Advertisement
Cloud Security Index 2026: Multi-Cloud Risk Analysis
Intruder analyzed cloud misconfigurations across AWS, Azure, and GCP, revealing distinct risk profiles and universal IAM challenges.
Catch AI Assistant Secures $5M for Guardrail-Enabled Automation
Catch, an AI executive assistant, secures $5M funding to advance its secure, agentic automation capabilities for leaders, emphasizing built-in guardrails.
OWASP Releases Top 10 Security List and Universal Skill Format for AI
OWASP debuts a top 10 security list and Universal Skill Format to secure AI add-ons, addressing modern artificial intelligence risks.
Hundreds of Leaked AWS Keys Expose Corporate Cloud Accounts
Research reveals over 9,000 publicly exposed Amazon Web Services access keys remain active, including hundreds of root and administrator credentials.
CUSTODY Framework: Constraining Enterprise AI Agents
Enterprise security expert Jake Williams releases the CUSTODY framework to restrict agentic AI behavior following attacks on Hugging Face.
Securing Model Context Protocol (MCP) Traffic with Cloudflare
Learn how Cloudflare One identifies inspected Model Context Protocol traffic and controls AI agent tool calls to secure enterprise environments.
Advertisement
Security Blind Spots in AI Accelerators and Neo-Clouds
AI accelerators and neo-clouds introduce significant security blind spots, challenging traditional tools and creating an invisible supply chain threat to AI models.
ChatGPT Secure Sandbox PoC Enables C2-Style Influence
A researcher demonstrated a proof-of-concept attack chain enabling C2-style influence over ChatGPT's secure sandbox environment.
Azure Cosmos DB CosmosEscape Flaw: Cross-Tenant Database Access
Wiz researchers uncover CosmosEscape, a sandbox escape in Azure Cosmos DB's Gremlin API allowing unauthorized cross-tenant read and write access.
DataBahn Secures $40M for Agentic Data Control Plane Innovation
DataBahn raised $40 million to scale its agentic data control plane, addressing critical security and governance challenges in autonomous enterprise pipelines.
Mitigating Cloud Attack Paths from Non-Human Identity Sprawl
Non-human identity sprawl in cloud environments creates new attack paths through dormant or over-privileged credentials. Learn to detect and mitigate these risks.
Confused Deputy Flaws in Google Cloud & Azure: Admin Bypass
Analysis of 'Confused Deputy' vulnerabilities across Google Cloud and Microsoft Azure, enabling administrative privilege escalation and access control bypass.
Securing Autonomous AI Agents: Discovery and Governance Strategies
Learn how to detect and secure shadow AI agents within enterprise environments to prevent data leakage and unmanaged autonomous permission risks.
Azure Automation Default Setting: Cross-Tenant Identity Takeover
Runtime Rebel analyzes a critical security flaw in Azure Automation's default settings allowing cross-tenant identity takeover and access to sensitive data.
Microsoft 365 Outage: How an Automated Network Maintenance Bug Impacted Azure
Technical analysis of the Microsoft 365 and Azure outage caused by a bug in the automated network maintenance system, resulting in accidental IP route removal.
Microsoft Fixes Exchange Online Erroneous Mailbox Quarantine Issue
Microsoft is mitigating a service disruption where Exchange Online mailboxes were incorrectly quarantined, causing delivery failures and access issues.
Palo Alto Networks Acquires Embrace: Security Observability Implications
Palo Alto Networks acquires Embrace, deepening its cloud security capabilities by integrating observability for enhanced application protection and threat detection.
AWS Kiro RCE via Indirect Prompt Injection - Mitigation Guide
Research reveals a critical flaw in AWS Kiro where malicious web pages trigger RCE by rewriting configuration files via indirect prompt injection attacks.
Identifying Origin IP Addresses Behind Cloudflare and WAF Services
Examine technical methods used to discover backend origin IPs hidden behind Cloudflare, including DNS history, TLS fingerprinting, and outbound leaks.
Google Cloud Agentic Defense: Automating AI-Driven Security Response
Google Cloud integrates Wiz and Mandiant capabilities into its new Agentic Defense model, using AI agents to automate complex threat detection workflows.
Securing AI Data Centers: Addressing New Hardware and Network Risks
AI infrastructure growth is outpacing security protocols, introducing risks from high-speed interconnects and GPU multi-tenancy that demand new defenses.
Exposed Cloud Functions: Hardening GCP Serverless Against LFI & RCE
Mandiant identifies exposed serverless functions as initial access points. Learn to harden Google Cloud Run against LFI and RCE with IAM, WAF, and secure SDLC.
SASE AI Blind Spot: Why Packet Inspection Fails Modern Workflows
Enterprise data leakage via generative AI tools and browser extensions exposes critical flaws in traditional SASE models that rely solely on packet inspection.
Windows 11 26H2 Default Backup for Entra-Joined Systems
Microsoft will enable Windows settings backup by default for Entra-joined organizational systems after Windows 11 26H2 upgrade, impacting IT management and compliance.