bitbucket source code management system.

cloud

NIST Warns of Unique Security Risks in Multi-Cloud Environments

The National Institute of Standards and Technology (NIST) has issued a warning to organizations regarding the unique cybersecurity and compliance challenges inherent in multi-cloud environments. NIST's new report, published on August 21, highlights that utilizing two or more cloud service providers (CSPs) introduces complexities that make it difficult to maintain consistent security policies,…

breach

Researchers Uncover Thousands of Leaked AWS Keys

A cybersecurity firm has reported finding over 9,300 active Amazon Web Services (AWS) keys that were publicly exposed between August 2022 and August 2026, with hundreds of these keys granting full administrative privileges. Truffle Security stated its scanners identified 64,024 unique AWS key pairs across 431,875 public sources, including git histories, Hugging Face datasets, Docker images,…

cloud

AWS makes it easier to spot firewall rules that have gone quiet

Amazon Web Services (AWS) has introduced a new capability for its Network Firewall service, providing visibility into the hit counts of stateful firewall rules. This feature, which became available on August 24, 2026, is designed to help security teams identify unused or redundant rules, validate the effectiveness of security controls, and streamline incident response.

ransomware

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

A threat actor known as "TheHatman" has claimed to have exfiltrated millions of employee records from the Microsoft Azure environments of several Fortune 500 companies. The alleged victims include prominent global businesses such as McDonald's, Vodafone, Kyndryl, and Tata Consultancy Services (TCS).

breach

AWS Security makes an inscrutable choice

Hundreds of AWS root keys, some of which are still active and valid, have been discovered in public GitHub repositories, according to a recent finding by Truffle Security. While AWS Security typically applies a "Quarantine Policy" to leaked credentials, this policy has been criticized for not fully deactivating compromised keys, potentially leaving customer environments vulnerable to…

ai

Say it once: introducing Bot Preference Sync

Cloudflare has confirmed that it was targeted by the advanced persistent threat (APT) group known as Spook. The attack, which occurred between October 26 and October 30, 2023, involved Spook gaining unauthorized access to Cloudflare's internal Atlassian server. This server hosted Cloudflare's Confluence wiki, Jira bug-tracking system, and Bitbucket source code management system.

breach

Apollo discloses data breach from ongoing wave of attacks hitting financial sector

Apollo Global Management, a major private equity firm, has confirmed it experienced a data breach in July, impacting some of its cloud platforms. The company disclosed that sensitive personal data, including names, dates of birth, contact information, home addresses, and Social Security numbers, was compromised during the incident.

vulnerabilitycritical

Six Maximum-Severity Flaws Found in Cisco Products

Cisco has released a series of security patches addressing nine vulnerabilities across its Crosswork platforms and Secure Workload software, with six of these flaws receiving the maximum CVSS score of 10.0. The vulnerabilities were discovered during an internal security review conducted by Cisco's engineering team, which included the use of advanced AI models. As of the announcement on August…

vulnerabilityhigh

CISA orders feds to patch actively exploited TrueConf Server flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to immediately patch two critical vulnerabilities in the TrueConf Server self-hosted communications platform, which are reportedly being actively exploited in the wild. The directive, issued on Thursday, August 21, 2026, requires all U.S. Federal Civilian Executive Branch (FCEB) agencies to secure…

CVE-2026-69836critical

Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836)

Microsoft has issued a patch for a critical remote code execution vulnerability, identified as CVE-2026-69836, within its Entra ID cloud identity service. The company confirmed that the vulnerability has been actively exploited in the wild. Entra ID, previously known as Azure Active Directory, is a core Microsoft service responsible for authenticating user logins and managing access to…

breach

Medical records, SSNs, and bank details exposed in CareCloud data breach

CareCloud, a healthcare technology provider, has confirmed a data breach that exposed the personal and medical information of over 3.75 million individuals. The incident, which occurred in March, involved an unauthorized third party accessing one of the company's Amazon Web Services (AWS) environments.

vulnerability

U.S. CISA adds TrueConf Server flaws to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities in TrueConf Server, an on-premises video conferencing and unified communications platform, to its Known Exploited Vulnerabilities (KEV) catalog. The flaws, identified as CVE-2026-72529 and CVE-2026-72530, both carry high CVSS scores, indicating their severity.

