cloud news
210 stories · page 3 of 5
Medusa ransomware gang has hit over 500 organizations, CISA warns
The Medusa ransomware group has compromised over 500 organizations across various critical infrastructure sectors since its emergence in June 2021, according to a joint advisory updated by the FBI, CISA, and the Department of Health and Human Services (HHS). The updated guidance, released in August 2026, incorporates findings from FBI investigations conducted through April 2026 and expands…

Google’s AI security agents found 100+ critical software vulnerabilities in just two days
Google's Mandiant security division has revealed an internal AI-driven tool designed to identify software vulnerabilities, which successfully uncovered over 100 verified, high-severity flaws in just two days during a live investigation of stolen corporate code repositories. The tool, named the Agentic Vulnerability Discovery Harness (AVDH), has been operational within Mandiant for ten months,…

U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal agencies patch them by August 21, 2026. The newly cataloged flaws affect Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft Internet Key Exchange (IKE) Service Extensions.

CareCloud Data Breach Impact Grows to 3.7 Million Individuals
A recent report indicates that a data breach affecting CareCloud, a health information technology provider, has expanded significantly in scope. Initially estimated to impact approximately 350,000 individuals, the incident is now reported to affect 3.7 million individuals, according to updated information on the U.S. Department of Health and Human Services (HHS) breach tracker.

Hackers Expose Data of 1.2 Million Heights Finance Customers
Heights Finance Holdings Co., a U.S. consumer finance company, has begun notifying over 1.2 million individuals that their personal and financial data was exposed following a cybersecurity incident. The breach, discovered on May 7, 2026, involved unauthorized access to a third-party cloud platform used by Heights Finance to store customer information.
Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
Varonis Threat Labs has reported the discovery of three vulnerabilities in Microsoft Copilot Personal. These flaws, collectively dubbed "CoSnitch" by the researchers, reportedly enable data exfiltration from connected applications and other information accessible within a victim's Copilot session through a single click on a specially crafted link. The researchers indicated that one aspect of…

Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Recent reports indicate active exploitation attempts targeting a Server-Side Request Forgery (SSRF) vulnerability within MLflow, an open-source artificial intelligence platform. Attackers are reportedly leveraging this flaw to exfiltrate cloud credentials and other sensitive secrets. This activity highlights the ongoing risk associated with critical vulnerabilities in widely adopted platforms,…

Medusa ransomware tallies hundreds of new victims, says updated advisory on group’s tactics
The Medusa ransomware-as-a-service group has expanded its victim count to over 500 organizations, an increase of more than 200 since March 2025, according to an updated advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the Department of Health and Human Services (HHS). The group, first identified in 2021, has also refined its tactics for initial…

NASA Ground Control Software Flaw Enables Unauthenticated Commands
A critical vulnerability has been discovered in NASA's open-source AMMOS Instrument Toolkit (AIT)-GUI ground software, which could allow unauthenticated attackers to issue commands to spacecraft and instruments, execute server-side scripts, and run command sequences. The flaw, identified as GHSA-p9r8-2q67-fp86, carries a CVSS rating of 9.4 and affects AIT-GUI versions up to and including…

Video Call Exploit Chains Two Flaws in Unisoc Modems
A recent report indicates that a pair of vulnerabilities in Unisoc modems can be chained together to facilitate remote compromise of Android devices. The exploit reportedly allows an attacker to deliver a malicious payload to a target device, achieving full control once the user answers an incoming call. This finding highlights a significant attack vector through a core communication component…

Hacker claims 3.6 million Azure account records stolen from major companies
A threat actor operating under the alias "TheHatman" has claimed to have stolen 3.64 million employee records from the Microsoft Azure infrastructure of several major corporations, including McDonald's, Gap Inc., Vodafone, Tata Consultancy Services, HCL Technologies, InterContinental Hotels (IHG), and Kyndryl. The alleged breaches were advertised in multiple posts starting July 31st, with the…

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities
A financially motivated cybercrime group, identified as Storm-0501, has evolved its ransomware tactics to target cloud environments, specifically Microsoft Azure. This group, which Microsoft has been tracking since 2024, is noted for its ability to bridge on-premises Active Directory systems with cloud-native Microsoft Entra ID and Azure environments.

