Advertisement
ServiceNow Flaw Exploited: Unauthenticated Access to Customer Instances
ServiceNow advises customers of a critical flaw leading to unauthorized access to hosted instances.
Opal Security Series B: Scaling AI-Native Identity Governance
Opal Security secures $23 million in Series B funding to scale its AI-native identity governance platform for hybrid and multi-cloud environments.
Coralogix Secures $200M Series D to Scale AI Observability Platform
Coralogix raises $200M to expand its AI-driven observability and security platform, addressing rising data costs and monitoring complexity for modern SOCs.
Kali365 Phishing-as-a-Service Expands to Target AWS and Okta
The FBI-flagged Kali365 phishing kit now targets AWS and Okta via device code phishing, bypassing multi-factor authentication for cloud enterprise accounts.
OpenAI GPT-3.5 Upgrades & Legacy Model Retirement: Security Impact
OpenAI is upgrading GPT-3.5 models and retiring legacy versions. Understand the impact on AI-powered security tools and data processing. Stay informed.
CVE-2026-39987: Attackers Use LLM Agents for Post-Exploitation
Discover how threat actors are leveraging LLM agents to automate post-exploitation tasks after compromising Marimo notebooks via CVE-2026-39987.
Advertisement
Securing Non-Human Identities: Lessons from Cloud Integration Flaws
Analysis of how over-permissioned non-human identities and architectural misconfigurations in cloud integrations lead to cross-tenant compromise risks.
Managing Shadow AI Tools: A Framework for Secure Enterprise Integration
Unvetted AI tools pose significant data privacy and security risks. Learn how to discover and manage shadow AI usage without impacting employee productivity.
Marlin AI: Autonomous Investigation for SaaS Security Posture
AppOmni's Marlin AI enhances SaaS security by automating misconfiguration analysis, activity investigation, and remediation recommendations across enterprise…
GCP API Keys Remain Active Post-Deletion: A 23-Minute Security Flaw
A security researcher found Google Cloud Platform (GCP) API keys stay active for 23 minutes post-deletion, posing a significant risk.
Securing Identity Attack Paths: Protecting Cached AWS Credentials
Attackers exploit cached AWS access keys to achieve lateral movement. Learn how identity-based attack paths expose 98% of cloud entities and how to defend.
Azure Backup for AKS Vulnerability: Risks of Silent Patches
A reported Azure Backup for AKS vulnerability allowed potential cluster compromise. Learn why Microsoft rejected the report and the impact of silent fixes.
OpenClaw "Claw Chain" Flaws: Data Theft and Persistence Risks
Researchers at Cyera have identified the Claw Chain, a set of four OpenClaw vulnerabilities enabling data theft, privilege escalation, and persistent access.
Optimizing Security for High-Performance AI Data Centers
Analysis of strategies to integrate robust cybersecurity measures into high-performance AI data centers without hindering critical operational efficiency and speed.
PCPJack Malware: Stealing Cloud Secrets via Parquet File Discovery
PCPJack malware replaces TeamPCP, utilizing Apache Parquet files for stealthy cloud secret theft across multiple service providers and environments.
PCPJack Worm: Analyzing the Malware Displacement in Cloud Environments
PCPJack is a new Golang-based worm targeting AWS, Docker, and Kubernetes. Learn how it removes TeamPCP and steals credentials to compromise cloud infrastructure.
PCPJack Worm Steals Cloud Credentials, Cleans TeamPCP Access
New PCPJack worm actively targets exposed cloud infrastructure, stealing credentials and removing existing TeamPCP infections. Understand its TTPs and mitigation.
PCPJack Credential Stealer: Cloud System Exploitation & Spread
PCPJack, a new credential stealer, leverages 5 unspecified CVEs to achieve worm-like spread across cloud, container, developer, and financial service environments…
Cisco Acquires Astrix: Tackling Non-Human Identity Risks for AI & Machines
Cisco's acquisition of Astrix Security targets emerging non-human identity risks in AI and machine access, enhancing identity-centric security for cloud environments.
US DoD Partners with 7 Tech Giants for Classified AI Integration
The US Department of Defense secures deals with AWS, Google, and OpenAI to integrate AI into classified environments, focusing on operational decision-making.
Secure AI Agent Integration: Preventing Production Data Loss
Organizations face catastrophic data loss as AI agents misinterpret prompts. Learn how to secure autonomous agents and implement strict guardrails.
TeamPCP Targets SAP npm Packages: Mini Shai-Hulud Supply Chain Attack
TeamPCP broadens supply chain attacks, compromising npm packages in SAP's cloud development ecosystem with the 'Mini Shai-Hulud' malicious code injection.
New DEEP#DOOR Python Backdoor Targets Cloud and Browser Credentials
DEEP#DOOR is a stealthy Python-based backdoor framework using tunneling services for persistent C2 and credential harvesting from cloud and browser data.
Beyond Code Security: Managing Your Expanding Attack Surface
Organizations often overlook security gaps in shadow IT, SaaS, and AI agents. Learn to manage an expanding attack surface beyond just secure code.