#cloudsecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cloudsecurity, aggregated by home.social.
-
🚨 New HIGH CVE detected in AWS Lambda 🚨
CVE-2026-73566 impacts tar in 3 Lambda base images.Details: https://github.com/aws/aws-lambda-base-images/issues/674
More: https://lambdawatchdog.com/ -
🚨 New HIGH CVE detected in AWS Lambda 🚨
CVE-2026-73566 impacts tar in 3 Lambda base images.Details: https://github.com/aws/aws-lambda-base-images/issues/674
More: https://lambdawatchdog.com/ -
🚨 New HIGH CVE detected in AWS Lambda 🚨
CVE-2026-73566 impacts tar in 3 Lambda base images.Details: https://github.com/aws/aws-lambda-base-images/issues/674
More: https://lambdawatchdog.com/ -
🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 43 CVEs across 25 images:
• 🔴 Critical: 2
• 🟠 High: 15
• 🟡 Medium: 21
• 🔵 Low: 5
Check the full report 👉 https://lambdawatchdog.com/
#AWS #Lambda #CVE #CloudSecurity #Serverless -
🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 43 CVEs across 25 images:
• 🔴 Critical: 2
• 🟠 High: 15
• 🟡 Medium: 21
• 🔵 Low: 5
Check the full report 👉 https://lambdawatchdog.com/
#AWS #Lambda #CVE #CloudSecurity #Serverless -
🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 43 CVEs across 25 images:
• 🔴 Critical: 2
• 🟠 High: 15
• 🟡 Medium: 21
• 🔵 Low: 5
Check the full report 👉 https://lambdawatchdog.com/
#AWS #Lambda #CVE #CloudSecurity #Serverless -
CRITICAL (CVSS 9.3): CVE-2026-12710 in Google Cloud Application Integration (QueryEngineTask) enabled unauthorized data access. Patched by Google on 2026-04-04 — no customer action needed. Details: https://radar.offseq.com/threat/cve-2026-12710-cwe-862-missing-authorization-in-google-cloud-application-integration-f732bf9f6ab56812 #OffSeq #CloudSecurity #CVE #Vuln
-
CRITICAL (CVSS 9.3): CVE-2026-12710 in Google Cloud Application Integration (QueryEngineTask) enabled unauthorized data access. Patched by Google on 2026-04-04 — no customer action needed. Details: https://radar.offseq.com/threat/cve-2026-12710-cwe-862-missing-authorization-in-google-cloud-application-integration-f732bf9f6ab56812 #OffSeq #CloudSecurity #CVE #Vuln
-
CRITICAL (CVSS 9.3): CVE-2026-12710 in Google Cloud Application Integration (QueryEngineTask) enabled unauthorized data access. Patched by Google on 2026-04-04 — no customer action needed. Details: https://radar.offseq.com/threat/cve-2026-12710-cwe-862-missing-authorization-in-google-cloud-application-integration-f732bf9f6ab56812 #OffSeq #CloudSecurity #CVE #Vuln
-
CRITICAL (CVSS 9.3): CVE-2026-12710 in Google Cloud Application Integration (QueryEngineTask) enabled unauthorized data access. Patched by Google on 2026-04-04 — no customer action needed. Details: https://radar.offseq.com/threat/cve-2026-12710-cwe-862-missing-authorization-in-google-cloud-application-integration-f732bf9f6ab56812 #OffSeq #CloudSecurity #CVE #Vuln
-
Truffle Security's long-term monitoring uncovered 9,300+ active AWS keys sitting in public repositories and paste sites. Over 500 were root-level credentials. Hundreds carried full admin privileges. These are open invitations to take over cloud environments, and many remain valid today.
#AWSExposedKeys #CloudSecurity #IAMSecurity #ThreatResearch
https://cyberworldops.eu/en/more-than-9300-active-aws-keys-exposed-online-hundreds-could-grant
-
Reward: You've unlocked the Cardboard Vault — a decorative trophy shaped like a cloud with a very large, unguarded door.
#Cybersecurity #DataBreach #PrivateEquity #SocialEngineering #CloudSecurity #BreachAlert (3/3)
-
Reward: You've unlocked the Cardboard Vault — a decorative trophy shaped like a cloud with a very large, unguarded door.
#Cybersecurity #DataBreach #PrivateEquity #SocialEngineering #CloudSecurity #BreachAlert (3/3)
-
Reward: You've unlocked the Cardboard Vault — a decorative trophy shaped like a cloud with a very large, unguarded door.