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
A critical vulnerability in SAP Commerce Cloud, identified as CVE-2026-58231, was reportedly exploited in the wild just three days after its public disclosure. The flaw allows for arbitrary code execution and the compromise of internal system components, posing a significant risk to affected deployments.

Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology
A recent report highlights that the primary cybersecurity challenge facing organizations in Africa extends beyond mere access to technology, according to Gopan Sivasankaran, Rapid7's Regional Director for the Middle East & Africa. The observation focuses on the expanding technological landscape across key nations including Egypt, Nigeria, South Africa, and Kenya, where organizations are…

Fortune 500 Companies Hit in Azure Data Theft Campaign
Reports indicate that a threat actor is claiming to have exfiltrated millions of records from multiple large organizations, including McDonald’s, TCS, and Vodafone. The campaign reportedly targets Fortune 500 companies, with the actor asserting successful data theft from several prominent entities. The specific mechanism of the alleged exfiltration was not detailed in the initial reports, but…

Hazmat: Open-source containment for AI agents
Hazmat is an open-source tool designed to contain AI coding agents within a separate, isolated environment on a user's machine. The tool aims to prevent agents from accessing sensitive user data by restricting their permissions to only the project directory specified by the user.

SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
A critical vulnerability in SAP Commerce Cloud, identified as CVE-2026-58231, is being actively exploited in the wild just days after a patch was released. The flaw, which carries a maximum CVSS score of 10.0, allows for unauthenticated arbitrary code execution and compromise of internal components.

Max severity SAP Commerce Cloud flaw now targeted in attacks
A critical remote code execution vulnerability in SAP Commerce Cloud, identified as CVE-2026-58231, is reportedly being exploited in active attacks just three days after a patch was released. The flaw, which carries a maximum severity rating, affects the core Data Hub Adapter extension of the e-commerce platform, formerly known as SAP Hybris.

How Cloudflare detects MCP traffic and helps secure it
Cloudflare has confirmed that it is actively detecting and mitigating traffic associated with the Model Context Protocol (MCP), a new protocol identified as being used in large-scale distributed denial-of-service (DDoS) attacks. The company's security systems are designed to identify and neutralize these attacks, which leverage a novel method of amplification.

Secure all your internal vibe-coded applications — in one click
Cloudflare has confirmed that it was affected by a critical vulnerability, CVE-2023-50387, dubbed "KeyTrap," which could allow an attacker to exhaust CPU resources on a DNS resolver, effectively creating a denial-of-service condition. The vulnerability, which affects DNSSEC, was publicly disclosed by researchers at the University of Stuttgart and the German National Research Center for Applied…

If the Markets Reject OpenAI and Anthropic, the US Should Nationalize Them
OpenAI and Anthropic, two prominent artificial intelligence development companies, are facing market headwinds that could challenge their long-term financial viability, leading some observers to suggest their potential nationalization if they fail as private enterprises. Both companies were founded by AI developers who expressed concerns about the unchecked development of AI by large…

Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal
Google Cloud has reportedly outlined its comprehensive roadmap for achieving full post-quantum cryptography (PQC) readiness, targeting a complete transition by 2029. This initiative includes specific milestones planned for 2027 and 2028, indicating a phased approach to integrating quantum-resistant cryptographic algorithms across its cloud infrastructure. The move reflects a proactive stance…

Over 1,000 Charities Hit by Beacon CRM Data Breach
A recent report indicates that over 1,000 charitable organizations have been impacted by a data breach affecting Beacon CRM. The incident's root cause has been attributed to a compromised AWS access key, which was reportedly exposed within publicly available JavaScript build artifacts.

