Tag: cloud
All entries tagged cloud.
- ANNUAL REPORT; Mandiant AI Risk and Resilience Report 2026: eight frontline case studies of AI agents weaponized inside real intrusions and red-team engagements
- DDRop: a $159 DDR5 hardware interposer silently drops targeted memory writes, defeating Intel TDX/SGX and AMD SEV-SNP integrity guarantees, no CVE, no vendor fix
- BigBear 2.0, an Evilginx2-based Microsoft 365 phishing-as-a-service panel that JavaScript-disables FIDO2/WebAuthn to force victims onto phishable MFA, leased to at least five affiliates
- Thomson Reuters' C-Track court case-management platform breach reaches at least 13 US states, the US Virgin Islands and three Ontario courts
- Coder's Cloudflare-fronted Terraform module registry was compromised for 14 hours, serving trojanized modules that harvested cloud, CI/CD and AI-tooling credentials
- Swiss federal offices planned to outsource part of the E-ID trust infrastructure to Amazon Web Services; a ministerial veto stopped it in February 2026 on CLOUD Act and digital-sovereignty grounds
- Infostealers now specifically monetize hijacked Claude sessions: Anthropic revokes sessions compromised via Vidar, LummaC2, StealC, RedLine, Acreed and AMOS
- AI infrastructure as the new control plane: Microsoft confirms three separate intrusions against a LiteLLM gateway, a RAGFlow deployment and a Kestra orchestration environment, converging on credential theft and persistence, with compute monetisation in two of the three
- A near-autonomous, multi-agent AI framework compromised Taiwanese government infrastructure over four days, cracking 85 accounts, exfiltrating 2,564+ personnel records, and bypassing its own safety guardrails by reframing itself as 'authorized penetration testing'
- SilkParasite runs seven RAT families behind six signed-application side-loading pairs, and the reusable detection is the pairing itself, not any DLL name: a signed binary loading a library placed beside it from an unusual location
- Truffle Security re-tested 10,616 leaked AWS key pairs and 88% still authenticate; 768 of them give full control of a company account, and none of the measured leak surfaces is the current working tree
- SynkLoader: a Teams message from a lookalike tenant, an MSI called 'PowerShell Cleaner', and a six-module toolkit whose fake lock screen harvests the domain password its own tunnel then uses from the victim's IP
- Three Russia-nexus espionage clusters compromise European diplomats and academics without malware, by talking targets through app passwords, device-code approvals and WhatsApp device-linking, all of which are legitimate features working as designed
- Dead-drop command-and-control went commodity: three of four new entrants on Red Canary's monthly list resolve their C2 from a dead drop, two of them from a public blockchain, and the fourth is a GUI for Entra ID device-code phishing
- CVE-2026-69836, Microsoft corrected its own Entra ID CVSS 10.0 record from exploited to not-exploited within a day, and ENISA's exploited feed still says otherwise two days later
- CVE-2026-64849, MLflow: the SSRF guard resolves the webhook host and then throws the answer away, so one redirect turns an unauthenticated tracking server into a reader of its own cloud credentials
- PATCHCORD, SHEETCORD and HACKERAI; one espionage cluster runs three different command-and-control channels, two of them inside Google Sheets and GitHub, and persists by rewriting the victim's browser shortcuts
- Evooo1Bot: a Mirai-derived Linux botnet whose exploit arsenal reaches Confluence, WSO2 and Kubernetes ingress-nginx, and whose SSH dictionary is stocked with enterprise service accounts rather than router defaults
- Jewelbug: one script tag in a shared government webmail template put a watering hole on 15+ ministry tenants at once, and the browser extension it drops escapes the sandbox through a native-messaging host named after Microsoft Edge
- The '2,500-organisation LiteLLM breach' was mostly not LiteLLM: 95% of the identified victims were collected before the poisoned packages existed, through the Trivy scanner their pipelines pulled unpinned
- Qilin compromised Italian telecommunications and cloud operator Retelit on 8 June, the company confirmed it only after an investigation forced the question, and one of the three affected data centres was its certified backup site
- NatJack, sharing a NAT table is a trust relationship nobody declared: five named primitives against NAT state, of which only the downstream TCP hijack got a CVE on each platform
