#cloudsecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cloudsecurity, aggregated by home.social.
-
768 Exposed AWS Keys Grant Full Admin Access
Researchers found 768 still-active AWS access keys with root or admin privileges exposed in public code repositories and AI training datasets.
https://pulseofnations.lol/768-exposed-aws-keys/
#Aws #CloudSecurity #Cybersecurity #DataExposure #LeakedKeys #TruffleSecurity
-
Google-synced passkeys can be hijacked by malware already running on Windows, researchers found, without breaking passkey cryptography. 🔐
Three “Pass-ta-key” attacks can abuse device trust, recovery, or extract the master key. ⚠️#TechNews #Passkeys #Google #Cybersecurity #Malware #Authentication #Privacy #Security #Encryption #Identity #CloudSecurity #Technology #Infosec
-
Apache CloudStack patched 20 flaws. CVE-2026-50112, a critical bug, allows cross-tenant remote code execution as root on KVM hypervisor hosts.
#ApacheCloudStack #CVE202650112 #RCE #KVM #CloudSecurity #IaaS
-
Truffle Security found leaked corporate AWS keys holding full control. See how leaked corporate AWS keys admin rights expose enterprise cloud accounts.
#AWS #CloudSecurity #DataLeak #TruffleSecurity #InfoSec
https://securityonline.info/leaked-corporate-aws-keys/?utm_source=mastodon&utm_medium=jetpack_social
-
Protecting your breakglass accounts: https://marshsecurity.org/securing-your-breakglass-accounts/
Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.
In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.
The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.Read the blog: https://marshsecurity.org/securing-your-breakglass-accounts/
#Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity
-
Sakura Internet disclosed a breach of its customer management system affecting 1.36 million accounts, though passwords were hashed and salted and no ransom was demanded.
#SakuraInternet #DataBreach #Japan #CloudSecurity #CyberSecurity
-
CVE-2026-69836, a CVSS 10 Entra ID remote code execution flaw, was exploited in the wild. Microsoft has fully mitigated it server-side.
#CVE202669836 #EntraID #RemoteCodeExecution #Microsoft #CloudSecurity #RCE
-
CVE-2026-77176 lets a malicious operator mount arbitrary guest rootfs paths in Kata Containers Confidential Containers setups. Update to Kata 4.1.0.
#CVE202677176 #KataContainers #ConfidentialContainers #CloudSecurity #genpolicy #infosec
-
Cloudflare Workers Spectre Leaks JWT Tokens
Researchers extract authentication tokens from co-located cloud workers at 12 bits per second, 360 times faster than a 2021 attack
https://pulseofnations.lol/cloudflare-workers/
#CloudSecurity #Cloudflare #JwtLeak #Research #SideChannel #Spectre #Vulnerability #WebSecurity
-
🛡️ ZapScape (CVE-2026-64561): Vulnerabilitate critică de evadare din mașina virtuală în KVM Linux!Echipa de securitate a dezvăluit detaliile despre ZapScape (identificată ca CVE-2026-64561), o vulnerabilitate critică descoperită în modulul KVM (Kernel-based Virtual Machine) din Linux, care permite evadarea din sandbox-ul mașinii virtuale (VM Escape) bezpośredno pe sistemul gazdă (host).✨ Detaliile tehnice ale vulnerabilității ZapScape:💥 Mecanismul de atac (VM Escape):• Cauzată de o gestionare defectuoasă a memoriei virtualizate la nivelul MMU (Memory Management Unit) în subsistemul KVM, bresa permite unui utilizator cu privilegii de root dintr-un sistem oaspete (guest VM) să scrie direct în memoria fizică a sistemului gazdă.🔓 Execuție de cod la nivel de Kernel (Host Compromise):• Un atac reușit duce la preluarea completă a serverului gazdă (Arbitrary Code Execution în spațiul kernel-ului gazdă), depășind barierele tradiționale de securitate ale hypervisorului.☁️ Impact masiv pentru furnizorii de Cloud & VPS:• Riscul este critic în special pentru infrastructurile de cloud public și furnizorii de găzduire (OpenStack, Proxmox, AWS, Google Cloud), unde atacatorii pot accesa sau compromite datele altor clienți găzduiți pe același nod fizic.🛠️ Soluții și măsuri de remediere:• Patch-urile oficiale au fost integrate de urgență în ramurile stabile ale kernelului Linux. Se recomandă administratorilor de sistem actualizarea imediată a kernelului pe toate nodurile de virtualizare KVM și repornirea infrastructurii.O vulnerabilitate de severitate ridicată ce subliniază încă o dată importanța izolării stricte la nivel de hardware și kernel în mediile de virtualizare! 🚀#ZapScape #CVE202664561 #KVM #Linux #CyberSecurity #Vulnerability #CloudSecurity #SysAdmin #DesdeLinux #TechNews #FOSS
-
🚨 SIGINT // Cybersecurity Watch — 2026-08-18
Fortune 500 companies hit in a sweeping Azure data theft campaign, spotlighting persistent cloud credential abuse risks.
https://www.securityweek.com/fortune-500-companies-hit-in-azure-data-theft-campaign/
#Cybersecurity #CloudSecurity #Azure #DataBreach -
Einordnung: Eigentlich ist das fast unangenehmer als ein Zero-Day. Die Plattformen funktionieren wie vorgesehen, nur die Berechtigungen sind falsch gesetzt. Wer Gastzugriffe ermöglicht, sollte deshalb nicht darauf vertrauen, dass »niemand die URL kennt«. Öffentlich erreichbar bedeutet am Ende eben öffentlich erreichbar.
2/2
-
Google Cloud published a dated PQC migration roadmap on 11 Aug. Nineteen dated entries against named services, which is more resolution than AWS or Microsoft has published.
Domain 1 covers store-now-decrypt-later mitigation - end of 2027. Domain 2 covers integrity and non-repudiation, Domain 3 foundations and key management, and both for 2028. Everything converges on 2029.
Google's March post said it had adjusted its threat model to prioritize authentication and digital signatures. The roadmap now puts signatures a year behind confidentiality anyway.
So I try to explain the change.
https://postquantum.com/security-pqc/google-cloud-pqc-roadmap/
#PQC #postquantum #cryptography #infosec #TLS #PKI #cloudsecurity
-
☁️ Cloud security is about more than the cloud.
Identity, APIs, applications, infrastructure, availability and resilience all need to work together.
📍 SANS Cloud Security Exchange 2026
📅 August 17–23
📌 San FranciscoRELIANOID will be following the conversations around Zero Trust, cloud security, DevSecOps and cyber resilience — and how secure application delivery can help protect modern cloud environments.
🚀 Attending? Let’s connect!
🔗 https://www.relianoid.com/about-us/events/sans-cloud-security-exchange-2026/
-
#Pinterest has revealed the Resource Provisioner Pipeline (RPP) - its own Terraform execution engine.
RPP enforces least-privilege access and dual-control reviews, adding strict guardrails to GitHub Actions workflows and AWS infrastructure.
Read the full story on #InfoQ 👉 https://bit.ly/3RK9Fik
-
Code review can tell you what AI was supposed to do. It can't tell you what it's actually doing in production.
The 2026 Runtime Execution Report from OLIGO Security digs into real-world execution data to show where AI risk truly lives: at runtime.
Thank you, Oligo Security, for supporting AppSec Village at DEF CON 34 this year!
Download the free report
https://www.oligo.security/ai-in-production-the-2026-runtime-execution-report -
Companies need to do better about exposing "dev" systems. This is one of the things I mentioned in my cloud security talk on Saturday. Oh well.
-
Ever wondered what devices are connected to your Dropbox? Our latest guide shows you how to find them all. It's a crucial step for account security, helping you identify lost devices or potential unauthorized access. Keep your files safe and your account secure. #Dropbox #Privacy #CloudSecurity #TechTutorial #Windows
-
OpenStack: 46 CVEs, 89% unpatched, max CVSS 9.9. Trust Score: C. Cloud IaaS risk rising +28% YoY—patch now. #OpenStack #cloudsecurity #infosec
-
CRITICAL: Snowflake accounts hacked — no MFA, stolen creds from infostealer malware led to massive data theft (100M+ affected, $9.5M loss). All orgs: enforce MFA & strong passwords. No CVE assigned. https://radar.offseq.com/threat/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks-21f9fb8717cf2802 #OffSeq #CloudSecurity #ThreatIntel
-
So, phishers are now using the cloud to fish for your credentials? 🎣 Apparently, the internet's favorite hobby is now a "cloud-based service" too. And Kaspersky's got a solution for every possible company size, right down to a one-person startup that just realized their toaster needs cybersecurity! 🍞🔒
https://securelist.com/cloud-platforms-in-phishing/120832/ #phishing #cloudsecurity #Kaspersky #cybersecurity #startups #onlineprivacy #HackerNews #ngated -
Phishers are hijacking legitimate cloud infrastructure
https://securelist.com/cloud-platforms-in-phishing/120832/
Comments: https://news.ycombinator.com/item?id=49185931
#HackerNews #phishing #cloudsecurity #cybersecurity #infosec #threatintelligence
-
🔈 Webinar Gratuito: "Secretos para una Presentación Exitosa de Ciberseguridad" 🎯 Miércoles 12 de Agosto 2026. De 11:00 am a 11:45 am (UTC -05:00) ⌚️ Registro libre: https://docs.google.com/forms/d/e/1FAIpQLScR624fU_3w9gmw5fNmXHxn4-5Ulhd3RpTiMqWQKcYdC7MU7w/viewform #informationsecurity #zerotrust #threatintelligence #cloudsecurity #cybersecurityawareness #cybersecurityjobs -
🎥 New video: our CEO Tobias Hagemann introduces Cryptomator Hub
☁️ Teams keep their most sensitive files in the cloud. But who can actually read them?
🔐 Tobias shows how zero-knowledge encryption works for teams, walks through user and group management, and gives a sneak peek at Hub 2.0.
👉 Watch it now: https://www.youtube.com/watch?v=WLgRIeFQKj8
#Cryptomator #CryptomatorHub #Encryption #CloudSecurity #DataProtection #OpenSource
-
Imagine finding a master key that can create the keys to access almost every Azure Cosmos DB instance on the planet. That's essentially what #CosmosEscape achieved.
One of the most fascinating recent cloud security bugs:
#CloudSecurity
👇
https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db