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals
AWS Certificate Manager (ACM) is set to discontinue support for email-validated public certificates throughout 2027, in anticipation of a broader industry shift mandated by the Certification Authority/Browser (CA/B) Forum. The CA/B Forum, which establishes standards for publicly trusted certificates followed by browsers and certificate authorities, has set a deadline of March 15, 2028, after…

Weak IAM affects up to 98% of cloud environments
A new report from Intruder, the 2026 Cloud Security Index, indicates that misconfigurations continue to be a primary threat to cloud environments, with a single error potentially leading to public network access, unrotated keys, or exposed services. The report highlights that weak identity and access management (IAM) controls and inadequate logging and alerting are the most pervasive security…

Total eclipse of the Internet: traffic impacts in Iceland, Spain, and Portugal
A significant internet outage impacted users in Iceland, Spain, and Portugal on November 27, 2023, attributed to a Border Gateway Protocol (BGP) routing leak. The incident, which began around 10:20 UTC and was largely resolved by 11:15 UTC, caused widespread connectivity issues, particularly affecting the Icelandic government network and various internet service providers (ISPs) in the Iberian…

U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to address these flaws due to active exploitation. The vulnerabilities affect Metabase, Microsoft Windows, and Cisco Secure Firewall products.

Why API Discovery Is Critical for Modern AppSec Programs
Modern application security programs face a critical challenge in maintaining an accurate and comprehensive inventory of their APIs, a gap that attackers are increasingly exploiting. This "API discovery gap" arises because traditional, manual methods of tracking APIs cannot keep pace with the rapid development and deployment of new services, leading to a significant portion of an…

Exposed AWS Access Key Linked to Data Breach Affecting 1500+ UK Charities
A cyberattack on Beacon, a customer relationship management (CRM) provider, has resulted in the exposure of personal information belonging to supporters of approximately 1500 UK charities. The incident, which Beacon confirmed on August 12, was attributed to a compromised AWS access key.

The backup Microsoft never promised you
Organizations relying on Microsoft's cloud services, including Microsoft 365, Azure, and Entra ID, often operate under a significant misconception regarding data protection and recovery in the event of a cyberattack. While Microsoft ensures the availability and operational continuity of its services, it does not provide comprehensive data backup and recovery solutions that protect against…

Google Cloud Targets 2027 for First Major Post-Quantum Security Milestone
Google Cloud has outlined a phased roadmap for its transition to post-quantum cryptography, setting a target of late 2027 for the completion of its first major security milestone. This initial phase focuses on mitigating "store-now-decrypt-later" (SNDL) risks, where data collected today could be decrypted by a future quantum computer. The comprehensive plan, published on August 12, organizes…

Certificate Transparency Monitoring is now generally available
Cloudflare has announced the general availability of its Certificate Transparency Monitoring service, a tool designed to help organizations detect unauthorized certificate issuance for their domains. The service, which had been in a beta phase, now offers a more robust and integrated solution for tracking certificates.

Germany moves to give spy agencies hacking and sabotage powers
Germany's cabinet has approved a comprehensive legislative overhaul that would grant its intelligence agencies new powers to conduct cyber operations, including hacking foreign systems and sabotaging adversaries' supply chains. The 732-page bill, which still requires parliamentary approval, represents the most significant reform of the country's spy laws since the post-war era.

AWS key exposed in JavaScript may have lit way to Beacon's charity data
Beacon, a CRM provider for charities and nonprofits, has confirmed that an exposed AWS access key is the primary suspect in a July data breach that resulted in the copying and likely download of its entire customer database. The company's CTO, David Simpson, stated that the key was "potentially exposed in public JavaScript build artifacts," raising concerns about the effectiveness of Beacon's…

Separating AI’s Technological Problems from Its Capitalism Problems
The rapid advancement of artificial intelligence (AI) is creating a societal transformation comparable to the Industrial Revolution, yet public distrust in AI is widespread, with many Americans believing it is progressing too quickly and will negatively impact society. This confluence of technological revolution and public apprehension necessitates a clear distinction between the inherent…

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
Fortinet has released patches addressing authentication vulnerabilities in its FortiWeb Web Application Firewall (WAF) and FortiManager centralized management solution. The reported flaws could potentially enable unauthorized access, allowing attackers to log in using arbitrary usernames and passwords or to impersonate FortiGate appliances.

