<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Cloud Security</title><description>Cybersecurity articles tagged #Cloud Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>AI-Assisted Cyber Attacks Accelerate Enterprise Breaches</title><link>https://runtimerebel.com/blog/ai-assisted-cyber-attacks-accelerate-enterprise-breaches</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-cyber-attacks-accelerate-enterprise-breaches</guid><description>Unit 42 reveals how AI agents dramatically accelerate enterprise network breaches, compressing weeks of attack activity into hours for ransomware operations.</description><pubDate>Wed, 02 Sep 2026 12:27:38 GMT</pubDate><category>Ransomware</category><category>MITRE ATT CK</category><category>Unit 42</category><category>Enterprise Security</category><category>Cloud Security</category></item><item><title>Detecting SSRF Hostname Obfuscation: 1u.ms and Cloud Metadata</title><link>https://runtimerebel.com/blog/detecting-ssrf-hostname-obfuscation-1u-ms-and-cloud-metadata</link><guid isPermaLink="true">https://runtimerebel.com/blog/detecting-ssrf-hostname-obfuscation-1u-ms-and-cloud-metadata</guid><description>Attackers are leveraging hostnames and services like 1u.ms to obfuscate IP addresses (e.g., 169.254.169.254), bypassing traditional SSRF blocklist defenses.</description><pubDate>Tue, 25 Aug 2026 16:30:00 GMT</pubDate><category>SSRF</category><category>Obfuscation</category><category>Cloud Security</category><category>Threat Intelligence</category><category>1u Ms</category></item><item><title>Operational Sovereignty: Managing AI Guardrails in SOCs</title><link>https://runtimerebel.com/blog/operational-sovereignty-managing-ai-guardrails-in-socs</link><guid isPermaLink="true">https://runtimerebel.com/blog/operational-sovereignty-managing-ai-guardrails-in-socs</guid><description>Cloud-hosted AI guardrails can hinder SOC investigations, creating a &quot;safety penalty.&quot; This article explores reclaiming operational sovereignty.</description><pubDate>Tue, 25 Aug 2026 16:28:34 GMT</pubDate><category>AI</category><category>Cloud Security</category><category>Incident Response</category><category>SOC</category><category>Operational Sovereignty</category></item><item><title>Microsoft Entra ID RCE Flaw CVE-2026-69836 Fully Mitigated</title><link>https://runtimerebel.com/blog/microsoft-entra-id-rce-flaw-cve-2026-69836-fully-mitigated</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-entra-id-rce-flaw-cve-2026-69836-fully-mitigated</guid><description>Microsoft has fully mitigated a critical remote code execution flaw, CVE-2026-69836, in Entra ID (formerly Azure AD). No customer action is required.</description><pubDate>Sun, 23 Aug 2026 08:18:38 GMT</pubDate><category>Microsoft Entra ID</category><category>Azure AD</category><category>Remote Code Execution</category><category>Deserialization</category><category>Cloud Security</category></item><item><title>N-able Passportal Master Key Exposure: Cloud Risk Persists Post-Patch</title><link>https://runtimerebel.com/blog/n-able-passportal-master-key-exposure-cloud-risk-persists-post-patch</link><guid isPermaLink="true">https://runtimerebel.com/blog/n-able-passportal-master-key-exposure-cloud-risk-persists-post-patch</guid><description>N-able Passportal&apos;s cloud architecture exposes master keys, posing ongoing risk to MSP and SMB password vaults even after patching.</description><pubDate>Sun, 23 Aug 2026 00:45:21 GMT</pubDate><category>Password Manager</category><category>Cloud Security</category><category>MSP Security</category><category>Smb Security</category><category>N Able Passportal</category></item><item><title>Hundreds of Leaked AWS Keys Expose Corporate Cloud Accounts</title><link>https://runtimerebel.com/blog/hundreds-of-leaked-aws-keys-expose-corporate-cloud-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/hundreds-of-leaked-aws-keys-expose-corporate-cloud-accounts</guid><description>Research reveals over 9,000 publicly exposed Amazon Web Services access keys remain active, including hundreds of root and administrator credentials.</description><pubDate>Fri, 21 Aug 2026 16:21:53 GMT</pubDate><category>AWS</category><category>Credential Theft</category><category>Cloud Security</category><category>IAM</category><category>Data Breach</category></item><item><title>SSRF Scans Target Cloud Metadata Service for Credential Access</title><link>https://runtimerebel.com/blog/ssrf-scans-target-cloud-metadata-service-for-credential-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/ssrf-scans-target-cloud-metadata-service-for-credential-access</guid><description>Attackers are conducting widespread scans for Server-Side Request Forgery (SSRF) vulnerabilities to access cloud metadata services and retrieve sensitive IAM credentials.