#cloudsecurity

26 posts · Last used 49m

Back to Timeline
Security Crawler Carl @security_crawler_carl@infosec.exchange · 49m ago
Replying to @security_crawler_carl@infosec.exchange
Microsoft has patched this. Researcher Shay Shavit will be demonstrating the full horror at Black Hat USA. Review your Azure Automation account identity exposure and apply Microsoft's security updates immediately. Reward: You've received the Binding Arbitration Bracer — it does nothing, but you clicked Accept, so here we are. #AzureSecurity #CloudSecurity #CyberSecurity #IdentityTheft #Microsoft #AchievementUnlocked (3/3)
0
0
0
Alonso Caballero / ReYDeS @Alonso_ReYDeS@infosec.exchange · 1d ago
🆓 Webinar Gratuito: "Fundamentos de Ciberseguridad" 🏁Miércoles 29 de Julio 2026. De 11:00 am a 11:45 am (UTC -05:00) 🎇 Registro libre: https://docs.google.com/forms/d/e/1FAIpQLSfhDJsMv0TvBqyTnjSepFwV68dhpsoyWTELZ7v1lZw7HoUGdw/viewform #dataprotection #ciso #gdpr #malware #threatintelligence #ransomware #cloudsecurity #zerotrust
0
0
0
OffSequence @offseq@infosec.exchange · 1d ago
CVE-2026-56163: CRITICAL (CVSS 10) in Azure Kubernetes Service — Missing authentication allows remote privilege escalation. Microsoft has released a fix; verify your AKS is updated. https://radar.offseq.com/threat/cve-2026-56163-cwe-306-missing-authentication-for-critical-function-in-microsoft-azure-kubernetes-c5571c5da7b404e3 #OffSeq #Azure #Kubernetes #CloudSecurity
0
0
0
OffSequence @offseq@infosec.exchange · 1d ago
CVE-2026-62835 (CRITICAL, CVSS 9.3) affects Microsoft Azure Portal: improper authorization enables remote info disclosure with high confidentiality impact. Microsoft has fixed server-side. More at https://radar.offseq.com/threat/cve-2026-62835-cwe-285-improper-authorization-in-microsoft-azure-portal-defd11bbcf2e17c7 #OffSeq #Azure #Vuln #CloudSecurity
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 2d ago
A Konnectivity vulnerability (CVE-2026-16242, CVSS 9.4) lets unauthenticated attackers proxy and modify control-plane traffic. See the fix and mitigation. #Konnectivity #Kubernetes #CVE202616242 #CloudSecurity #ControlPlane #AuthBypass #InfoSec #PatchNow http://securityonline.info/konnectivity-vulnerability-cve-2026-16242/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
OffSequence @offseq@infosec.exchange · 2d ago
CVE-2026-50517: CRITICAL deserialization flaw (CVSS 9.9) in Microsoft 365 Copilot permits remote code execution by authorized attackers. Microsoft has issued a server-side fix — confirm your environment is protected. https://radar.offseq.com/threat/cve-2026-50517-cwe-502-deserialization-of-untrusted-data-in-microsoft-microsoft-365-copilot-71d778a5726cf6f5 #OffSeq #Microsoft365 #CloudSecurity #CVE202650517
0
0
0
OffSequence @offseq@infosec.exchange · 2d ago
CVE-2026-58275 | Microsoft Azure DNS (CRITICAL, CVSS 10): Missing authorization lets attackers escalate privileges remotely — integrity & availability at risk. Microsoft has patched server-side. Details: https://radar.offseq.com/threat/cve-2026-58275-cwe-862-missing-authorization-in-microsoft-azure-dns-8fa245e6deabe29a #OffSeq #Azure #CVE #CloudSecurity
0
0
0
Alonso Caballero / ReYDeS @Alonso_ReYDeS@infosec.exchange · 2d ago
🆓 Webinar Gratuito: "Fundamentos de Ciberseguridad" 🏁Miércoles 29 de Julio 2026. De 11:00 am a 11:45 am (UTC -05:00) 🎇 Registro libre: https://docs.google.com/forms/d/e/1FAIpQLSfhDJsMv0TvBqyTnjSepFwV68dhpsoyWTELZ7v1lZw7HoUGdw/viewform #infosec #informationsecurity #cyber #zerotrust #threatintel #ransomware #phishing #cloudsecurity #malware
0
0
0
Alonso Caballero / ReYDeS @Alonso_ReYDeS@infosec.exchange · 2d ago