153GB of stolen credentials surface after LiteLLM supply chain attack
A substantial archive of 153GB containing credentials and other sensitive information, reportedly stolen during a supply chain attack involving the open-source proxy gateway LiteLLM, has surfaced. The data is linked to thousands of corporate domains, including major entities like AWS, Samsung, Cisco, and Salesforce.

Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits
A collective of approximately 3,000 lawsuits, initiated by state attorneys general and families, is challenging Meta, Google, ByteDance's TikTok, and Snap over allegations that their platforms are intentionally designed to be addictive and detrimental to the mental health of children and teenagers. The tech companies recently experienced a significant procedural setback in their efforts to…

DDoS attacks hit record scale as 1 Tbps+ campaigns become more common
Distributed denial-of-service (DDoS) attacks reached unprecedented scales in the first half of 2026, with campaigns generating traffic in excess of one terabit per second (Tbps) becoming increasingly common. Cloudflare's H1 2026 DDoS Threat Report indicates a rise in both the volume and sophistication of these attacks, characterized by larger traffic floods, shorter durations, and greater…

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
An ongoing data theft campaign, dubbed "City-Forum" by the SaaS security firm Reco, is targeting data exposed to unauthenticated users through misconfigured Salesforce Experience Cloud and ServiceNow customer portals. The attacks, which are not exploiting vulnerabilities in either platform, have been traced to a single server and are reportedly increasing in volume.

Qualys Introduces Real-Time Cloud Security Posture Management (CSPM) for Faster Risk Detection and Remediation
Qualys has announced the release of Real-Time Cloud Security Posture Management (CSPM), a new capability integrated into the Qualys Cloud Platform designed to provide instant detection and remediation guidance for cloud security risks across multi-cloud environments. The new offering aims to address the limitations of traditional CSPM tools that rely on periodic scans, which can leave…

“Zoomsday” flaws could let one Zoom participant attack another
Three vulnerabilities, collectively dubbed "Zoomsday" by researchers, have been identified in the Zoom meeting platform. These flaws, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, could enable one participant in a Zoom meeting to compromise another through specially crafted collaboration data.

Patch Tuesday: Update now to fix 421 flaws, including three zero-days
Microsoft’s August 2026 Patch Tuesday addresses 421 vulnerabilities across its product line, including 62 rated as critical. The update package, while smaller than July’s record release, remains one of the largest Patch Tuesday batches to date. Among the fixes are three zero-day vulnerabilities, one of which has been actively exploited in the wild by the Lazarus group.

Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure
A joint advisory from U.S. and Republic of Korea authorities has warned that the Gunra ransomware-as-a-service (RaaS) operation is actively exploiting two Fortinet vulnerabilities to target government and critical national infrastructure organizations. The advisory, issued on August 10, was authored by the FBI, CISA, and other U.S. government agencies, alongside the Republic of Korea’s…

Ivanti EPM Update Patches Remotely Exploitable Flaws
Ivanti has released an update for its Endpoint Manager (EPM) software to address several remotely exploitable vulnerabilities. These flaws, if successfully exploited, could lead to the leakage of credentials used for external SQL connections or cause an agent service to crash. The update is critical for maintaining the integrity and availability of systems managed by EPM.

Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
Reports indicate that the Gunra ransomware-as-a-service (RaaS) operation is actively exploiting unpatched vulnerabilities in Fortinet firewalls and VPN appliances to gain initial access to target networks. The gang has reportedly been successful in compromising critical infrastructure organizations, leveraging these flaws to bypass multi-factor authentication (MFA) mechanisms. This activity…

Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Microsoft has reportedly issued its monthly security updates, addressing a substantial number of vulnerabilities, including a Windows kernel driver zero-day that is actively being exploited in the wild. This critical flaw is said to be present in a core Windows kernel driver responsible for managing network socket operations. The update package reportedly includes patches for 398 distinct…

ExfilSquad Targets New Victims, Shares Data via Torrents
The cybercrime group ExfilSquad, which emerged in mid-2026, has announced new victims, targeting 13 organizations across the U.S., the UK, and Sweden. This follows a previous attack in July against a major financial institution in Nigeria. The group's modus operandi involves stealing data and threatening to publish it on a dark web leak site if a ransom is not paid, rather than deploying…