Cloud-Sicherheit
CLOUD-SICHERHEIT
Google Bets ‚Agentic Defense‘ Strategy Can Outpace Attackers
Google Cloud incorporates key Wiz capabilities into an agentic defense platform to automate threat detection and remediation against AI attacks....
🟠 CVE-2026-9765: High Schwachstelle
Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are...
🔴 CVE-2026-58630: Critical Schwachstelle
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
🔴 CVE-2026-56163: Critical Schwachstelle
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
CLOUD-SICHERHEIT
Flaws in Passkey Implementation Show Old Attacks Still Work
Ahead of Black Hat USA, researchers find exploitable flaws in how Microsoft handles passkeys that could allow attackers to impersonate...
CLOUD-SICHERHEIT
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
Microsoft addresses a public-by-default configuration and chain of code flaws in Azure Automation that could have let attackers seize another...
🟠 CVE-2026-16745: High Schwachstelle
A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network...
CLOUD-SICHERHEIT
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government,...
CLOUD-SICHERHEIT
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a...
Stop renting storage space — this lifetime 2TB plan is yours for $59
Cloud storage costs tend to creep up over time, since most services charge monthly or annually for as long as...