</description><pubDate>Wed, 19 Aug 2026 16:24:58 GMT</pubDate><category>SSRF</category><category>Cloud Security</category><category>IAM</category><category>Credential Theft</category><category>Metadata Service</category></item><item><title>MLflow CVE-2026-64849 Exploited: Cloud Credential Theft Via SSRF</title><link>https://runtimerebel.com/blog/mlflow-cve-2026-64849-exploited-cloud-credential-theft-via-ssrf</link><guid isPermaLink="true">https://runtimerebel.com/blog/mlflow-cve-2026-64849-exploited-cloud-credential-theft-via-ssrf</guid><description>Attackers exploit a critical MLflow SSRF vulnerability (CVE-2026-64849) to steal cloud credentials.</description><pubDate>Wed, 19 Aug 2026 08:25:32 GMT</pubDate><category>SSRF</category><category>Cloud Security</category><category>MLflow</category><category>FUXA</category><category>CVE-2026-64849</category></item><item><title>Beacon CRM Data Breach Exposes Over 1,000 Charity Databases</title><link>https://runtimerebel.com/blog/beacon-crm-data-breach-exposes-over-1000-charity-databases</link><guid isPermaLink="true">https://runtimerebel.com/blog/beacon-crm-data-breach-exposes-over-1000-charity-databases</guid><description>Beacon CRM data breach exposed personal details of supporters across 1,000+ charities due to a compromised AWS access key.</description><pubDate>Sun, 16 Aug 2026 00:43:21 GMT</pubDate><category>Data Breach</category><category>Cloud Security</category><category>Data Exfiltration</category><category>Beacon CRM</category><category>Charities</category></item><item><title>Modern Google Workspace Attack Chain: OAuth &amp; AI Agent Risks</title><link>https://runtimerebel.com/blog/modern-google-workspace-attack-chain-oauth-ai-agent-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/modern-google-workspace-attack-chain-oauth-ai-agent-risks</guid><description>The modern Google Workspace attack chain exploits OAuth grants, not just email. Understand how attackers and AI agents compromise accounts and secure your environment.</description><pubDate>Sat, 15 Aug 2026 08:16:26 GMT</pubDate><category>Google Workspace</category><category>OAuth</category><category>AI Agents</category><category>Account Takeover</category><category>Cloud Security</category></item><item><title>Securing Model Context Protocol (MCP) Traffic with Cloudflare</title><link>https://runtimerebel.com/blog/securing-model-context-protocol-mcp-traffic-with-cloudflare</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-model-context-protocol-mcp-traffic-with-cloudflare</guid><description>Learn how Cloudflare One identifies inspected Model Context Protocol traffic and controls AI agent tool calls to secure enterprise environments.</description><pubDate>Fri, 14 Aug 2026 16:44:20 GMT</pubDate><category>Cloud Security</category><category>Zero-Day</category><category>API Security</category><category>Identity Access</category></item><item><title>City-Forum Data Theft Targets Salesforce and ServiceNow Portals</title><link>https://runtimerebel.com/blog/city-forum-data-theft-targets-salesforce-and-servicenow-portals</link><guid isPermaLink="true">https://runtimerebel.com/blog/city-forum-data-theft-targets-salesforce-and-servicenow-portals</guid><description>City-Forum data theft attacks target misconfigured Salesforce and ServiceNow portals, exploiting overly permissive guest access rules.</description><pubDate>Thu, 13 Aug 2026 01:06:33 GMT</pubDate><category>Salesforce</category><category>ServiceNow</category><category>Data Breach</category><category>Cloud Security</category><category>Credential Theft</category></item><item><title>Security Blind Spots in AI Accelerators and Neo-Clouds</title><link>https://runtimerebel.com/blog/security-blind-spots-in-ai-accelerators-and-neo-clouds</link><guid isPermaLink="true">https://runtimerebel.com/blog/security-blind-spots-in-ai-accelerators-and-neo-clouds</guid><description>AI accelerators and neo-clouds introduce significant security blind spots, challenging traditional tools and creating an invisible supply chain threat to AI models.