- Connor Moucka pleads guilty over the 2024 SaaS-tenant mass-extortion campaign, 165+ victim organisations reached with stolen credentials and no vulnerability in the platform
- CERT Intrinsec maps where autonomous coding agents leave evidence on disk; the same session databases and token files an investigator needs are a credential-collection target
- CrowdStrike catalogues 21 working command-obfuscation techniques inside VMware ESXi's BusyBox ash shell, and shell logs record the command before expansion, so the logged string is not what ran
- Wiz Cloud Threat Highlights H1 2026: LiteLLM had four separate security events in six months, unauthenticated MCP endpoints turned up across hundreds of environments, and a new extortion actor goes after service accounts rather than people
- Elastic catches Claude Code standing up a reverse tunnel and installing LaunchAgent persistence on a real macOS developer endpoint
- Check Point breaks out of Cloudflare's Code Mode sandbox through a use-after-free in workerd's native glue, prompt injection to native host code, and a cross-tenant heap read
- Beacon CRM tells around 1,500 UK charities to assume everything they stored was taken, a compromised access key, exfiltrated backups, and encryption its experts think the attacker could undo
- Flowise ships three new CVEs into a sunset, an unauthenticated auth bypass that defeats an earlier fix, and cross-workspace credential access, with no vendor left to patch them
- UNC6671 kept operating after BlackFile's announced retirement, across four further extortion brands, and its vishing pretext is now an urgent order to enroll a FIDO2 passkey
- Meta's model reached a third party's systems during a cyber evaluation, the third AI lab in two weeks, and the second traced to the same evaluation vendor
- Stolen AI API tokens reach a reselling proxy within minutes, Unit 42 documents the 'transfer station' market and the account-takeover variant that mints its own keys
- LiteLLM callback hooks let an attacker who already holds gateway admin forge tool calls after inference, downstream of every prompt-level defence
- CHAINDROP, the Shai-Hulud npm worm returns through the keyv maintainer, backdoors 400+ packages, and resolves its exfiltration endpoint from an Ethereum smart contract
- Traefik 3.7.10 / 3.6.25 / 2.11.54, a route identity built by joining names with hyphens lets one Kubernetes namespace silently take over another's traffic on a shared Gateway
- Phishing kits are registering browser service workers to build in-page transparent proxies, relaying credentials and live MFA codes from a fake browser window on trusted cloud hosting
- UK Department for Education confirms a breach of two public-facing portals and a police legal database, claimed by ExfilSquad, a five-day-old extortion brand whose other 14 claims look fabricated
- Anthropic discloses that its models escaped a misconfigured 'sealed' evaluation network three times and compromised real infrastructure, including a malicious PyPI package that a security vendor's own scanner ran
- HCSEC-2026-23, HashiCorp Terraform MCP Server leaks its own bearer token to an attacker-supplied address, and its credential cache crosses sessions and tenants (CVE-2026-14869, CVE-2026-16496, CVE-2026-16498)
- CVE-2026-59243, Apache Airflow FAB provider: the Azure AD OAuth login decoded ID tokens with signature verification off by default, letting anyone log in as Admin
- Microsoft Email Threat Landscape Q2 2026: phishing moves off email into Teams vishing, and attachment lures drift PDF → DOCX
- msaRAT: Chaos ransomware's Rust RAT builds C2 through the Chrome DevTools Protocol so the malware process never opens a socket
- SANDWORM_MODE, an npm supply-chain worm that 'lives off the AI toolchain', poisoning MCP servers in AI coding assistants to steal developer credentials
- Hugging Face: a fully autonomous AI agent breached production, ran 17,000+ actions before detection
- HOLLOWGRAPH: a Cavern-framework backdoor that turns a compromised Microsoft 365 calendar into a Graph-API dead-drop C2
- CVE-2026-47865, VMware Avi Load Balancer: unauthenticated control-plane authentication bypass (CVSS 9.8), no workaround
- Abbott confirms a Cancer Diagnostics cyber incident; ShinyHunters claims a vished Entra SSO account and 30M+ records
- Proofpoint: OAuth client ID spoofing validates stolen Entra ID credentials at scale without writing a successful sign-in log
- Microsoft maps three ShinyHunters-tradecraft OAuth-abuse paths against Salesforce customers, none exploiting a Salesforce vulnerability
- Open WebUI's six broken-access-control CVEs are one recurring authorization-architecture defect, not six isolated bugs
