Security news aggregator

Latest coverage for Cloud

Stay updated with the latest trends and security protocols in cloud computing. Navigate the evolving landscape of Cloud Information Security with us.

2248 headlines in this view

Refine the feed

Search across headline titles and summaries.

Tag briefing

Background for this topic.

Cloud is a term that describes the use of networked remote servers hosted on the internet to store, manage, and process data, as opposed to using a local server or a personal computer. In the context of information security, the cloud represents an environment that facilitates both the convenience and challenges of managing and safeguarding data and applications.

In this environment, security concerns include protecting data from unauthorized access, ensuring data integrity, preventing data breaches, and maintaining user privacy. Due to the shared resource nature of cloud services, information security must also address multi-tenancy issues, where multiple users or organizations store their data on the same physical hardware.

Additionally, the dynamic nature of cloud computing, with its ability to scale resources on demand, introduces unique security considerations. These include the need for robust identity and access management (IAM) systems, encryption of data both at rest and in transit, and adherence to compliance standards and regulations that govern data security in the cloud.

Securing the cloud involves a shared responsibility model—where cloud service providers are responsible for the security of the cloud infrastructure, and customers must secure their data and applications within the cloud. This collaborative effort helps ensure that the full potential of cloud computing is realized in a secure and compliant manner.

Volume over time

Weekly headline count for the current query.

Showing 20 most recent headlines of 2248 Filtered view

A large-scale npm supply chain attack compromised over 90 versions of @redhat-cloud-services packages, silently infecting CI/CD environments and developer systems. The malicious code steals credentials from GitHub, cloud platforms, and local machines, then spreads like a worm by republishing trusted packages. Discover how the attack works, what data is at risk, and the steps you can take to protect your organization. The post Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign appeared first on Microsoft Security Blog.

An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclosed vulnerability

Microsoft Security Research 5 days, 20 hours ago

Typosquatted npm packages used to steal cloud and CI/CD secrets

The Mini Shai-Hulud campaign used malicious npm packages to target cloud and CI/CD credentials across developer environments. This report details the attack chain, detection opportunities, and mitigation guidance to help organizations identify and disrupt related activity. The post Typosquatted npm packages used to steal cloud and CI/CD secrets appeared first on Microsoft Security Blog.

19.6 Billion files are exposed in misconfigured cloud buckets, including 685K credential files and nearly 1M database dumps. There’s a comfortable myth most people carry around: that the data they hand to companies is locked somewhere safe. Researchers at Mysterium VPN just ran the numbers, and the numbers disagree. Across 535,480 publicly listable cloud storage […]

Startup Symmetry Systems Maps Relationships Across AI, SaaS and Cloud AssetsZscaler plans to acquire San Francisco-based Symmetry Systems to unify visibility across AI models, identities, applications and datasets, helping enterprises track AI lineage, govern agentic identities and enforce granular zero trust controls across cloud and SaaS environments.

The Hacker News 1 week, 6 days ago

When Identity is the Attack Path

Consider a cached access key on a single Windows machine. It got there the way most cached credentials do - a user logged in, and the key stored itself automatically. Standard AWS behavior. No one misconfigured anything or violated a policy. Yet that single key, which was easily accessible to a minor-league attacker, could have opened a path to some 98% of entities in the company's cloud

Dark Reading editors reflect on two decades of dramatic change — from perimeter defense to assume-breach strategies — and warn that while AI, cloud, and COVID-19 have transformed the threat landscape, organizations are still failing at fundamental security hygiene that could stop sophisticated attacks in their tracks.

Bank Info Security 2 weeks, 1 day ago

Dell Technologies Bets on AI Infrastructure

Dell Conference Speakers Say 67% of AI Innovation Is Running Outside the CloudDell predicts up to $4 trillion in AI infrastructure investment by 2030, with 67% of AI workloads are already run outside the cloud. If this estimate is even roughly correct, the idea that enterprise AI mainly exists in hyperscaler environments is more of a forced narrative than a market reality.

Microsoft Security Research 2 weeks, 2 days ago

How Storm-2949 turned a compromised identity into a cloud-wide breach

Storm-2949 turned stolen credentials into a cloud-wide breach, moving from identity compromise to large-scale data theft without using malware. This incident shows how threat actors can exploit trusted systems to operate undetected. The post How Storm-2949 turned a compromised identity into a cloud-wide breach appeared first on Microsoft Security Blog.

Loading more headlines...