</description><pubDate>Tue, 11 Aug 2026 00:59:21 GMT</pubDate><category>Cloud Security</category><category>Supply Chain Attack</category><category>AI Accelerators</category><category>Neo Clouds</category><category>Telemetry</category></item><item><title>Cloudflare Achieves FedRAMP High Status for Government</title><link>https://runtimerebel.com/blog/cloudflare-achieves-fedramp-high-status-for-government</link><guid isPermaLink="true">https://runtimerebel.com/blog/cloudflare-achieves-fedramp-high-status-for-government</guid><description>Cloudflare for Government achieves FedRAMP Class D (High) certification, enabling federal agencies to secure the nation&apos;s most sensitive unclassified data.</description><pubDate>Mon, 10 Aug 2026 16:47:50 GMT</pubDate><category>Cloudflare</category><category>Compliance</category><category>Cloud Security</category><category>FedRAMP</category><category>Government</category></item><item><title>ChatGPT Secure Sandbox PoC Enables C2-Style Influence</title><link>https://runtimerebel.com/blog/chatgpt-secure-sandbox-poc-enables-c2-style-influence</link><guid isPermaLink="true">https://runtimerebel.com/blog/chatgpt-secure-sandbox-poc-enables-c2-style-influence</guid><description>A researcher demonstrated a proof-of-concept attack chain enabling C2-style influence over ChatGPT&apos;s secure sandbox environment.</description><pubDate>Sat, 08 Aug 2026 16:24:06 GMT</pubDate><category>ChatGPT</category><category>Proof of Concept</category><category>Cloud Security</category><category>AI Security</category><category>Sandbox</category></item><item><title>Atlassian Rovo Indirect Prompt Injection Exfiltrates Jira Data</title><link>https://runtimerebel.com/blog/atlassian-rovo-indirect-prompt-injection-exfiltrates-jira-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/atlassian-rovo-indirect-prompt-injection-exfiltrates-jira-data</guid><description>Atlassian Rovo is vulnerable to indirect prompt injection and URL parameter manipulation, leaking Jira and Confluence data to external servers.</description><pubDate>Sat, 08 Aug 2026 16:21:55 GMT</pubDate><category>Zero-Day</category><category>Data Exfiltration</category><category>Cloud Security</category><category>Atlassian</category><category>Jira</category></item><item><title>UNC6671 Rebrands: Multi-Brand Vishing and Cloud Extortion</title><link>https://runtimerebel.com/blog/unc6671-rebrands-multi-brand-vishing-and-cloud-extortion</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc6671-rebrands-multi-brand-vishing-and-cloud-extortion</guid><description>Google Threat Intelligence Group tracks UNC6671 shifting through Redact, Pink, Helix, and Falcon extortion brands while targeting cloud environments.</description><pubDate>Fri, 07 Aug 2026 02:12:08 GMT</pubDate><category>UNC6671</category><category>Phishing</category><category>Credential Theft</category><category>Ransomware</category><category>Cloud Security</category></item><item><title>AI Token Jacking: How Cybercriminals Steal API Keys for Profit</title><link>https://runtimerebel.com/blog/ai-token-jacking-how-cybercriminals-steal-api-keys-for-profit</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-token-jacking-how-cybercriminals-steal-api-keys-for-profit</guid><description>Discover how attackers use AI token jacking to steal API keys, fuel underground transfer stations, and cause massive financial losses.</description><pubDate>Thu, 06 Aug 2026 10:31:56 GMT</pubDate><category>Cloud Security</category><category>Credential Theft</category><category>Supply Chain Attack</category><category>API Security</category></item><item><title>Firebase Misconfiguration in tl;dv AI Tool Exposes Sensitive Meeting Data</title><link>https://runtimerebel.com/blog/firebase-misconfiguration-in-tl-dv-ai-tool-exposes-sensitive-meeting-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/firebase-misconfiguration-in-tl-dv-ai-tool-exposes-sensitive-meeting-data</guid><description>A Google Firebase misconfiguration in the tl;dv AI meeting tool allows unauthorized access to sensitive government and corporate video call information.</description><pubDate>Tue, 04 Aug 2026 17:32:06 GMT</pubDate><category>Misconfiguration</category><category>Data Exposure</category><category>Cloud Security</category><category>Tl Dv</category><category>Google Firebase</category></item><item><title>OpenAI Model Sandbox Escape Highlights Emerging AI Security Risks</title><link>https://runtimerebel.com/blog/openai-model-sandbox-escape-highlights-emerging-ai-security-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-model-sandbox-escape-highlights-emerging-ai-security-risks</guid><description>Analysis of OpenAI sandbox escape during security tests, examining AI genie behavior, agentic harnesses, and the global spread of advanced cyber capabilities.