Cloud Security News

Security news for cloud platforms and services — misconfigurations, vulnerabilities and incidents affecting AWS, Azure, GCP and SaaS providers.

Cloud security incidents increasingly stem from misconfiguration and identity/access failures as much as classic software vulnerabilities, given how much infrastructure now runs on shared platforms. This feed tracks vulnerabilities, misconfig-driven exposures and incidents affecting major cloud providers and SaaS services as they are reported. It is a fast-growing category as more of the attack surface moves off traditional on-prem infrastructure.

Recent Cloud items

CVE-2026-47766crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` directory without `O_NOFOLLOW`. If a…
@cveNotify · Aug 14, 2026
CVE-2026-8715Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with…
@cveNotify · Aug 14, 2026
CVE-2026-13622A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /pr…
@cveNotify · Aug 14, 2026
Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goalhttps://ift.tt/W91fKYL
@ctinow · Aug 14, 2026
CVE-2026-13622A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /pr…
@cveNotify · Aug 14, 2026
Beacon CRM Data Breach Exposes Customer Data via Compromised AWS Access Keyhttps://gbhackers.com/beacon-crm-data-breach-exposes-customer-data/
@PentestingNews · Aug 14, 2026
CVE-2026-8715Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with…
@cveNotify · Aug 14, 2026
CVE-2026-73843OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the external…
@cveNotify · Aug 13, 2026
CVE-2026-73842OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /a…
@cveNotify · Aug 13, 2026
CVE-2026-73841OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handler…
@cveNotify · Aug 13, 2026
CVE-2026-73840OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/h…
@cveNotify · Aug 13, 2026
CVE-2026-73667OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/workflow…
@cveNotify · Aug 13, 2026
CVE-2026-73666OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerouslyDisableDefaultAuthPolicy and auth.…
@cveNotify · Aug 13, 2026
CVE-2026-8715Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with…
@cveNotify · Aug 13, 2026
CVE-2026-18741Worksuite SaaS versions prior to 6.0.14 contains a stored cross-site scripting vulnerability in the Asset Management module that allows authenticated administrators to inject arbitrary J…
@cveNotify · Aug 13, 2026
CVE-2026-17616IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain…
@cveNotify · Aug 13, 2026
CVE-2026-11932IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 is vulnerable to a denial…
@cveNotify · Aug 13, 2026
CVE-2026-18428A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on A…
@cveNotify · Aug 13, 2026
CVE-2026-62775Incorrect authorization in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to disclose information locally.🎖@cveNotify
@cveNotify · Aug 13, 2026
CVE-2026-62772Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.🎖@cveNotify
@cveNotify · Aug 13, 2026
CVE-2026-70355Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.🎖@c…
@cveNotify · Aug 13, 2026
CVE-2026-70326Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.🎖@cveNotify
@cveNotify · Aug 13, 2026
CVE-2026-70324Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.🎖@cveNotify
@cveNotify · Aug 13, 2026
CVE-2026-70321Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.🎖@cveNotify
@cveNotify · Aug 13, 2026
CVE-2026-70306Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.🎖@c…
@cveNotify · Aug 13, 2026
Cloudflare Mitigates 23.2 Million DDoS Attacks as 1 Tbps Attacks Surge 519%https://gbhackers.com/cloudflare-mitigates-23-2-million-ddos-attacks/
@PentestingNews · Aug 13, 2026
SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploithttps://securityaffairs.com/197137/hacking/sharepoint-cve-2026-55040-comes-under-attack-following-public-exploit.html
@PentestingNews · Aug 13, 2026
SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploithttps://ift.tt/cDkvOEN
@ctinow · Aug 13, 2026
Attackers Exploit SharePoint Authentication Bypass After Public PoC Releasehttps://ift.tt/lNbtYTE
@ctinow · Aug 13, 2026
CVE-2025-7195Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_s…
@cveNotify · Aug 13, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.