Cloud-Sicherheit
🔴 CVE-2026-59243: Critical Schwachstelle
The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to...
CLOUD-SICHERHEIT
‚Confused Deputy‘ Flaws Persist in Google Cloud, Microsoft Azure
This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers' access controls....
CLOUD-SICHERHEIT
Agentic Browsers Rewind Web Security by 20 Years
PleaseFix class of flaws makes it easy to socially engineer agentic browsers and highlights weaknesses in how they handle cross-origin...
CLOUD-SICHERHEIT
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a...
CLOUD-SICHERHEIT
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from...
CLOUD-SICHERHEIT
‚Confused Deputy‘ Flaws Persist in Google Cloud, Microsoft Azure
This category of vulnerabilities allows an attacker to easily acquire administrative level permissions and bypass cloud providers' access controls....
CLOUD-SICHERHEIT
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools...
CLOUD-SICHERHEIT
AWS Unveils ‚Continuum,‘ an AI-Powered Vulnerability Management Platform
Working with frontier AI models, this new platform aims to help discovering, prioritizing, validating and remediating code vulnerabilities...
CLOUD-SICHERHEIT
Google Bets ‚Agentic Defense‘ Strategy Can Outpace Attackers
Google Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks....
CLOUD-SICHERHEIT
Novel OAuth Client ID Spoofing Technique Targets Cloud Environments
New research reveals cyber-attackers can spoof OAuth Client IDs in Microsoft Entra ID, creating a stealthy path into cloud environments...