#Cybersecurity #DataBreach #PrivateEquity #SocialEngineering #CloudSecurity #BreachAlert (3/3)
-
Google-synced passkeys can be hijacked by malware already running on Windows, researchers found, without breaking passkey cryptography. 🔐
Three “Pass-ta-key” attacks can abuse device trust, recovery, or extract the master key. ⚠️#TechNews #Passkeys #Google #Cybersecurity #Malware #Authentication #Privacy #Security #Encryption #Identity #CloudSecurity #Technology #Infosec
-
Google-synced passkeys can be hijacked by malware already running on Windows, researchers found, without breaking passkey cryptography. 🔐
Three “Pass-ta-key” attacks can abuse device trust, recovery, or extract the master key. ⚠️#TechNews #Passkeys #Google #Cybersecurity #Malware #Authentication #Privacy #Security #Encryption #Identity #CloudSecurity #Technology #Infosec
-
Google-synced passkeys can be hijacked by malware already running on Windows, researchers found, without breaking passkey cryptography. 🔐
Three “Pass-ta-key” attacks can abuse device trust, recovery, or extract the master key. ⚠️#TechNews #Passkeys #Google #Cybersecurity #Malware #Authentication #Privacy #Security #Encryption #Identity #CloudSecurity #Technology #Infosec
-
Google-synced passkeys can be hijacked by malware already running on Windows, researchers found, without breaking passkey cryptography. 🔐
Three “Pass-ta-key” attacks can abuse device trust, recovery, or extract the master key. ⚠️#TechNews #Passkeys #Google #Cybersecurity #Malware #Authentication #Privacy #Security #Encryption #Identity #CloudSecurity #Technology #Infosec
-
Google-synced passkeys can be hijacked by malware already running on Windows, researchers found, without breaking passkey cryptography. 🔐
Three “Pass-ta-key” attacks can abuse device trust, recovery, or extract the master key. ⚠️#TechNews #Passkeys #Google #Cybersecurity #Malware #Authentication #Privacy #Security #Encryption #Identity #CloudSecurity #Technology #Infosec
-
Apache CloudStack patched 20 flaws. CVE-2026-50112, a critical bug, allows cross-tenant remote code execution as root on KVM hypervisor hosts.
#ApacheCloudStack #CVE202650112 #RCE #KVM #CloudSecurity #IaaS
-
Apache CloudStack patched 20 flaws. CVE-2026-50112, a critical bug, allows cross-tenant remote code execution as root on KVM hypervisor hosts.
#ApacheCloudStack #CVE202650112 #RCE #KVM #CloudSecurity #IaaS
-
Apache CloudStack patched 20 flaws. CVE-2026-50112, a critical bug, allows cross-tenant remote code execution as root on KVM hypervisor hosts.
#ApacheCloudStack #CVE202650112 #RCE #KVM #CloudSecurity #IaaS
-
27M Records Exposed Via Misconfigured Microsoft Power Pages
Extortion group ExfilSquad claims to have stolen over 27 million records from 13 organizations including governments and airlines through publicly accessible Microsoft Power Pages portals.
https://pulseofnations.lol/27m-records-exposed-via/
#CloudSecurity #DataBreach #Dataverse #Dynamics365 #Enterprise #Exfilsquad #Microsoft #PowerPages
-
🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 51 CVEs across 25 images:
• 🔴 Critical: 2
• 🟠 High: 22
• 🟡 Medium: 22
• 🔵 Low: 5
Check the full report 👉 https://lambdawatchdog.com/
#AWS #Lambda #CVE #CloudSecurity #Serverless -
🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 51 CVEs across 25 images:
• 🔴 Critical: 2
• 🟠 High: 22
• 🟡 Medium: 22
• 🔵 Low: 5
Check the full report 👉 https://lambdawatchdog.com/
#AWS #Lambda #CVE #CloudSecurity #Serverless -
🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 51 CVEs across 25 images:
• 🔴 Critical: 2
• 🟠 High: 22
• 🟡 Medium: 22
• 🔵 Low: 5
Check the full report 👉 https://lambdawatchdog.com/
#AWS #Lambda #CVE #CloudSecurity #Serverless -
Truffle Security found leaked corporate AWS keys holding full control. See how leaked corporate AWS keys admin rights expose enterprise cloud accounts.
#AWS #CloudSecurity #DataLeak #TruffleSecurity #InfoSec
https://securityonline.info/leaked-corporate-aws-keys/?utm_source=mastodon&utm_medium=jetpack_social
-
Truffle Security found leaked corporate AWS keys holding full control. See how leaked corporate AWS keys admin rights expose enterprise cloud accounts.
#AWS #CloudSecurity #DataLeak #TruffleSecurity #InfoSec
https://securityonline.info/leaked-corporate-aws-keys/?utm_source=mastodon&utm_medium=jetpack_social
-
Truffle Security found leaked corporate AWS keys holding full control. See how leaked corporate AWS keys admin rights expose enterprise cloud accounts.