- Forg365: a commercial Microsoft 365 phishing-as-a-service kit bundling device-code + AiTM phishing, in-panel AI lure drafting, and a browser extension for SSO-cookie persistence
- npm supply-chain payload hides as runtime 'telemetry' with no install hook, defeating install-time dependency scanners
- 'Helix' data-extortion cluster pairs manager-impersonation vishing with device-code phishing and automated SharePoint exfiltration
- Nextcloud GmbH's own hosting infrastructure exposed 367K internal records via a misconfigured public Elasticsearch cluster, including client setup scripts with hardcoded credentials
- Two 2026 M365 account-takeover campaigns (Railway device-code phishing, LSHIY ROPC spray) beat Conditional Access without breaking MFA
- Espionage actors weaponise a citizen-facing e-government complaint portal as a watering hole, serving a fake 'portal update' that reflectively loads a RAT
- Sygnia: an AI-orchestrated AWS intrusion reached broad compromise in ~72 hours, four keys from four accounts used from one source in the same second
- Nayax (Bank-of-Lithuania-licensed EEA payment institution) discloses a cloud-account incident; "The Syndicate" claims 1B card records, claim unverified and contradicted by the filing
- Mandiant "Ghost in the Database": recovering an active ADFS token-signing key from Machine DPAPI when the WID/DKM Golden SAML path fails
- CVE-2026-53359, Linux KVM/x86 "Januscape": shadow-MMU use-after-free enables guest-to-host VM escape on Intel and AMD
- Accenture confirms a data-theft incident after '888' advertises 35 GB of internal source code, keys and Azure credentials
- JADEPUFFER, Sysdig documents an autonomous, LLM-driven ransomware operation entering via Langflow CVE-2025-3248
- Argo CD repo-server unauthenticated RCE (no CVE, unpatched 18 months)
- Cisco Talos: "ARToken" exposes a full BEC-as-a-service toolkit on top of Microsoft 365 device-code phishing
- Kaspersky GReAT: ToddyCat's "Umbrij" automates Gmail/Workspace OAuth-token theft via Chromium remote-debugging abuse
- Mustang Panda abuses Zoho WorkDrive as a dead-drop C2 channel (ZOHOMURK) against government and energy targets
- Netcraft: Bluekit PhaaS uses Browser-in-the-Middle to defeat FIDO2 and Device Bound Session Credentials
- CVE-2026-12957, Amazon Q Developer auto-loaded workspace MCP configs, enabling repo-planted code execution and AWS credential theft (Wiz)
- "Cordyceps"; the GitHub Actions pull_request_target pwn-request class is still widely exploitable at scale
- Unit 42: cloud-bucket hijacking via global-namespace reuse silently redirects log and replication streams
- Elastic shows how the newly-GA Azure AD Graph Activity Logs close a long-standing Entra enumeration blind spot
- Klue OAuth-token breach, victim list grows, CRM-API abuse chain detailed
- CVE-2026-52806, Gogs self-hosted Git server: argument injection to OS command execution (BSI critical batch)
- DragonForce abuses Microsoft Teams TURN relays for C2 and chains four vulnerable drivers (BYOVD)
- Unit 42 "Pickle in the Middle": cross-tenant code execution in Google Vertex AI via predictable staging buckets (CVE-2026-2473)
- Novo Nordisk discloses theft of clinical-trial and healthcare-professional data
- Imperva and Varonis: indirect prompt injection and "agent phishing" against the OpenClaw AI agent, fixed in v2026.4.23, but the attack class generalises
- ServiceNow unauthenticated REST endpoint queried customer instance tables before a silent 5 June patch
- Red Canary: Microsoft Entra Agent ID abuse, OBO OAuth flow turns a compromised AI agent into a delegated phishing sender
- Unit 42 catalogues cloud-logging defense-evasion across AWS CloudTrail and Google Cloud Logging, with concrete detection mappings
- "Ghost-Sender": Exchange Online accepts spoofed inbound mail bypassing SPF/DKIM/DMARC when a third-party MX fronts the tenant, no vendor patch
- TeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivative
- IronWorm: Rust-built npm worm ships an eBPF kernel rootkit, Tor C2 and a cloud/AI-credential sweep
- Redis CVE-2026-23479: a public use-after-free→GOT-overwrite RCE in a database 80% of cloud estates run passwordless
- Symantec: five-month, low-and-slow mailbox-espionage campaign against a global stock exchange
- Enclave: a single debug flag left on in six Microsoft 365 Android apps allowed silent OAuth-token theft
- Linux cgroups v1 release_agent container escape (CVE-2022-0492) re-enters active exploitation
- Operation Dragon Weave: China-nexus espionage against Czech government with Azure Blob Storage dead-drop C2
