Cloud Security News

Security news for cloud platforms and services: misconfigurations, vulnerabilities and incidents affecting AWS, Azure, GCP and SaaS providers.

Cloud security incidents increasingly stem from misconfiguration and identity or access failures as much as from classic software vulnerabilities, now that so much infrastructure runs on shared platforms. Vulnerabilities, misconfig-driven exposures and incidents affecting major cloud providers and SaaS services land here.

Recent Cloud items

CVE-2026-102273 PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because HMAC key guard only recognizes top-level pub…
@cveNotify · Sep 28, 2026
Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts https://ift.tt/KXu476w
@ctinow · Sep 28, 2026
JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources 🖋️ The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft…
@cibsecurity · Sep 28, 2026
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent 🖋️ Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting ex…
@cibsecurity · Sep 28, 2026
CVE-2026-19759 An Incorrect Authorization vulnerability in the task configuration in Google Cloud Application Integration versions prior to 2026-06-17 on Google Cloud Platform allows an authenticated…
@cveNotify · Sep 28, 2026
CVE-2026-55160 Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to force the S…
@cveNotify · Sep 28, 2026
CVE-2026-55160 Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery (SSRF) vulnerability allows any authenticated user to force the S…
@cveNotify · Sep 28, 2026
CVE-2026-87114 A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untrusted container image's entrypoint instead of merely extracting d…
@cveNotify · Sep 28, 2026
CVE-2026-93539 A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without veri…
@cveNotify · Sep 28, 2026
JadePuffer agentic AI attacks target Azure, destroy cloud resources The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentia…
@bleepingcomputer · Sep 28, 2026
JadePuffer agentic AI attacks target Azure, destroy cloud resources https://ift.tt/54uiBtr
@ctinow · Sep 28, 2026
CVE-2026-100839 Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML handling is vulnerable to an AML injection attack ("BadAML"). ACPI t…
@cveNotify · Sep 28, 2026
CVE-2026-100838 Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generated by the Contrast CLI contained a flaw in the CopyFile verificat…
@cveNotify · Sep 28, 2026
CVE-2025-71426 Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.4.1, a recovering Coordinator does not verify the seed supplied by the recovering party. An attacker ca…
@cveNotify · Sep 28, 2026
CVE-2025-71425 Contrast (Edgeless Systems) before 1.8.1 logs the workload secret to stderr, and thus to Kubernetes logs, when the Contrast initializer is configured with CONTRAST_LOG_LEVEL set to info…
@cveNotify · Sep 28, 2026
CVE-2025-71423 Edgelesssys Contrast is a confidential-computing runtime for Kubernetes. In versions 1.9.0 before 1.12.2, the initializer logs the full NewMeshCert response — which contains the workloa…
@cveNotify · Sep 28, 2026
CVE-2025-71422 Contrast is a Kubernetes runtime for confidential containers. In versions before 1.12.1, the secure persistent volume feature is vulnerable to a malicious host supplying a crafted LUKS2…
@cveNotify · Sep 28, 2026
JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack https://ift.tt/XRIznxE
@ctinow · Sep 28, 2026
CVE-2026-93539 A vulnerability was discovered in Fleet's Git webhook receiver (the gitjob webhook service). When a webhook secret is not configured, incoming webhook requests are accepted without veri…
@cveNotify · Sep 28, 2026
KB5002907 Paused After Office 2016 and 2019 Lose Activation or Disappear Microsoft has paused KB5002907 after the update left some Office 2016 and Office 2019 installations unusable. A repair intended…
@topcybersecurity · Sep 28, 2026
US organizations are a primary target of CSuite. The operation uses business-themed lures to steal M365 sessions or deliver RMM tools. The detection surface is the reused lure build: /m/js/utils.js or…
@anyrun_app · Sep 28, 2026
CVE-2026-93537 A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push access, or through permission to create or modify a GitRepo, can caus…
@cveNotify · Sep 28, 2026
CVE-2026-3855 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allow…
@cveNotify · Sep 28, 2026
Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities https://securityaffairs.com/199905/cyber-crime/storm-3168-linked-to-jadepuffer-abused-stolen-azure-identities.html
@PentestingNews · Sep 28, 2026
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent https://ift.tt/NqMOIXx
@ctinow · Sep 28, 2026
CVE-2026-78424 Improper parameter handling in NeuVector allows any authenticated user who holds the namespaced Runtime Policies (write) permission or anyone with access to NeuVector’s internal gRPC ce…
@cveNotify · Sep 28, 2026
CVE-2026-19444 A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the containe…
@cveNotify · Sep 28, 2026
Carbonato compromises unauthenticated Docker daemons, then deploys Hermes Agent for Telegram-driven, LLM-generated commands. The botnet persists on infected hosts and scans nearby networks every five…
@thehackernews · Sep 28, 2026
Storm-3168, Linked to JADEPUFFER, Abused Stolen Azure Identities https://ift.tt/Lr2NF7m
@ctinow · Sep 28, 2026
CVE-2026-81867 A Deserialization of Untrusted Data vulnerability in the JavaScript Task in Google Cloud Application Integration versions prior to 2026-06-28 on Google Cloud Platform allows an authenti…
@cveNotify · Sep 28, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Ransomware
Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.