Glossary
Cloud Security
The practices, controls, and technologies used to protect data, applications, and infrastructure hosted in cloud environments, addressing the shared-responsibility split between the cloud provider, which secures the underlying infrastructure, and the customer, who secures what they configure and put in it. Misconfiguration on the customer side of that split is the leading cause of cloud breaches.
// Recent coverage mentioning Cloud Security
Azure Cosmos DB CosmosEscape Flaw: Cross-Tenant Database Access
Wiz researchers uncover CosmosEscape, a sandbox escape in Azure Cosmos DB's Gremlin API allowing unauthorized cross-tenant read and write access.
Chrome Security Update and SonicWall Targeted in AI-Driven Campaigns
Analysis of 370 Chrome vulnerabilities and active SonicWall targeting, highlighting the rise of AI-powered phishing and automated DNS hijacking threats.
Azure Automation Default Setting: Cross-Tenant Identity Takeover
Runtime Rebel analyzes a critical security flaw in Azure Automation's default settings allowing cross-tenant identity takeover and access to sensitive data.
Amazon Q Flaw: Cloud Credential Theft via Malicious Repositories
AWS patches a critical Amazon Q flaw enabling cloud credential theft via malicious repositories. Understand its impact and recommended mitigations.
Dify AI Platform Data Exposure: Multi-Tenant Risks
Dify AI platform users face critical data exposure flaws, enabling access to private chats, documents, and internal APIs in multi-tenant environments.
Cisco Acquires WideField Security to Advance Splunk Agentic SOC
Cisco expands its security portfolio by acquiring WideField Security to integrate identity and session context into Splunk’s AI-driven Agentic SOC platform.