home.social

#cloudsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cloudsecurity, aggregated by home.social.

fetched live
  1. 🚨 New HIGH CVE detected in AWS Lambda 🚨
    CVE-2026-73566 impacts tar in 3 Lambda base images.

    Details: github.com/aws/aws-lambda-base
    More: lambdawatchdog.com/

  2. 🚨 Lambda Watchdog CVE Report 🚨
    Latest AWS Lambda image scan detected 43 CVEs across 25 images:
    • 🔴 Critical: 2
    • 🟠 High: 15
    • 🟡 Medium: 21
    • 🔵 Low: 5

    Check the full report 👉 lambdawatchdog.com/
    #AWS #Lambda #CVE #CloudSecurity #Serverless

  3. 🚨 Lambda Watchdog CVE Report 🚨
    Latest AWS Lambda image scan detected 43 CVEs across 25 images:
    • 🔴 Critical: 2
    • 🟠 High: 15
    • 🟡 Medium: 21
    • 🔵 Low: 5

    Check the full report 👉 lambdawatchdog.com/
    #AWS #Lambda #CVE #CloudSecurity #Serverless

  4. 🚨 Lambda Watchdog CVE Report 🚨
    Latest AWS Lambda image scan detected 43 CVEs across 25 images:
    • 🔴 Critical: 2
    • 🟠 High: 15
    • 🟡 Medium: 21
    • 🔵 Low: 5

    Check the full report 👉 lambdawatchdog.com/

  5. CRITICAL (CVSS 9.3): CVE-2026-12710 in Google Cloud Application Integration (QueryEngineTask) enabled unauthorized data access. Patched by Google on 2026-04-04 — no customer action needed. Details: radar.offseq.com/threat/cve-20 #OffSeq #CloudSecurity #CVE #Vuln

  6. CRITICAL (CVSS 9.3): CVE-2026-12710 in Google Cloud Application Integration (QueryEngineTask) enabled unauthorized data access. Patched by Google on 2026-04-04 — no customer action needed. Details: radar.offseq.com/threat/cve-20 #OffSeq #CloudSecurity #CVE #Vuln

  7. CRITICAL (CVSS 9.3): CVE-2026-12710 in Google Cloud Application Integration (QueryEngineTask) enabled unauthorized data access. Patched by Google on 2026-04-04 — no customer action needed. Details: radar.offseq.com/threat/cve-20 #OffSeq #CloudSecurity #CVE #Vuln

  8. CRITICAL (CVSS 9.3): CVE-2026-12710 in Google Cloud Application Integration (QueryEngineTask) enabled unauthorized data access. Patched by Google on 2026-04-04 — no customer action needed. Details: radar.offseq.com/threat/cve-20 #OffSeq #CloudSecurity #CVE #Vuln

  9. Truffle Security's long-term monitoring uncovered 9,300+ active AWS keys sitting in public repositories and paste sites. Over 500 were root-level credentials. Hundreds carried full admin privileges. These are open invitations to take over cloud environments, and many remain valid today.

    #AWSExposedKeys #CloudSecurity #IAMSecurity #ThreatResearch

    cyberworldops.eu/en/more-than-

  10. Google-synced passkeys can be hijacked by malware already running on Windows, researchers found, without breaking passkey cryptography. 🔐
    Three “Pass-ta-key” attacks can abuse device trust, recovery, or extract the master key. ⚠️

    🔗 bleepingcomputer.com/news/secu

    #TechNews #Passkeys #Google #Cybersecurity #Malware #Authentication #Privacy #Security #Encryption #Identity #CloudSecurity #Technology #Infosec

  11. Google-synced passkeys can be hijacked by malware already running on Windows, researchers found, without breaking passkey cryptography. 🔐
    Three “Pass-ta-key” attacks can abuse device trust, recovery, or extract the master key. ⚠️

    🔗 bleepingcomputer.com/news/secu

    #TechNews #Passkeys #Google #Cybersecurity #Malware #Authentication #Privacy #Security #Encryption #Identity #CloudSecurity #Technology #Infosec

