Cloud-Sicherheit
CLOUD-SICHERHEIT
The ‚Industrial Accidents‘ Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed
Rich Mogull, chief analyst with the Cloud Security Alliance, joins the Dark Reading News Desk with what defenders need to...
🟠 CVE-2026-10582: High Schwachstelle
Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone....
CLOUD-SICHERHEIT
Silent ‚TwinLoot‘ Cyber Threat Operates Entirely From Microsoft’s Cloud
The Python-based malware framework takes living-off-the-land tactics to a new heights of stealth, with a modular implant that steals credentials...
CLOUD-SICHERHEIT
The ‚Industrial Accidents‘ Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed
Rich Mogull, chief analyst with the Cloud Security Alliance, joins the Dark Reading News Desk with what defenders need to...
CLOUD-SICHERHEIT
N-able Bug Exposes Password Vault Master Keys
The popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based...
CLOUD-SICHERHEIT
TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024...
🟠 CVE-2026-47827: High Schwachstelle
Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands...
🟠 CVE-2026-77775: High Schwachstelle
Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in headroom/proxy/handlers/openai.py accepts the...
🟠 CVE-2026-61400: High Schwachstelle
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality...
🟠 CVE-2026-50112: High Schwachstelle
SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing...