Friday, September 11, 2026

Cloud

Fake OpenAI, Anthropic and DeepSeek Crawlers Target .env Files and Cloud Credentials

Threat actors are impersonating AI web crawlers from organizations such as OpenAI, Anthropic, DeepSeek, Google, Perplexity, and Amazon to scan internet-facing servers for exposed secrets, according to a GreyNoise...

Google Cloud Vertex AI Vulnerability Lets Attackers Take Over and Poison AI Models

A critical vulnerability in Google Cloud's Vertex AI has been discovered, allowing attackers to hijack machine learning model uploads, poison artifacts, and achieve cross-tenant...

Attackers Exploit Cloud Logging Platforms to Hide Malicious Activity

Attackers are increasingly targeting cloud logging platforms to evade detection and maintain persistent visibility into compromised environments. The report highlights how critical services such as...

WhatsApp Tests Encrypted Cloud Backup Service for Safer Message Storage

WhatsApp is actively developing an independent, first-party cloud backup service featuring mandatory end-to-end encryption. This upcoming feature aims to reduce users' reliance on third-party...

Most Important Key Factors Organizations Should Consider in Implementing the Cloud Security Solutions

Cloud Security Solutions is one of the challenging tasks while performing the cloud migration for any organization and they need to ensure the best...

Threat Actors Breach Global Companies Using Leaked Cloud Credentials

A sophisticated cybercriminal operating under the moniker "Zestix" (alias "Sentap") has successfully infiltrated approximately 50 major global enterprises through a deceptively devastating yet straightforward...

Top 10 Best Cloud Workload Protection Platforms (CWPP) in 2026

The cloud landscape in 2026 continues its unprecedented growth, with organizations of all sizes rapidly migrating critical workloads to public, private, and hybrid cloud...

Top 10 Best Cloud Access Security Brokers (CASB) in 2026

The year 2026 marks a new era in enterprise cloud adoption, characterized by a complex tapestry of Software-as-a-Service (SaaS) applications, Infrastructure-as-a-Service (IaaS) platforms, and...

Hackers Exploit OAuth Apps to Keep Cloud Access Even After Password Resets

Cloud account takeover attacks have evolved beyond simple credential theft. Cybercriminals are now exploiting OAuth applications to maintain persistent access to compromised environments, bypassing...

Hackers Abuse IMDS Service for Cloud Initial Access

Cloud environments rely on the Instance Metadata Service (IMDS) to provide virtual machines with temporary credentials and essential configuration data. IMDS allows applications to securely...

God Mode Vulnerability Lets Attackers Access Any Resource in Microsoft Cloud Tenants

A recently disclosed flaw, tracked as CVE-2025-55241, allowed any attacker in possession of a single “Actor token” from a test or lab tenant to...