  12. Google-synced passkeys can be hijacked by malware already running on Windows, researchers found, without breaking passkey cryptography. 🔐
    Three “Pass-ta-key” attacks can abuse device trust, recovery, or extract the master key. ⚠️

    🔗 bleepingcomputer.com/news/secu

    #TechNews #Passkeys #Google #Cybersecurity #Malware #Authentication #Privacy #Security #Encryption #Identity #CloudSecurity #Technology #Infosec

  13. Google-synced passkeys can be hijacked by malware already running on Windows, researchers found, without breaking passkey cryptography. 🔐
    Three “Pass-ta-key” attacks can abuse device trust, recovery, or extract the master key. ⚠️

    🔗 bleepingcomputer.com/news/secu

    #TechNews #Passkeys #Google #Cybersecurity #Malware #Authentication #Privacy #Security #Encryption #Identity #CloudSecurity #Technology #Infosec

  14. Google-synced passkeys can be hijacked by malware already running on Windows, researchers found, without breaking passkey cryptography. 🔐
    Three “Pass-ta-key” attacks can abuse device trust, recovery, or extract the master key. ⚠️

    🔗 bleepingcomputer.com/news/secu

    #TechNews #Passkeys #Google #Cybersecurity #Malware #Authentication #Privacy #Security #Encryption #Identity #CloudSecurity #Technology #Infosec

  15. 27M Records Exposed Via Misconfigured Microsoft Power Pages

    Extortion group ExfilSquad claims to have stolen over 27 million records from 13 organizations including governments and airlines through publicly accessible Microsoft Power Pages portals.

    pulseofnations.lol/27m-records

    #CloudSecurity #DataBreach #Dataverse #Dynamics365 #Enterprise #Exfilsquad #Microsoft #PowerPages

  16. 🚨 Lambda Watchdog CVE Report 🚨
    Latest AWS Lambda image scan detected 51 CVEs across 25 images:
    • 🔴 Critical: 2
    • 🟠 High: 22
    • 🟡 Medium: 22
    • 🔵 Low: 5

    Check the full report 👉 lambdawatchdog.com/
    #AWS #Lambda #CVE #CloudSecurity #Serverless

  17. 🚨 Lambda Watchdog CVE Report 🚨
    Latest AWS Lambda image scan detected 51 CVEs across 25 images:
    • 🔴 Critical: 2
    • 🟠 High: 22
    • 🟡 Medium: 22
    • 🔵 Low: 5

    Check the full report 👉 lambdawatchdog.com/
    #AWS #Lambda #CVE #CloudSecurity #Serverless

  18. 🚨 Lambda Watchdog CVE Report 🚨
    Latest AWS Lambda image scan detected 51 CVEs across 25 images:
    • 🔴 Critical: 2
    • 🟠 High: 22
    • 🟡 Medium: 22
    • 🔵 Low: 5

    Check the full report 👉 lambdawatchdog.com/

  19. Protecting your breakglass accounts: marshsecurity.org/securing-you

    Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.

    In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.

    The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
    If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.

    Read the blog: marshsecurity.org/securing-you

    #Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity

  20. Protecting your breakglass accounts: marshsecurity.org/securing-you

    Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.

    In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.

    The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
    If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.

    Read the blog: marshsecurity.org/securing-you

    #Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity

  21. Protecting your breakglass accounts: marshsecurity.org/securing-you

    Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.

    In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.

    The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
    If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.

    Read the blog: marshsecurity.org/securing-you

    #Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity

  22. Protecting your breakglass accounts: marshsecurity.org/securing-you

    Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.

    In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.

    The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
    If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.

    Read the blog: marshsecurity.org/securing-you

    #Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity

  23. Protecting your breakglass accounts: marshsecurity.org/securing-you

    Breakglass accounts are one of those controls that everyone agrees are important, yet they're frequently overlooked when it comes to ongoing security hygiene.

    In my latest blog. I discuss practical approaches to securing Microsoft emergency access accounts.

    The goal of a break glass account is to help you recover from an identity-related outage, not become the cause of your next security incident.
    If you're working with Entra ID, Microsoft 365, Defender, or Zero Trust architectures, I'd be interested to hear how your organisation approaches emergency access.

