cloud security
77 stories on cloud security, newest first, from 78 briefings. Each is a plain-language summary written here for Australian business, with a link to the original reporting. Where several outlets covered the same event, the rest sit under it as extra coverage.
- Wiz Launches New Program to Help MSPs Deliver Cloud Security at Scale
- AI Integration Tool 'MCP' Found Riddled with Governance Blind Spots
- Attackers Hijack Azure Service Accounts to Wipe Cloud Resources
- OpenAI Halts Advanced Model Training After AI Agents Behave Unexpectedly
- US Soldier Jailed Nearly Six Years Over AT&T and Verizon Data Extortion
- Former US Army Soldier Sentenced Over AT&T and Snowflake Extortion Spree
- Stolen Credentials: How Infostealer Malware Opens the Door to Your Cloud and Code Systems
- AI Is Making Cyberattacks Cheaper and Faster to Retry, Researchers Warn
- Cloudflare Patches Container Flaw That Exposed Other Customers' Leftover Data
- Wiz Recognised as a Leader in Forrester's Proactive Security Platforms Report
- Rethinking Edge Security: A Practical Path to SASE
- Forgotten Service Accounts Leave Microsoft 365 Environments Exposed
- Why More Businesses Are Turning to SASE for Network Security
- Watchdog: Most US Federal Agencies Missed Deadline for Cloud Security Rules
- Unpatched Ubuntu Kernel Flaw Lets Attackers Escape Containers and Take Over the Host
- Microsoft Takes Down Major Phishing Service Targeting Microsoft 365 Accounts
- Wiz Expands AI Security Ecosystem with New Agent Integration Tools
- How AWS Automatically Locks Down Leaked Cloud Credentials
- Why Knowing Who Has Access Is the New Frontline of Cyber Defence
- Why Multi-Factor Authentication Alone Won't Stop OAuth Consent Abuse
- Microsoft Fixes Maximum-Severity Flaw in Azure AI Foundry
- AWS AI Agent Tool Could Let Attackers Steal Credentials via Prompt Injection
- Modern Attacks Don't Stay in One Place, So Your Defences Shouldn't Either
- London Property Manager Breach Exposes Bank Details and Key Lockbox Codes
- New AWS Sign-Up Sandbox Leaves Security Gaps, Research Finds
- New US Guidance Targets Weak Links in Cloud Login Tokens
- New Phishing Kit 'N0va' Hijacks Logins by Abusing Real Authentication Systems
- Behind the Betting Wheel: How Illegal Gambling Sites Hide Serious Cyber Threats
- Wiz and Google Join Forces to Speed Up Cloud Threat Investigations
- New Guidance Aims to Stop Attackers Forging Login Tokens in Cloud Systems
- Attackers Are Scanning for Exposed Vite Dev Servers to Steal Cloud Credentials
- Researchers Uncover Hardware Flaw That Can Break 'Confidential Computing' Protections
- New 'DDRop' Attack Undermines Intel and AMD Confidential Computing Protections
- Human Hacker Beats AI-Speed Attacks: Marimo Notebook Flaw Exploited in Eight Seconds
- Cyber Warfare Spending Set to Nearly Double by 2031, Report Finds
- New Research Uses Behaviour Patterns to Spot Fake or Malicious Cloud Identities
- Microsoft Warns of AI-Powered CEO Fraud and Passkey Phishing Targeting Cloud Accounts
- Wiz Cloud Security Platform Earns High-Level Government Authorization
- Research Reveals How Root Access Can Undermine Kubernetes Identity Systems
- Default Admin Key Left Thousands of AI Gateways Wide Open
- Critical Flaws in Popular AI Gateway LiteLLM Let Attackers Hijack Servers and Steal Cloud Credentials
- Webinar Tackles the Toughest Question After a New CVE: Are We Exposed?
- New Cybercrime Group 'Slim Spider' Targets Brazilian Banks' Crypto and Instant Payment Systems
- AI-Powered Attacks Are Speeding Up: Google Warns of Autonomous Hacking Campaigns
- AI-Powered Attackers Are Now Stealing Credentials in Hours, Not Days
- One-Size Cloud Security Checklists Don't Work: Each Provider Fails Differently
- Weekly Roundup: Microsoft Cloud Fixes, Dropbox Account Breach, and a Billion-Dollar Security Startup
- Dropbox Confirms Breach Affecting About 5,000 Accounts
- 9.5 Million Affected in Major Healthcare Data Breach at Aesto Health
- AI Research Nonprofit METR Hit by API Key Theft, Racks Up $600,000 in Unauthorised AI Usage
- Cloudflare's New Defence Aims to Make Cyberattacks Too Costly for Criminals
- Hundreds of AI Agents Teamed Up to Breach Hugging Face Servers
- Why 'Identity Fabric' Is Becoming a Must-Have for Business Security in 2026
- Password Vault Flaw Puts MSP and SMB Credentials at Risk
- Critical MLflow Flaw Being Exploited to Steal Cloud Credentials
- CrowdStrike Recognised as Top Performer in Cloud Security Rankings
- Researchers Demonstrate Data-Leaking Attack on Cloudflare Workers
- New 'TwinLoot' Malware Hides Inside Microsoft's Own Cloud Services
- Iranian Hackers Refine 'Cavern' Malware to Hide Inside Everyday Web Traffic
- Hackers Claim Massive Data Theft from Microsoft Azure, Targeting Major Global Brands
- Google Cloud Charts Path to Quantum-Safe Security by 2029
- Beacon CRM Breach Exposes Data from Over 1,000 Charities
- Long-Running 'City-Forum' Campaign Targets Salesforce and ServiceNow Data
- Brief but Dangerous: Malicious LiteLLM Package May Have Hit 2,100+ Organisations
- New Startup Aims to Close Security Gaps in AI Cloud Infrastructure
- OpenAI's AI Agents Accidentally Attacked Hugging Face, Timeline Reveals
- Microsoft and Apple Roll Out Critical Security Patches — Update Now
- New 'Zapscape' Flaw Could Let Attackers Break Out of Virtual Machines
-
Canadian Man Pleads Guilty to Snowflake Data Extortion Spree
Also covered by Krebs on Security
- Snowflake Hacker Pleads Guilty in US Court
- Same Scammers, New Names: Vishing Extortion Gang Rebrands to Evade Detection
- Security Gaps in AWS, Google and Vercel AI Agent Tools Could Let Attackers Bypass Safety Checks
- Hacker Pleads Guilty in Massive Data Breach Affecting 100 Million People
- Critical Flaws Patched in Veeam, HashiCorp Terraform MCP, and Django - Update Now
- New Phishing Kit 'Kali365' Tricks Users Into Approving Attacker Logins on Real Microsoft Pages
- Exposed Cloud Functions: A Growing Entry Point for Attackers
- CISA's GitHub Credential Leak: A Wake-Up Call for Secure Code Practices