#AWS #CloudSecurity #DataLeak #TruffleSecurity #InfoSec
https://securityonline.info/leaked-corporate-aws-keys/?utm_source=mastodon&utm_medium=jetpack_social
-
Protecting your breakglass accounts: https://marshsecurity.org/securing-your-breakglass-accounts/
Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.
In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.
The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.Read the blog: https://marshsecurity.org/securing-your-breakglass-accounts/
#Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity
-
Protecting your breakglass accounts: https://marshsecurity.org/securing-your-breakglass-accounts/
Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.
In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.
The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.Read the blog: https://marshsecurity.org/securing-your-breakglass-accounts/
#Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity
-
Protecting your breakglass accounts: https://marshsecurity.org/securing-your-breakglass-accounts/
Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.
In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.
The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.Read the blog: https://marshsecurity.org/securing-your-breakglass-accounts/
#Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity
-
Protecting your breakglass accounts: https://marshsecurity.org/securing-your-breakglass-accounts/
Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.
In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.
The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.Read the blog: https://marshsecurity.org/securing-your-breakglass-accounts/
#Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity
-
Protecting your breakglass accounts: https://marshsecurity.org/securing-your-breakglass-accounts/
Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.
In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.
The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.Read the blog: https://marshsecurity.org/securing-your-breakglass-accounts/
#Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity
-
Sakura Internet disclosed a breach of its customer management system affecting 1.36 million accounts, though passwords were hashed and salted and no ransom was demanded.
#SakuraInternet #DataBreach #Japan #CloudSecurity #CyberSecurity
-
Sakura Internet disclosed a breach of its customer management system affecting 1.36 million accounts, though passwords were hashed and salted and no ransom was demanded.
#SakuraInternet #DataBreach #Japan #CloudSecurity #CyberSecurity
-
Sakura Internet disclosed a breach of its customer management system affecting 1.36 million accounts, though passwords were hashed and salted and no ransom was demanded.
#SakuraInternet #DataBreach #Japan #CloudSecurity #CyberSecurity
-
CVE-2026-69836, a CVSS 10 Entra ID remote code execution flaw, was exploited in the wild. Microsoft has fully mitigated it server-side.
#CVE202669836 #EntraID #RemoteCodeExecution #Microsoft #CloudSecurity #RCE
-
CVE-2026-69836, a CVSS 10 Entra ID remote code execution flaw, was exploited in the wild. Microsoft has fully mitigated it server-side.
#CVE202669836 #EntraID #RemoteCodeExecution #Microsoft #CloudSecurity #RCE
-
CVE-2026-69836, a CVSS 10 Entra ID remote code execution flaw, was exploited in the wild. Microsoft has fully mitigated it server-side.
#CVE202669836 #EntraID #RemoteCodeExecution #Microsoft #CloudSecurity #RCE
-
CVE-2026-69836, a CVSS 10 Entra ID remote code execution flaw, was exploited in the wild. Microsoft has fully mitigated it server-side.
#CVE202669836 #EntraID #RemoteCodeExecution #Microsoft #CloudSecurity #RCE
-
CVE-2026-69836, a CVSS 10 Entra ID remote code execution flaw, was exploited in the wild. Microsoft has fully mitigated it server-side.
#CVE202669836 #EntraID #RemoteCodeExecution #Microsoft #CloudSecurity #RCE
-
CVE-2026-77176 lets a malicious operator mount arbitrary guest rootfs paths in Kata Containers Confidential Containers setups. Update to Kata 4.1.0.
#CVE202677176 #KataContainers #ConfidentialContainers #CloudSecurity #genpolicy #infosec
-
CVE-2026-77176 lets a malicious operator mount arbitrary guest rootfs paths in Kata Containers Confidential Containers setups. Update to Kata 4.1.0.
#CVE202677176 #KataContainers #ConfidentialContainers #CloudSecurity #genpolicy #infosec
-
CVE-2026-77176 lets a malicious operator mount arbitrary guest rootfs paths in Kata Containers Confidential Containers setups. Update to Kata 4.1.0.
#CVE202677176 #KataContainers #ConfidentialContainers #CloudSecurity #genpolicy #infosec
-
CVE-2026-77176 lets a malicious operator mount arbitrary guest rootfs paths in Kata Containers Confidential Containers setups. Update to Kata 4.1.0.
#CVE202677176 #KataContainers #ConfidentialContainers #CloudSecurity #genpolicy #infosec
-
CISA has detected active exploitation of CVE-2026-64849, a critical SSRF in MLflow. Exposed tracking servers without authentication can be abused to query cloud metadata, internal services, and loopback addresses, leading to credential theft and internal reconnaissance.