    Read the blog: marshsecurity.org/securing-you

    #Microsoft365 #EntraID #MicrosoftDefender #CyberSecurity #SecurityArchitecture #ZeroTrust #CloudSecurity #IdentityAccessManagement #IAM #CyberDefence #SecurityEngineering #InfoSec #M365 #TechCommunity

  24. CISA has detected active exploitation of CVE-2026-64849, a critical SSRF in MLflow. Exposed tracking servers without authentication can be abused to query cloud metadata, internal services, and loopback addresses, leading to credential theft and internal reconnaissance.

    #CloudSecurity #SSRF #Vulnerability #ThreatIntel

    cyberworldops.eu/en/mlflow-und

  25. 🚨 Lambda Watchdog CVE Report 🚨
    Latest AWS Lambda image scan detected 51 CVEs across 25 images:
    • 🔴 Critical: 2
    • 🟠 High: 22
    • 🟡 Medium: 22
    • 🔵 Low: 5

    Check the full report 👉 lambdawatchdog.com/

  26. Cloudflare Workers Spectre Leaks JWT Tokens

    Researchers extract authentication tokens from co-located cloud workers at 12 bits per second, 360 times faster than a 2021 attack

    pulseofnations.lol/cloudflare-

    #CloudSecurity #Cloudflare #JwtLeak #Research #SideChannel #Spectre #Vulnerability #WebSecurity

  27. Cloudflare Workers Spectre Leaks JWT Tokens

    Researchers extract authentication tokens from co-located cloud workers at 12 bits per second, 360 times faster than a 2021 attack

    pulseofnations.lol/cloudflare-

    #CloudSecurity #Cloudflare #JwtLeak #Research #SideChannel #Spectre #Vulnerability #WebSecurity

  28. Cloudflare Workers Spectre Leaks JWT Tokens

    Researchers extract authentication tokens from co-located cloud workers at 12 bits per second, 360 times faster than a 2021 attack

    pulseofnations.lol/cloudflare-

    #CloudSecurity #Cloudflare #JwtLeak #Research #SideChannel #Spectre #Vulnerability #WebSecurity

  29. Cloudflare Workers Spectre Leaks JWT Tokens

    Researchers extract authentication tokens from co-located cloud workers at 12 bits per second, 360 times faster than a 2021 attack

    pulseofnations.lol/cloudflare-

    #CloudSecurity #Cloudflare #JwtLeak #Research #SideChannel #Spectre #Vulnerability #WebSecurity

  30. Cloudflare Workers Spectre Leaks JWT Tokens

    Researchers extract authentication tokens from co-located cloud workers at 12 bits per second, 360 times faster than a 2021 attack

    pulseofnations.lol/cloudflare-

    #CloudSecurity #Cloudflare #JwtLeak #Research #SideChannel #Spectre #Vulnerability #WebSecurity

  31. Security researchers achieved a remote Spectre-based side-channel attack on Cloudflare Workers, extracting a JWT from co-located production Workers at 12 bits per second with over 99% accuracy.

    #SpectreAttack #CloudSecurity #SideChannelVulnerability #ServerlessSecurity

    cyberworldops.eu/en/cloudflare

  32. 🚨 Lambda Watchdog CVE Report 🚨
    Latest AWS Lambda image scan detected 51 CVEs across 25 images:
    • 🔴 Critical: 2
    • 🟠 High: 22
    • 🟡 Medium: 22
    • 🔵 Low: 5

    Check the full report 👉 lambdawatchdog.com/
    #AWS #Lambda #CVE #CloudSecurity #Serverless

  33. 🚨 Lambda Watchdog CVE Report 🚨
    Latest AWS Lambda image scan detected 51 CVEs across 25 images:
    • 🔴 Critical: 2
    • 🟠 High: 22
    • 🟡 Medium: 22
    • 🔵 Low: 5

    Check the full report 👉 lambdawatchdog.com/

  34. Why is SSRF still one of the most critical threats to cloud infrastructure? Our latest analysis dives into the technical mechanics of Server-Side Request Forgery, its impact on IMDS, and why security teams need to stay vigilant. Read the full breakdown: cvedatabase.com/blog/the-silen