AI
Fake OpenAI, Anthropic and DeepSeek Crawlers Target .env Files and Cloud Credentials
Threat actors are impersonating AI web crawlers from organizations such as OpenAI, Anthropic, DeepSeek, Google, Perplexity, and Amazon to scan internet-facing servers for exposed secrets, according to a GreyNoise...
Cloud
Google Cloud Vertex AI Vulnerability Lets Attackers Take Over and Poison AI Models
A critical vulnerability in Google Cloud's Vertex AI has been discovered, allowing attackers to hijack machine learning model uploads, poison artifacts, and achieve cross-tenant...
Amazon
Attackers Exploit Cloud Logging Platforms to Hide Malicious Activity
Attackers are increasingly targeting cloud logging platforms to evade detection and maintain persistent visibility into compromised environments.
The report highlights how critical services such as...
Cloud
WhatsApp Tests Encrypted Cloud Backup Service for Safer Message Storage
WhatsApp is actively developing an independent, first-party cloud backup service featuring mandatory end-to-end encryption.
This upcoming feature aims to reduce users' reliance on third-party...
Cloud
Most Important Key Factors Organizations Should Consider in Implementing the Cloud Security Solutions
Cloud Security Solutions is one of the challenging tasks while performing the cloud migration for any organization and they need to ensure the best...
Cloud
Threat Actors Breach Global Companies Using Leaked Cloud Credentials
A sophisticated cybercriminal operating under the moniker "Zestix" (alias "Sentap") has successfully infiltrated approximately 50 major global enterprises through a deceptively devastating yet straightforward...
Cloud
Top 10 Best Cloud Workload Protection Platforms (CWPP) in 2026
The cloud landscape in 2026 continues its unprecedented growth, with organizations of all sizes rapidly migrating critical workloads to public, private, and hybrid cloud...
Cloud
Top 10 Best Cloud Access Security Brokers (CASB) in 2026
The year 2026 marks a new era in enterprise cloud adoption, characterized by a complex tapestry of Software-as-a-Service (SaaS) applications, Infrastructure-as-a-Service (IaaS) platforms, and...
Cloud
Hackers Exploit OAuth Apps to Keep Cloud Access Even After Password Resets
Cloud account takeover attacks have evolved beyond simple credential theft. Cybercriminals are now exploiting OAuth applications to maintain persistent access to compromised environments, bypassing...
Cloud
Hackers Abuse IMDS Service for Cloud Initial Access
Cloud environments rely on the Instance Metadata Service (IMDS) to provide virtual machines with temporary credentials and essential configuration data.
IMDS allows applications to securely...
Cloud
God Mode Vulnerability Lets Attackers Access Any Resource in Microsoft Cloud Tenants
A recently disclosed flaw, tracked as CVE-2025-55241, allowed any attacker in possession of a single “Actor token” from a test or lab tenant to...