🆓 Webinar Gratuito: "Fundamentos de Ciberseguridad" 🏁Miércoles 29 de Julio 2026. De 11:00 am a 11:45 am (UTC -05:00) 🎇 Registro libre: https://docs.google.com/forms/d/e/1FAIpQLSfhDJsMv0TvBqyTnjSepFwV68dhpsoyWTELZ7v1lZw7HoUGdw/viewform #infosec #informationsecurity #cyber #zerotrust #threatintel #ransomware #phishing #cloudsecurity #malware
0
0
0
Altered Security @alteredsecurity@bird.makeup · 5d ago
The recording and slides for our Hacker Summer 2026 webinar, From Initial Access to Persistence: Abusing Synced Passkeys in Azure, are now available. Video: https://youtu.be/kwEga-U96dw?si=_nwzT74aT26cNpAx Slides: https://16cdd728-52b5-4665-b161-30113ba1b7e4.usrfiles.com/ugd/16cdd7_684bf5951d5648f0a213cf3a3836505f.pdf Special thanks to @nathanmcnulty@bird.makeup for an excellent session. #HackerSummer2026 #CloudSecurity #RedTeaming #AlteredSecurity
1008
0
9
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 4d ago
Iran's IRGC claims cruise missiles destroyed the AWS Bahrain data center, but the site has been offline since March and no one has confirmed the strike. #AWS #Bahrain #Iran #IRGC #DataCenter #CloudSecurity https://securityonline.info/aws-bahrain-data-center-claim/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · 4d ago
Oracle just shipped 1,449 security fixes. Most you can ignore. A few you cannot: unauthenticated, no-login code execution scored 10.0 in WebLogic, Oracle HTTP Server, and Coherence. Self-host those and they face the internet? Patch them first. https://suriq.io/blog/oracle-july-2026-cpu-unauthenticated-rce-weblogic-coherence #CVE #CloudSecurity #infosec #cybersecurity
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 5d ago
OVH patched CVE-2026-53359, a critical KVM flaw, across tens of thousands of hosts in under 10 days without warning most clients first. #OVHcloud #CVE202653359 #KVM #LinuxKernel #CloudSecurity https://securityonline.info/ovh-cve-2026-53359-kvm-patch/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 6d ago
Proofpoint details OAuth client ID spoofing, a stealthy account enumeration technique that probes Microsoft Entra ID without a successful sign-in event. #OAuthSpoofing #EntraID #AccountEnumeration #CloudSecurity #Proofpoint http://securityonline.info/oauth-client-id-spoofing/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · 6d ago
OpenShift hosted control planes: a missing certificate check (CVE-2026-16242, CVSS 9.4) lets a remote attacker read traffic between the control plane and its nodes. No fix shipped yet. Restrict the endpoint and watch for unknown agents. https://suriq.io/blog/openshift-hypershift-konnectivity-cert-bypass #CVE #CloudSecurity #infosec #cybersecurity
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 19, 2026
NadMesh is a new Go botnet scanning for exposed AI tools like Ollama and ComfyUI. It skips the server and reads the host for cloud keys and Kubernetes tokens. One dashboard claims 3,811 stolen AWS keys. Evict it before you rotate credentials. https://suriq.io/blog/nadmesh-botnet-exposed-ai-cloud-keys #CloudSecurity #ThreatIntel #DataBreach #Phishing
0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 15, 2026
An unauthenticated stranger can trick Grafana's official AI connector into leaking its access token, and relaying into your cloud. Affects versions up to 0.17.1. Fix: upgrade to 0.17.2 and rotate the token. (CVE-2026-15583) https://suriq.io/blog/grafana-mcp-server-token-leak-ssrf #CloudSecurity #DataBreach #infosec #cybersecurity
0
0
0
OffSequence @offseq@infosec.exchange · Jul 13, 2026
Google Cloud BigQuery, Dataform, & Colab Enterprise hit by CVE-2026-14934 (CRITICAL, CVSS 9.4): Missing authorization lets authenticated users take over cross-tenant repos. Patched by Google as of May 10, 2026. https://radar.offseq.com/threat/cve-2026-14934-cwe-862-missing-authorization-in-go-383108321f0353c8 #OffSeq #CloudSecurity #CVE202614934
0
0
0
hasamba @hasamba@infosec.exchange · Jul 11, 2026

