Threats Tagged 'cloud'
View all threats tagged with 'cloud'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cloud'
Click on any threat for detailed analysis and mitigation recommendations
This analysis discusses a new type of denial-of-service attack against AI agents called "denial of wallet," where attackers exploit the pay-as-you-go token consumption model of large language models (LLMs) to cause excessive financial costs. Autonomous AI agents that operate continuously and retry failed steps can consume tokens unpredictably and in large bursts, making costs difficult to control. Attackers can exploit this by sending numerous complex or looping requests that inflate token usage, leading to significant budget overruns. This issue has been recognized as a top risk in the OWASP guide for language models (LLM06:2026). Join the discussion | Kaspersky Security Blog | 09/23/2026, 14:40:55 UTC Added: 09/23/2026, 14:46:02 UTC |
0 CVE-2026-94450 is a denial of service vulnerability in s2n-quic, a Rust implementation of the QUIC protocol. The flaw involves improper validation of the Destination Connection ID length when a server is configured to send Retry packets. This allows an unauthenticated attacker to shut down a server endpoint with a single crafted UDP datagram. The issue affects s2n-quic versions 1.88.0 and earlier. AWS services are not impacted, and only server endpoints configured to issue Retry packets are vulnerable. The vulnerability is fixed in s2n-quic version 1.89.0. No workaround exists, so upgrading is necessary. Join the discussion | AWS Security Bulletins | 09/22/2026, 20:08:17 UTC Added: 09/22/2026, 20:15:59 UTC |
0 CVE-2026-94384 is a missing authorization vulnerability in the sfExecuteAWSService Lambda function of the Amazon Connect Salesforce Lambda application. This function, used only during initial setup, improperly dispatches caller-supplied parameters to privileged AWS service APIs without validating authorization. Consequently, any IAM principal with lambda:InvokeFunction permission on this function can perform AWS operations beyond their own IAM permissions. Versions from 5.15 through 5.24.16 are affected. The issue is remediated by upgrading to version 5.26 or later, deleting or disabling the vulnerable function after setup, or restricting invocation permissions tightly. Join the discussion | AWS Security Bulletins | 09/22/2026, 17:10:17 UTC Added: 09/22/2026, 17:14:55 UTC |
This content is an analysis discussing cybersecurity challenges and strategies for small and medium-sized businesses (SMBs). It highlights how SMBs face increasing cyber risks as they grow and adopt more digital technologies, often without proportional increases in IT resources. The analysis emphasizes that cybersecurity should be integrated as a business enabler rather than a mere compliance task. It outlines common internal constraints SMBs face, such as limited incident responders and heavy IT workloads, and advocates for a gradual, proactive approach to evolving cybersecurity posture aligned with business growth. The piece also describes two strategic paths for SMBs: hardening protection levels and expanding coverage with modular security solutions. Join the discussion | Kaspersky Security Blog | 09/21/2026, 15:23:26 UTC Added: 09/21/2026, 15:29:36 UTC |
0 This article analyzes how AWS mitigates risks from exposed IAM access keys by automatically attaching the AWSCompromisedKeyQuarantine managed policy to affected IAM users. The policy restricts permissions to limit damage from compromised credentials. The article details the evolution of this managed policy, the integration with GitHub's secret scanning program that detects exposed credentials in public repositories, and the notification and remediation process AWS follows. It also highlights monitoring strategies for security teams to detect quarantine events and respond rapidly. Join the discussion | Palo Alto Unit 42 | 09/21/2026, 10:00:13 UTC Added: 09/21/2026, 10:09:58 UTC |
Microsoft released patches for 18 vulnerabilities affecting Azure cloud and AI-branded products, primarily involving privilege escalation flaws. The vulnerabilities span multiple Azure services and Microsoft 365 Copilot products, with some information disclosure and spoofing issues also addressed. Microsoft rated all vulnerabilities as critical, though CVSS scores vary from medium to high severity. No exploitation in the wild has been reported, and all fixes were implemented server-side, requiring no customer action. Additionally, a Windows privilege escalation vulnerability was patched, with updates required by users. Microsoft continues to see increased vulnerability discovery driven by AI advancements. Join the discussion | SecurityWeek | 09/18/2026, 10:57:03 UTC Added: 09/18/2026, 11:01:39 UTC |
Unit 42 researchers identified that AWS AgentCore Harness's default configuration enables a built-in shell tool with root privileges, which can be exploited via prompt injection to exfiltrate plaintext credentials from the AgentCore Identity vault. The shell tool is enabled by default and can execute arbitrary shell commands with root access, posing a risk if allowedTools is not scoped properly. AWS reviewed the finding and classified it as informative under the shared responsibility model, emphasizing customer-side controls such as scoping allowedTools and egress filtering. Mitigation involves restricting allowedTools to only necessary tools, applying least privilege to identity vault service accounts, and monitoring outbound traffic from harness containers. No official patch or fix is indicated; remediation relies on configuration and operational controls. Join the discussion | Palo Alto Unit 42 | 09/18/2026, 10:00:36 UTC Added: 09/18/2026, 10:10:37 UTC |
0 Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AWS IoT Core endpoint, read device telemetry, and inject arbitrary MQTT messages that the device processes as authentic, via a certificate issued for an unrelated hostname by a certificate authority present in the device trust store. To remediate this issue, users should upgrade to version 1.6.1. Join the discussion | CVE Database V5 | 09/17/2026, 19:14:56 UTC Added: 09/17/2026, 19:32:32 UTC |
0 CVE-2026-86831 is a high-severity vulnerability in the aws-network-policy-agent component of Amazon EKS. It involves improper validation of pod identifier uniqueness, which may allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namespaces by crafting pod and namespace names that cause pod identifier collisions. This issue affects versions prior to 1.4.0 of the Network Policy Agent and versions prior to 1.22.4 of the Amazon VPC CNI Managed Add-on. A fix is available in Network Policy Agent 1.4.0 and Amazon VPC CNI Managed Add-on 1.22.4 or later. Join the discussion | CVE Database V5 | 09/16/2026, 19:49:49 UTC Added: 09/16/2026, 20:17:10 UTC |
The Australian Signals Directorate (ASD) is transitioning from the Essential Eight cybersecurity framework to a new outcomes-based Essentials series starting mid-2027, with full retirement of the Essential Eight expected around mid-2028. This shift moves organizations away from periodic, checklist-style compliance assessments toward continuous validation of security posture across enterprise IT, cloud, operational technology (OT), and potentially agentic AI environments. The new framework emphasizes demonstrating ongoing achievement of security outcomes rather than merely implementing specific controls. Compliance with the Essential Eight remains mandatory only for certain Commonwealth entities, while private-sector adoption is voluntary but often expected by insurers and government contractors. The Essentials series introduces chapters tailored to different environments, reflecting their unique security challenges and dynamic nature. Exposure management tools are highlighted as a means to continuously identify and prioritize security exposures and provide real-time evidence of security posture. Join the discussion | Tenable Research | 09/15/2026, 13:32:00 UTC Added: 09/15/2026, 13:42:37 UTC |
Showing 1 to 10 of 237 results