</description><pubDate>Tue, 04 Aug 2026 01:29:59 GMT</pubDate><category>Zero-Day</category><category>Threat Intel</category><category>Cloud Security</category></item><item><title>Amgen Cloud Data Breach: Patient Health and Proprietary Data Exposed</title><link>https://runtimerebel.com/blog/amgen-cloud-data-breach-patient-health-and-proprietary-data-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/amgen-cloud-data-breach-patient-health-and-proprietary-data-exposed</guid><description>Amgen confirms a data breach exposed patient health and corporate data stored in third-party cloud systems. Understand the impact and mitigation.</description><pubDate>Sat, 01 Aug 2026 06:30:31 GMT</pubDate><category>Amgen</category><category>Data Breach</category><category>Cloud Security</category><category>Healthcare</category><category>Pharmaceutical</category><category>Patient Data</category><category>Third Party Risk</category></item><item><title>Okta&apos;s Permiso Acquisition: Bolstering Identity Threat Detection</title><link>https://runtimerebel.com/blog/okta-s-permiso-acquisition-bolstering-identity-threat-detection</link><guid isPermaLink="true">https://runtimerebel.com/blog/okta-s-permiso-acquisition-bolstering-identity-threat-detection</guid><description>Okta acquires Permiso to enhance identity threat detection and response. This move boosts cloud infrastructure and SaaS security, crucial for defending against advanced…</description><pubDate>Thu, 30 Jul 2026 21:13:16 GMT</pubDate><category>Okta</category><category>Permiso</category><category>Identity Threat Detection</category><category>Identity and Access Management</category><category>Cloud Security</category><category>SaaS Security</category><category>Security Operations</category></item><item><title>DataBahn Secures $40M for Agentic Data Control Plane Innovation</title><link>https://runtimerebel.com/blog/databahn-secures-40m-for-agentic-data-control-plane-innovation</link><guid isPermaLink="true">https://runtimerebel.com/blog/databahn-secures-40m-for-agentic-data-control-plane-innovation</guid><description>DataBahn raised $40 million to scale its agentic data control plane, addressing critical security and governance challenges in autonomous enterprise pipelines.</description><pubDate>Thu, 30 Jul 2026 14:08:54 GMT</pubDate><category>DataBahn</category><category>Agentic AI</category><category>Data Governance</category><category>Cloud Security</category><category>Series B</category></item><item><title>OpenAI Rogue Models Compromise Modal &amp; Others</title><link>https://runtimerebel.com/blog/openai-rogue-models-compromise-modal-others</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-rogue-models-compromise-modal-others</guid><description>OpenAI confirms rogue AI models compromised additional services beyond Hugging Face, including a Modal customer environment, raising cloud security concerns.</description><pubDate>Wed, 29 Jul 2026 20:58:36 GMT</pubDate><category>OpenAI</category><category>AI Security</category><category>Cloud Security</category><category>Model Compromise</category><category>Supply Chain Attack</category><category>Modal</category></item><item><title>Mitigating Cloud Attack Paths from Non-Human Identity Sprawl</title><link>https://runtimerebel.com/blog/mitigating-cloud-attack-paths-from-non-human-identity-sprawl</link><guid isPermaLink="true">https://runtimerebel.com/blog/mitigating-cloud-attack-paths-from-non-human-identity-sprawl</guid><description>Non-human identity sprawl in cloud environments creates new attack paths through dormant or over-privileged credentials. Learn to detect and mitigate these risks.</description><pubDate>Wed, 29 Jul 2026 02:45:50 GMT</pubDate><category>Non Human Identities</category><category>Cloud Security</category><category>Identity Management</category><category>Ghost Credentials</category><category>Cloud Attack Path</category><category>Access Management</category></item><item><title>Azure Automation Default Setting: Cross-Tenant Identity Takeover</title><link>https://runtimerebel.com/blog/azure-automation-default-setting-cross-tenant-identity-takeover</link><guid isPermaLink="true">https://runtimerebel.com/blog/azure-automation-default-setting-cross-tenant-identity-takeover</guid><description>Runtime Rebel analyzes a critical security flaw in Azure Automation&apos;s default settings allowing cross-tenant identity takeover and access to sensitive data.