🎯 AI

Sygnia: AI-Supercharged 72-Hour Cloud Attack Investigation

Sygnia published findings from an incident response engagement where a threat actor compromised an AWS-based environment, progressing from initial access to broad cloud compromise in approximately 72 hours. The case is notable not for novel techniques, but for the apparent use of AI to accelerate familiar cloud attack methods.

Key Findings • The intrusion expanded across applications, cloud infrastructure, source-control systems, CI/CD pipelines, and runtime services • No zero-day exploits or novel malware were observed. Every technique mapped to established MITRE ATT&CK behaviors • Multiple artifacts suggested AI-assisted or agentic workflows: attacker-created scripts, structured reporting artifacts, and highly parallel activity • The threat actor repeatedly leveraged newly acquired credentials to restart discovery, secrets harvesting, persistence, and impact activities • The primary defensive challenge was the speed and scale of execution, not the novelty of individual techniques

Where AI Changed the Equation

The report identifies several indicators of AI involvement: • Rapid generation of environment-specific scripts and tooling • Structured, formatted reporting artifacts consistent with AI-generated output • Highly parallel discovery and exploitation activities across multiple surfaces • Compressed timeline for reconnaissance, adaptation, and operational execution inconsistent with purely manual operations

Attack Path

  1. Initial access to AWS environment
  2. Credential harvesting and secrets discovery
  3. Lateral movement across applications and cloud services
  4. Persistence through compromised identity and deployment workflows
  5. Expansion into source-control and CI/CD systems
  6. Impact across cloud, identity, and application layers

Each credential acquisition restarted the cycle.

Defensive Gaps • Fragmented visibility across cloud, identity, and application layers • Monitoring gaps that delayed detection and correlation • Absence of predefined incident response procedures • Weak secrets management and identity governance • Overly permissive cloud and CI/CD permissions

Remediation

Sygnia recommends adapting IR playbooks for AI-enabled threats, prioritizing broad containment over precision when speed matters, rotating credentials aggressively, treating identity as the primary security boundary, and automating defensive responses. Infrastructure rebuilds may be necessary for broadly compromised environments.

Known weaknesses get exploited faster and at broader scale when AI assistance is available. End-to-end visibility and predefined containment procedures are prerequisites, not aspirations.

🔹 AI #CloudSecurity #IncidentResponse #Sygnia #MITREATTACK

🔗 Source: https://www.sygnia.co/blog/inside-an-ai-assisted-cloud-attack/

0
0
0
Suriq - Always on Watch @suriq@infosec.exchange · Jul 09, 2026
Google Dialogflow CX had a flaw where one 'edit' permission on a chatbot ran code across every Code Block agent in the project, and reached cloud credentials. Google has fixed it. No CVE. The lesson: on managed AI platforms, an edit right is often a code-execution right. https://suriq.io/blog/dialogflow-cx-rogue-agent-edit-permission #CloudSecurity #Detection #infosec #cybersecurity
0
0
0