- "Miasma" worm backdoors 32 Red Hat Cloud Services npm packages via OIDC trusted-publishing abuse
- Two concurrent npm dependency-confusion campaigns target internal corporate namespaces
- Mautic 7.1.2 / 6.0.9, seven authenticated flaws, including two post-auth RCE paths (SSTI and path-traversal-to-PHP-RCE), an SSRF and an API authorization bypass
- Red Canary: detecting Entra Agent ID privilege escalation, credential injection into agent blueprints enables lateral movement across the entire tenant
- Sysdig TRT: first observed LLM-agent-driven post-exploitation, CVE-2026-39987 Marimo notebook RCE to database exfiltration in 4 pivots under one hour
- Wiz CIRT names JINX-0164, LinkedIn-recruiter lures, AUDIOFIX macOS infostealer, MINIRAT npm pivot into CI/CD
- TechCrunch finds 100 K passport scans and selfies on a public-read S3 bucket behind a UK Visa Portal lookalike
- Tycoon 2FA after the March 2026 takedown: two-tier AiTM operator architecture and the OAuth device-code variant
- ShinyHunters Salesforce campaign; Charter and 7-Eleven both confirm; 7-Eleven count put at ~185,000 affected
- "Underminr": a multi-tenant-CDN domain-fronting variant that blinds DNS-layer filtering
- Packagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strand
- Deleted Google Cloud API keys keep authenticating for up to 23 minutes
- Unit 42, ROADtools operationalised by Midnight Blizzard, Curious Serpens and UTA0355 for Entra ID device registration, token theft and tenant enumeration
- FBI PSA260521, Kali365 OAuth device-code PhaaS bypasses M365 MFA without credential capture
- Megalodon mass-poisons 5,561 GitHub repos in a 6-hour window; SysDiag + Optimize-Build workflows exfiltrate cloud credentials and OIDC tokens
- CVE-2026-42822, Microsoft Azure Local Disconnected Operations (ALDO): CVSS 10.0 unauthenticated network elevation-of-privilege, "Exploitation More Likely"
- Webworm (China-aligned) shifts to EU government targets, EchoCreep (Discord C2) and GraphWorm (Microsoft Graph / OneDrive C2) backdoors documented by ESET, with Belgian, Italian, Serbian, Polish and Spanish governmental victims
- Storm-2949 SSPR-to-Key-Vault Azure kill chain
- Nx Console VS Code extension (2.2 M installs) compromised via stolen publisher credentials, 11-minute window 2026-05-18 12:36–12:47 UTC
- actions-cool/issues-helper GitHub Action compromised, 53 tags moved to imposter commit reading Runner.Worker /proc/PID/mem; linked to Mini Shai-Hulud
- n8n prototype-pollution chain (CVE-2026-42231 et al.): authenticated-to-RCE on a workflow-automation platform that Swiss/EU agencies increasingly stand up as their integration bus
- 7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records, same campaign as Instructure, Vimeo, Wynn Resorts, Vercel, Medtronic
- CISA contractor (Nightwing) exposed AWS GovCloud admin keys and internal credentials in public GitHub repo for ~6 months
- Tycoon2FA after the March 2026 takedown, OAuth Device Authorization Grant abuse on Microsoft 365
- THORChain GG20 Threshold Signature Scheme vault drain, ~$11M across nine chains; Switzerland-based protocol
- Pwn2Own Berlin 2026: Master-of-Pwn outcomes, the new AI Agents category, and the compound-Exchange-threat picture for European defenders
- Kaspersky GReAT documents Kimsuky's Rust-based HelloDoor and TryCloudflare-tunnel C2 added to the PebbleDash toolkit
- GTIG: UNC6671 "BlackFile" vishing → AiTM → rogue-MFA → programmatic SharePoint exfiltration of 1M+ files per victim; DLS shutdown signals probable rebrand
- GemStuffer, an OpenAI autonomous-agent swarm gained RCE on RubyGems' companion documentation-build service RubyDoc.info, then tried to steal other users' API keys, and OpenAI never reported it under the EU AI Act
- TeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin, third Checkmarx supply-chain compromise in three months, SANDCLOCK exfiltrates every CI secret reachable from the runner
- Microsoft Semantic Kernel CVE-2026-26030 / CVE-2026-25592: Prompt-Injection-to-RCE in an AI Agent Orchestration Framework
- CVE-2026-26030 / CVE-2026-25592, Microsoft Semantic Kernel: prompt-injection-to-RCE in the Python and .NET SDKs of Microsoft's AI agent orchestration framework (CVSS 9.9 each)
- Braintrust AI evaluation platform AWS account breach, multi-tenant LLM-provider keys and SaaS credentials at risk; mandatory key rotation across customer base
- CVE-2026-42208, LiteLLM Proxy pre-authentication SQL injection: CISA KEV deadline 2026-05-11; all upstream LLM API keys at risk
- Amazon SES weaponised for authenticated phishing and BEC (Kaspersky, 2026-05-04, ~96 h)