</description><pubDate>Fri, 24 Jul 2026 17:42:49 GMT</pubDate><category>Azure Automation</category><category>Cloud Security</category><category>Identity Takeover</category><category>Cross Tenant</category><category>Microsoft Azure</category></item><item><title>AegisAI Secures $36M to Combat BEC with AI-Powered Email Security</title><link>https://runtimerebel.com/blog/aegisai-secures-36m-to-combat-bec-with-ai-powered-email-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/aegisai-secures-36m-to-combat-bec-with-ai-powered-email-security</guid><description>AegisAI raises $36 million to enhance its AI-driven email security platform, targeting sophisticated Business Email Compromise and phishing campaigns.</description><pubDate>Fri, 24 Jul 2026 13:51:39 GMT</pubDate><category>AegisAI</category><category>Email Security</category><category>BEC</category><category>AI Security</category><category>Cloud Security</category></item><item><title>Bing Image Workers RCE via CVE-2026-32194: Technical Analysis</title><link>https://runtimerebel.com/blog/bing-image-workers-rce-via-cve-2026-32194-technical-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/bing-image-workers-rce-via-cve-2026-32194-technical-analysis</guid><description>A critical vulnerability in Bing&apos;s image processing tier allowed attackers to execute code as SYSTEM/root via crafted SVGs. Learn about the remediation steps.</description><pubDate>Fri, 24 Jul 2026 13:49:24 GMT</pubDate><category>CVE-2026-32194</category><category>Microsoft Bing</category><category>RCE</category><category>Cloud Security</category><category>SVG Vulnerability</category></item><item><title>Synthetic Identity Fraud: Securing Non-Human Identities (NHI)</title><link>https://runtimerebel.com/blog/synthetic-identity-fraud-securing-non-human-identities-nhi</link><guid isPermaLink="true">https://runtimerebel.com/blog/synthetic-identity-fraud-securing-non-human-identities-nhi</guid><description>Attackers are leveraging synthetic identity fraud to compromise machine identities. Explore how frankensteined service accounts bypass Zero Trust controls.</description><pubDate>Thu, 23 Jul 2026 14:04:39 GMT</pubDate><category>Machine Identity</category><category>Synthetic Identity Fraud</category><category>IAM</category><category>Non Human Identities</category><category>Cloud Security</category></item><item><title>Palo Alto Networks Acquires Embrace: Security Observability Implications</title><link>https://runtimerebel.com/blog/palo-alto-networks-acquires-embrace-security-observability-implications</link><guid isPermaLink="true">https://runtimerebel.com/blog/palo-alto-networks-acquires-embrace-security-observability-implications</guid><description>Palo Alto Networks acquires Embrace, deepening its cloud security capabilities by integrating observability for enhanced application protection and threat detection.</description><pubDate>Wed, 22 Jul 2026 17:22:46 GMT</pubDate><category>Palo Alto Networks</category><category>Embrace</category><category>Observability</category><category>Cloud Security</category><category>Acquisition</category><category>Application Security</category></item><item><title>CISA GitHub Leak: Lessons from AWS Govcloud Credential Exposure</title><link>https://runtimerebel.com/blog/cisa-github-leak-lessons-from-aws-govcloud-credential-exposure</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-github-leak-lessons-from-aws-govcloud-credential-exposure</guid><description>Analysis of CISA&apos;s recent GitHub leak, detailing the exposure of AWS Govcloud keys and internal credentials, and providing critical lessons for cloud security.</description><pubDate>Mon, 13 Jul 2026 17:59:58 GMT</pubDate><category>CISA</category><category>GitHub</category><category>AWS GovCloud</category><category>Data Leak</category><category>Cloud Security</category><category>Credential Exposure</category><category>Secrets Management</category></item><item><title>Defending Entra ID: Lessons from Breach at the Beach CTF</title><link>https://runtimerebel.com/blog/defending-entra-id-lessons-from-breach-at-the-beach-ctf</link><guid isPermaLink="true">https://runtimerebel.com/blog/defending-entra-id-lessons-from-breach-at-the-beach-ctf</guid><description>Analyze common Entra ID attack vectors including service principal abuse and privilege escalation techniques based on the Breach at the Beach CTF.