CVE-2026-69836high

Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution

Microsoft has issued a warning regarding a critical security flaw in its Entra ID cloud-based identity and access management service, which has reportedly been exploited in the wild. The vulnerability, identified as CVE-2026-69836, carries a maximum CVSS score of 10.0, indicating its severe potential impact. Despite the active exploitation, Microsoft has stated that no immediate customer…

vulnerability

Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.

Cisco has issued an advisory regarding five vulnerabilities discovered in its Secure Workload Software, a micro-segmentation tool previously known as Tetration. These flaws, identified during an internal security review that included the use of advanced AI models, range in severity from critical to high. Cisco confirmed that it has not observed any malicious exploitation of these…

vulnerability

N-able Bug Exposes Password Vault Master Keys

A recently disclosed vulnerability in N-able's Passportal password manager reportedly exposed master keys for password vaults. The flaw, which affects a product widely used by Managed Service Providers (MSPs) and Small and Medium Businesses (SMBs), raises concerns about the security of cloud-based password management solutions even after a patch has been applied.

cloud

From all-or-nothing to task-based OAuth consent

A significant enhancement to the OAuth consent process, moving from an "all-or-nothing" model to a more granular, task-based approach, has been introduced. This update aims to provide users with finer control over the permissions granted to third-party applications, addressing long-standing security and privacy concerns associated with broad consent requests.

vulnerability

JFrog Artifactory Flaws Enable Software Supply Chain Attacks

Two vulnerabilities in JFrog Artifactory have been identified that could enable anonymous or low-privileged users to manipulate package metadata without altering the underlying artifacts, potentially leading to software supply chain compromises. The flaws, reported by Oligo Security to JFrog on June 25 and publicly detailed on August 20, have since been patched by JFrog.

vulnerabilitycritical

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities

Atlassian and Splunk have released patches addressing numerous critical and high-severity vulnerabilities across their product lines. The reported flaws could potentially be exploited by attackers to achieve arbitrary code execution, gain unauthorized access to sensitive data, and escalate privileges within affected systems. Users of Atlassian and Splunk products are strongly advised to apply…

vulnerability

Citrix urges admins to patch new NetScaler flaws as soon as possible

Citrix has issued an urgent advisory to customers, recommending immediate action to secure systems against two newly disclosed vulnerabilities impacting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. The company confirmed these flaws affect supported versions of customer-managed NetScaler ADC and NetScaler Gateway, including specific FIPS and NDcPP…

vulnerabilitycritical

MLflow Vulnerability Exploited for Cloud Credential Theft

A critical-severity vulnerability in MLflow has reportedly been exploited to facilitate the theft of cloud credentials. The flaw, described as allowing attackers to send HTTP requests to internal endpoints, was observed in active exploitation, leading to the extraction of sensitive information.

vulnerabilitycritical

Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities

Cisco has released patches addressing critical vulnerabilities in its Crosswork Network Automation and Secure Workload (formerly Tetration) products. These security flaws have been reported to potentially enable remote code execution, authentication bypasses, and path traversal attacks against affected systems. The patches are intended to mitigate the risk posed by these vulnerabilities.

ddos

Corero brings cloud-based AI threat analysis to SmartWall ONE

Corero Network Security has introduced AI-Augmented Cloud-Assist for its SmartWall ONE platform, integrating cloud-based artificial intelligence to enhance its automated distributed denial-of-service (DDoS) protection capabilities. This new feature aims to provide advanced threat analysis, intelligence gathering, and policy optimization.