#CloudSecurity #SSRF #Vulnerability #ThreatIntel
https://cyberworldops.eu/en/mlflow-under-attack-critical-ssrf-exposes-cloud-credentials-and
-
🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 51 CVEs across 25 images:
• 🔴 Critical: 2
• 🟠 High: 22
• 🟡 Medium: 22
• 🔵 Low: 5
Check the full report 👉 https://lambdawatchdog.com/
#AWS #Lambda #CVE #CloudSecurity #Serverless -
Cloudflare Workers Spectre Leaks JWT Tokens
Researchers extract authentication tokens from co-located cloud workers at 12 bits per second, 360 times faster than a 2021 attack
https://pulseofnations.lol/cloudflare-workers/
#CloudSecurity #Cloudflare #JwtLeak #Research #SideChannel #Spectre #Vulnerability #WebSecurity
-
Cloudflare Workers Spectre Leaks JWT Tokens
Researchers extract authentication tokens from co-located cloud workers at 12 bits per second, 360 times faster than a 2021 attack
https://pulseofnations.lol/cloudflare-workers/
#CloudSecurity #Cloudflare #JwtLeak #Research #SideChannel #Spectre #Vulnerability #WebSecurity
-
Cloudflare Workers Spectre Leaks JWT Tokens
Researchers extract authentication tokens from co-located cloud workers at 12 bits per second, 360 times faster than a 2021 attack
https://pulseofnations.lol/cloudflare-workers/
#CloudSecurity #Cloudflare #JwtLeak #Research #SideChannel #Spectre #Vulnerability #WebSecurity
-
Cloudflare Workers Spectre Leaks JWT Tokens
Researchers extract authentication tokens from co-located cloud workers at 12 bits per second, 360 times faster than a 2021 attack
https://pulseofnations.lol/cloudflare-workers/
#CloudSecurity #Cloudflare #JwtLeak #Research #SideChannel #Spectre #Vulnerability #WebSecurity
-
Cloudflare Workers Spectre Leaks JWT Tokens
Researchers extract authentication tokens from co-located cloud workers at 12 bits per second, 360 times faster than a 2021 attack
https://pulseofnations.lol/cloudflare-workers/
#CloudSecurity #Cloudflare #JwtLeak #Research #SideChannel #Spectre #Vulnerability #WebSecurity
-
Red Hat ACM privilege escalation flaws (CVE-2026-70496, CVSS 9.9) let attackers seize full cluster control. See the three Kubernetes bugs.
#RedHat #Kubernetes #PrivilegeEscalation #CVE #ACM #CloudSecurity #InfoSec
-
Red Hat ACM privilege escalation flaws (CVE-2026-70496, CVSS 9.9) let attackers seize full cluster control. See the three Kubernetes bugs.
#RedHat #Kubernetes #PrivilegeEscalation #CVE #ACM #CloudSecurity #InfoSec
-
Red Hat ACM privilege escalation flaws (CVE-2026-70496, CVSS 9.9) let attackers seize full cluster control. See the three Kubernetes bugs.
#RedHat #Kubernetes #PrivilegeEscalation #CVE #ACM #CloudSecurity #InfoSec
-
Security researchers achieved a remote Spectre-based side-channel attack on Cloudflare Workers, extracting a JWT from co-located production Workers at 12 bits per second with over 99% accuracy.
#SpectreAttack #CloudSecurity #SideChannelVulnerability #ServerlessSecurity
https://cyberworldops.eu/en/cloudflare-workers-spectre-exfiltrates-a-jwt-at-12-bits-per-second
-
🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 51 CVEs across 25 images:
• 🔴 Critical: 2
• 🟠 High: 22
• 🟡 Medium: 22
• 🔵 Low: 5
Check the full report 👉 https://lambdawatchdog.com/
#AWS #Lambda #CVE #CloudSecurity #Serverless -
🚨 Lambda Watchdog CVE Report 🚨
Latest AWS Lambda image scan detected 51 CVEs across 25 images:
• 🔴 Critical: 2
• 🟠 High: 22
• 🟡 Medium: 22
• 🔵 Low: 5
Check the full report 👉 https://lambdawatchdog.com/
#AWS #Lambda #CVE #CloudSecurity #Serverless -
Why is SSRF still one of the most critical threats to cloud infrastructure? Our latest analysis dives into the technical mechanics of Server-Side Request Forgery, its impact on IMDS, and why security teams need to stay vigilant. Read the full breakdown: https://cvedatabase.com/blog/the-silent-threat-to-cloud-environments-a-deep-dive-into-server-side-request-for-2026-08-17 #SSRF #CloudSecurity #Infosec