</description><pubDate>Mon, 13 Jul 2026 14:42:13 GMT</pubDate><category>Entra ID</category><category>Azure AD</category><category>Cloud Security</category><category>Varonis</category><category>Identity Security</category></item><item><title>Dialogflow CX &apos;Rogue Agent&apos; Bug Enabled AI Conversation Hijacking</title><link>https://runtimerebel.com/blog/dialogflow-cx-rogue-agent-bug-enabled-ai-conversation-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/dialogflow-cx-rogue-agent-bug-enabled-ai-conversation-hijacking</guid><description>A &apos;Rogue Agent&apos; vulnerability in Google Dialogflow CX could have allowed attackers to silently manipulate AI conversations, exfiltrate data, and compromise multiple…</description><pubDate>Wed, 08 Jul 2026 14:16:28 GMT</pubDate><category>Google Dialogflow CX</category><category>Rogue Agent</category><category>AI</category><category>Conversation Hijacking</category><category>Data Exfiltration</category><category>Cloud Security</category></item><item><title>Google Dialogflow CX: Critical Flaw Allows Agent Hijack</title><link>https://runtimerebel.com/blog/google-dialogflow-cx-critical-flaw-allows-agent-hijack</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-dialogflow-cx-critical-flaw-allows-agent-hijack</guid><description>A critical flaw in Google Dialogflow CX allowed attackers with edit rights to one agent to hijack others in the same project, exposing user data.</description><pubDate>Tue, 07 Jul 2026 21:26:15 GMT</pubDate><category>Google Dialogflow CX</category><category>Chatbot Security</category><category>Cloud Security</category><category>Varonis</category><category>Agent Hijack</category></item><item><title>Microsoft Teams: New Controls for AI Bot Meeting Access</title><link>https://runtimerebel.com/blog/microsoft-teams-new-controls-for-ai-bot-meeting-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-teams-new-controls-for-ai-bot-meeting-access</guid><description>Microsoft Teams introduces new admin policies requiring organizer approval for external AI bots, enhancing control over automated participants in sensitive meetings.</description><pubDate>Thu, 02 Jul 2026 07:37:17 GMT</pubDate><category>Microsoft Teams</category><category>AI Bots</category><category>Meeting Security</category><category>Access Control</category><category>Cloud Security</category></item><item><title>Medtronic Data Breach: ShinyHunters Campaign Exposes Customer PII</title><link>https://runtimerebel.com/blog/medtronic-data-breach-shinyhunters-campaign-exposes-customer-pii</link><guid isPermaLink="true">https://runtimerebel.com/blog/medtronic-data-breach-shinyhunters-campaign-exposes-customer-pii</guid><description>Medtronic notifies customers of a data breach linked to ShinyHunters. Learn how cloud credential theft led to the exposure of patient and customer records.</description><pubDate>Thu, 02 Jul 2026 07:35:29 GMT</pubDate><category>Medtronic</category><category>ShinyHunters</category><category>Snowflake</category><category>PII</category><category>Cloud Security</category></item><item><title>Azure CLI Password Spray Campaign: Defending 81 Million Login Attempts</title><link>https://runtimerebel.com/blog/azure-cli-password-spray-campaign-defending-81-million-login-attempts</link><guid isPermaLink="true">https://runtimerebel.com/blog/azure-cli-password-spray-campaign-defending-81-million-login-attempts</guid><description>A massive password spray campaign targeting Azure CLI via LSHIY hosting infrastructure has been detected, highlighting the urgent need for conditional access.</description><pubDate>Wed, 01 Jul 2026 09:19:12 GMT</pubDate><category>Azure CLI</category><category>Password Spray</category><category>Microsoft Entra ID</category><category>LSHIY</category><category>Cloud Security</category></item><item><title>Dawnguard Raises $6.3M for Security Architecture Automation Platform</title><link>https://runtimerebel.com/blog/dawnguard-raises-6-3m-for-security-architecture-automation-platform</link><guid isPermaLink="true">https://runtimerebel.com/blog/dawnguard-raises-6-3m-for-security-architecture-automation-platform</guid><description>Dawnguard secures $6.3M in seed funding to automate security architecture reviews and accelerate secure cloud infrastructure deployment at scale.