ai

AWS limits AI agents’ data access, even when manipulated

Amazon Web Services (AWS) has outlined a new strategy to restrict AI agents' access to sensitive data, even when those agents are subjected to manipulation or internal bugs. The approach focuses on enforcing user authorization at the infrastructure and downstream service levels, rather than relying on the AI agent itself to act as a gatekeeper. This method is designed to ensure that AI agents…

vulnerability

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

Security researchers at Cycode have reported a chain of vulnerabilities in AIT-GUI, a browser-based operator console developed by NASA/JPL. These flaws reportedly allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument command bus. The vulnerabilities are tracked under the identifier GHSA-p9r8-2q67-fp86 and have been assigned a CVSS v3.1 score…

cloud

Fake Gemini installer delivers Vidar infostealer via Google Colab lure

Cybersecurity researchers have identified a new campaign distributing the Vidar infostealer through a deceptive Google Gemini installer, leveraging Google Colaboratory (Colab) as part of its delivery mechanism. The attack, observed targeting a company in the EMEA region, exploited user interest in AI software by masquerading a malicious executable as a legitimate Google Gemini application.

ai

Tufin expands Unified Control Plane with AI intelligence and multi-vendor automation

Tufin has announced the release of Tufin Orchestration Suite (TOS) 5.3, an update designed to enhance security operations and maintain consistent control across complex, multi-vendor hybrid environments. The new version expands Tufin's Unified Control Plane with additional integrations, AI-powered intelligence, and automation capabilities.

vulnerabilitycritical

8,539 reasons to rethink how vulnerabilities get patched

The volume of high- and critical-severity vulnerability disclosures has doubled in the past year, with 8,539 recorded in Q2 2026, according to a recent industry report. This surge is intensifying pressure on security teams, who must prioritize which flaws to address immediately, often contending with a rapidly shrinking window between disclosure and exploit weaponization.

cloud

Sakura Internet hack exposes data of up to 1.36 million accounts

Sakura Internet, a prominent Japanese cloud and data center service provider, has disclosed that a cybersecurity incident may have exposed data belonging to up to 1,360,563 member accounts. The company, which is a key domestic provider for Japan's Government Cloud program, confirmed that attackers gained access to its sales management system, where customer contract and membership information…

breach

Healthtech firm CareCloud data breach impacts 3.7 million patients

CareCloud, a U.S. healthcare IT company, has confirmed that a data breach earlier this year impacted over 3.7 million individuals. The publicly traded firm, which provides electronic health records, medical billing, practice management, and revenue-cycle services, initially disclosed the incident in March through a filing with the U.S. Securities and Exchange Commission (SEC).

breach

Electronic health record company CareCloud says 3.7 million people affected by breach

CareCloud, a prominent provider of electronic health record (EHR) systems, has confirmed that a data breach in March affected 3,756,469 individuals. The company disclosed to federal regulators that an unauthorized actor gained access to one of its Amazon Web Services (AWS) environments, remaining undetected for approximately eight hours.

cloud

A revisit of remote Spectre attacks on Cloudflare Workers

Cloudflare has confirmed that its Workers serverless computing platform was vulnerable to a variant of the Spectre side-channel attack, specifically CVE-2023-50387, which could have allowed attackers to extract sensitive data from other customers' Workers. The vulnerability, dubbed "Rampage" by the researchers who discovered it, exploited speculative execution features in modern CPUs to leak…

cloud

Simple Scans for Cloud Metadata Service, (Wed, Aug 19th)

Reports indicate that cloud metadata services, commonly exposed by major cloud providers, are susceptible to simple scanning techniques that could lead to the unauthorized retrieval of sensitive machine-specific data. This service, typically accessible via a REST API at the IP address 169.254.169.254, is designed to allow applications running on virtual machines to programmatically discover…

CVE-2026-65400critical

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert regarding four critical vulnerabilities that are reportedly under active exploitation. These flaws affect Apple macOS, Microsoft SharePoint, VMware vCenter Server, and Microsoft Internet Key Exchange (IKE). CISA has added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating…

vulnerability

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent directive for organizations to immediately patch several exploited vulnerabilities affecting products from Microsoft, VMware, and Apple. These security flaws are reportedly being actively leveraged in the wild, posing significant risks to affected systems and data. The agency's alert emphasizes the critical need…