Cloud Security News

Security news for cloud platforms and services — misconfigurations, vulnerabilities and incidents affecting AWS, Azure, GCP and SaaS providers.

Cloud security incidents increasingly stem from misconfiguration and identity/access failures as much as classic software vulnerabilities, given how much infrastructure now runs on shared platforms. This feed tracks vulnerabilities, misconfig-driven exposures and incidents affecting major cloud providers and SaaS services as they are reported. It is a fast-growing category as more of the attack surface moves off traditional on-prem infrastructure.

Recent Cloud items

CVE-2025-7195 Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_…
@cveNotify · Sep 6, 2026
CVE-2026-7163 A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal…
@cveNotify · Sep 5, 2026
CVE-2026-7163 A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal…
@cveNotify · Sep 5, 2026
CVE-2026-75485 A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction t…
@cveNotify · Sep 5, 2026
CVE-2026-73834 A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without re…
@cveNotify · Sep 5, 2026
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials https://ift.tt/VJFWlyg
@ctinow · Sep 5, 2026
Attackers breached JetBrains Cadence via an unpatched TeamCity server, extracting AWS IAM credentials from a 2024 backup and accessing user data and S3 files.JetBrains is urging users to rotate secret…
@thehackernews · Sep 5, 2026
CVE-2026-75485 A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, bypassing the oc inspect redaction t…
@cveNotify · Sep 5, 2026
CVE-2026-73834 A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without re…
@cveNotify · Sep 5, 2026
CVE-2026-54100 A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the r…
@cveNotify · Sep 5, 2026
CVE-2026-54099 A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains…
@cveNotify · Sep 5, 2026
CVE-2026-66794 A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing rout…
@cveNotify · Sep 5, 2026
CVE-2026-10090 A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scop…
@cveNotify · Sep 5, 2026
CVE-2026-10059 A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating…
@cveNotify · Sep 5, 2026
CVE-2026-17107 A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends…
@cveNotify · Sep 5, 2026
CVE-2026-10090 A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scop…
@cveNotify · Sep 5, 2026
CVE-2026-4740 A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allow…
@cveNotify · Sep 5, 2026
CVE-2026-85596 Traefik versions >= v3.7.0 and
@cveNotify · Sep 5, 2026
CVE-2026-86124 AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can c…
@cveNotify · Sep 5, 2026
CVE-2026-86121 Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated atta…
@cveNotify · Sep 5, 2026
CVE-2026-86114 Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including instance-wide d…
@cveNotify · Sep 5, 2026
ALERT - Thousands of AI agents identifying as OpenAI systems quietly coordinated on a dormant German wiki.They left 18,000 posts, relayed answers, predicted questions, and shared a proxy bypass using…
@thehackernews · Sep 5, 2026
CVE-2026-83711 Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. 🎖
@cveNotify · Sep 5, 2026
CVE-2026-70352 Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network. 🎖
@cveNotify · Sep 5, 2026
CVE-2026-85787 An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data be…
@cveNotify · Sep 4, 2026
CVE-2026-69502 Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. 🎖
@cveNotify · Sep 4, 2026
CVE-2026-85786 Improper handling of highly compressed data in Amazon ion-java before 1.12.1 might allow remote attackers to cause a denial of service via a crafted compressed Ion document that expands…
@cveNotify · Sep 4, 2026
CVE-2026-85781 Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVo…
@cveNotify · Sep 4, 2026
CVE-2026-85781 Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVo…
@cveNotify · Sep 4, 2026
CVE-2026-85656 An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a…
@cveNotify · Sep 4, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.