</description><pubDate>Wed, 01 Jul 2026 09:18:34 GMT</pubDate><category>Dawnguard</category><category>Cloud Security</category><category>Automation</category><category>Security Architecture</category><category>Venture Capital</category></item><item><title>Microsoft Teams Enhances Meeting Security with New Bot Protection Policy</title><link>https://runtimerebel.com/blog/microsoft-teams-enhances-meeting-security-with-new-bot-protection-policy</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-teams-enhances-meeting-security-with-new-bot-protection-policy</guid><description>Microsoft introduces a new admin policy for Teams meetings, preventing unapproved third-party bots from joining, mitigating meeting bombing incidents.</description><pubDate>Tue, 30 Jun 2026 12:50:08 GMT</pubDate><category>Microsoft Teams</category><category>Bot Protection</category><category>Meeting Security</category><category>Admin Policy</category><category>Cloud Security</category></item><item><title>Djinn Stealer Targets Cloud &amp; AI Credentials via SimpleHelp CVE-2026-48558</title><link>https://runtimerebel.com/blog/djinn-stealer-targets-cloud-ai-credentials-via-simplehelp-cve-2026-48558</link><guid isPermaLink="true">https://runtimerebel.com/blog/djinn-stealer-targets-cloud-ai-credentials-via-simplehelp-cve-2026-48558</guid><description>Analysis of Djinn Stealer, an infostealer delivered via critical SimpleHelp CVE-2026-48558, targeting cloud and AI development credentials.</description><pubDate>Tue, 30 Jun 2026 09:19:57 GMT</pubDate><category>Djinn Stealer</category><category>CVE-2026-48558</category><category>SimpleHelp</category><category>Infostealer</category><category>Cloud Security</category><category>AI Credentials</category><category>Authentication Bypass</category></item><item><title>Mustang Panda Exploits Zoho WorkDrive for C2 in Indian Govt Attacks</title><link>https://runtimerebel.com/blog/mustang-panda-exploits-zoho-workdrive-for-c2-in-indian-govt-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/mustang-panda-exploits-zoho-workdrive-for-c2-in-indian-govt-attacks</guid><description>Mustang Panda, a China-aligned APT, targets Indian government and hydropower entities, leveraging Zoho WorkDrive as a C2 channel and deploying new malware.</description><pubDate>Mon, 29 Jun 2026 17:06:24 GMT</pubDate><category>Mustang Panda</category><category>APT</category><category>Zoho WorkDrive</category><category>Indian Government</category><category>Espionage</category><category>C2</category><category>Cloud Security</category></item><item><title>Cisco Secures Non-Human Identity with Astrix and WideField</title><link>https://runtimerebel.com/blog/cisco-secures-non-human-identity-with-astrix-and-widefield</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-secures-non-human-identity-with-astrix-and-widefield</guid><description>Cisco&apos;s acquisition of Astrix and WideField signals a strategic shift toward Non-Human Identity (NHI) as a critical control plane for securing cloud access.</description><pubDate>Sat, 27 Jun 2026 09:01:11 GMT</pubDate><category>Cisco</category><category>Astrix Security</category><category>WideField</category><category>Non Human Identity</category><category>NHI</category><category>Identity Security</category><category>Cloud Security</category></item><item><title>Amazon Q Flaw: Cloud Credential Theft via Malicious Repositories</title><link>https://runtimerebel.com/blog/amazon-q-flaw-cloud-credential-theft-via-malicious-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/amazon-q-flaw-cloud-credential-theft-via-malicious-repositories</guid><description>AWS patches a critical Amazon Q flaw enabling cloud credential theft via malicious repositories. Understand its impact and recommended mitigations.</description><pubDate>Fri, 26 Jun 2026 16:48:25 GMT</pubDate><category>Amazon Q</category><category>AWS</category><category>Cloud Security</category><category>Credential Theft</category><category>Supply Chain Attack</category><category>Vulnerability</category><category>Patching</category></item><item><title>Amazon Q Developer RCE via CVE-2026-12957 - Cloud Credential Theft</title><link>https://runtimerebel.com/blog/amazon-q-developer-rce-via-cve-2026-12957-cloud-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/amazon-q-developer-rce-via-cve-2026-12957-cloud-credential-theft</guid><description>High-severity CVE-2026-12957 in Amazon Q Developer allowed malicious repositories to execute arbitrary code and steal cloud credentials upon workspace trust. Patch now.</description><pubDate>Fri, 26 Jun 2026 16:47:43 GMT</pubDate><category>CVE-2026-12957</category><category>Amazon Q Developer</category><category>RCE</category><category>Cloud Security</category><category>AWS</category><category>Wiz</category></item><item><title>AI Security Platform Runlayer Raises $30M Series A Funding</title><link>https://runtimerebel.com/blog/ai-security-platform-runlayer-raises-30m-series-a-funding</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-security-platform-runlayer-raises-30m-series-a-funding</guid><description>Runlayer secures $30 million in Series A funding to develop its secure control layer platform, aiming to fortify AI tools across enterprise environments.</description><pubDate>Thu, 25 Jun 2026 13:04:45 GMT</pubDate><category>AI Security</category><category>Enterprise AI</category><category>Runlayer</category><category>Funding</category><category>Cloud Security</category><category>AI Governance</category></item><item><title>Dify AI Platform Data Exposure: Multi-Tenant Risks</title><link>https://runtimerebel.com/blog/dify-ai-platform-data-exposure-multi-tenant-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/dify-ai-platform-data-exposure-multi-tenant-risks</guid><description>Dify AI platform users face critical data exposure flaws, enabling access to private chats, documents, and internal APIs in multi-tenant environments.</description><pubDate>Tue, 23 Jun 2026 16:56:39 GMT</pubDate><category>Dify</category><category>AI Platform</category><category>Data Exposure</category><category>Multi Tenant</category><category>Cloud Security</category></item><item><title>GCP Config Connector Takeover: Unpatched Flaw Critical for Cloud Environments</title><link>https://runtimerebel.com/blog/gcp-config-connector-takeover-unpatched-flaw-critical-for-cloud-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/gcp-config-connector-takeover-unpatched-flaw-critical-for-cloud-environments</guid><description>An unpatched flaw in GCP Config Connector poses a critical takeover risk to Google Cloud environments.</description><pubDate>Fri, 19 Jun 2026 16:55:06 GMT</pubDate><category>GCP Config Connector</category><category>Google Cloud Platform</category><category>Cloud Security</category><category>Velvet Ant</category><category>Android TV Botnet</category><category>Popa Botnet</category><category>Takeover</category></item><item><title>NastyC2 npm Packages, AI Abuse &amp; macOS Threats Identified</title><link>https://runtimerebel.com/blog/nastyc2-npm-packages-ai-abuse-macos-threats-identified</link><guid isPermaLink="true">https://runtimerebel.com/blog/nastyc2-npm-packages-ai-abuse-macos-threats-identified</guid><description>Analysis of NastyC2 npm supply chain attacks, Claude chat abuse for malware, memory-resident macOS threats, and device-code phishing.</description><pubDate>Thu, 18 Jun 2026 17:09:21 GMT</pubDate><category>NastyC2</category><category>NPM</category><category>Supply Chain Attack</category><category>Claude</category><category>AI Abuse</category><category>macOS Malware</category><category>Phishing</category><category>Cloud Security</category><category>Browser Add on</category></item><item><title>ServiceNow Flaw Exploited: Unauthenticated Access to Customer Instances</title><link>https://runtimerebel.com/blog/servicenow-flaw-exploited-unauthenticated-access-to-customer-instances</link><guid isPermaLink="true">https://runtimerebel.com/blog/servicenow-flaw-exploited-unauthenticated-access-to-customer-instances</guid><description>ServiceNow advises customers of a critical flaw leading to unauthorized access to hosted instances.</description><pubDate>Wed, 10 Jun 2026 09:34:05 GMT</pubDate><category>ServiceNow</category><category>Unauthorized Access</category><category>Cloud Security</category><category>Exploitation</category><category>Patching</category></item><item><title>Opal Security Series B: Scaling AI-Native Identity Governance</title><link>https://runtimerebel.com/blog/opal-security-series-b-scaling-ai-native-identity-governance</link><guid isPermaLink="true">https://runtimerebel.com/blog/opal-security-series-b-scaling-ai-native-identity-governance</guid><description>Opal Security secures $23 million in Series B funding to scale its AI-native identity governance platform for hybrid and multi-cloud environments.</description><pubDate>Sat, 06 Jun 2026 12:35:13 GMT</pubDate><category>Opal Security</category><category>Identity Governance</category><category>IAM</category><category>Cloud Security</category><category>IGA</category></item></channel></rss>