Home/ Blog/ Topics/ Cloud security
Topic

Cloud security

Misconfigurations, identity, and vulnerabilities across AWS, Azure, GCP, Kubernetes, and the containerized stack.

Security news

Unitree G1 robot flaws give root over Bluetooth, and one hacked robot can reach the next

Two Unitree G1 humanoid robot flaws (CVE-2026-76639, CVE-2026-76640) give an attacker root over Bluetooth or the network, and one hacked robot can reach the

Security news

Five WordPress plugin and theme flaws let attackers take the site or the whole server

Wordfence and Patchstack disclosed five unauthenticated WordPress flaws rated 9.8 to 10.0. GiveWP and Avada run code on the host. Patch all five now.

Security news

Three ServiceNow AI Platform flaws (CVSS 10.0) let an unauthenticated attacker run code. Patch now.

ServiceNow patched three CVSS 10.0 AI Platform flaws an unauthenticated attacker can chain for code execution, SQL injection, and privilege escalation.

Security news

Two critical Next.js flaws let attackers run code on self-hosted servers

Next.js patched two critical flaws that let unauthenticated attackers run code on self-hosted servers. Vercel apps are covered. Update to 15.5.24 or 16.3.3 now.

Security news

Linux kernel IPv6 flaw (CVE-2026-53362) lets a container break out to host root, now exploited

CVE-2026-53362 is an actively exploited Linux kernel IPv6 flaw that lets a low-privilege user escape a container to host root.

Deep dive

Four SSRF flaws in one week turned self-hosted apps into a foothold in your own network

Four unrelated products shipped SSRF flaws this week, from a Kubernetes proxy to MLflow. Why self-hosted SSRF reaches cloud metadata, and how to contain it.

Security news

Thousands of leaked AWS keys still work, and 768 give attackers full account control

Truffle Security found 64,024 exposed AWS keys and 88% still authenticate; 768 give full account control. Why rotation fails and what to detect and fix.

Security news

Two exploited TrueConf Server flaws chain to unauthenticated code execution, now on CISA's must-patch list

CISA added two actively exploited TrueConf Server flaws (CVE-2026-72529, CVE-2026-72530) to its KEV catalog.

Security news

Unpatched Red Hat Multicluster Engine flaw lets a stranger reach internal services on managed clusters

CVE-2026-66794 (CVSS 9.3): an unauthenticated attacker can reach internal services on any Red Hat managed cluster through the cluster-proxy route. No patch yet.

Security news

Red Hat Advanced Cluster Management flaw lets a user run a rogue container as admin on managed clusters

CVE-2026-66793 (CVSS 8.8): a low-privilege user in Red Hat Advanced Cluster Management can swap in a rogue container and gain full admin on managed Kubernetes

Security news

A Linux kernel SCTP flaw (CVE-2026-64564) escalates to root and breaks out of default-seccomp containers

SCTPhantom (CVE-2026-64564) is a use-after-free in Linux SCTP that reaches host root and escaped default-seccomp containers in 6 of 8 tests.

Security news

The Snowflake hacker pleaded guilty. The breach used no exploit, just old passwords and MFA left off.

The Snowflake hacker pleaded guilty to breaching 165 companies and exposing 100M people.

Security news

bank-vaults Kubernetes webhook flaw lets a low-privilege user steal HashiCorp Vault secrets (CVE-2026-54725)

CVE-2026-54725 is a critical SSRF in bank-vaults vault-secrets-webhook (CVSS 9.6). A user who can create a ConfigMap can steal ServiceAccount tokens. Fix: 1.23.

Security news

Azure Cosmos DB flaw gave one platform key full read/write access to any customer database

Wiz's CosmosEscape exposed a platform-wide Azure Cosmos DB key that could read and write any customer's database.

Security news

New VMware flaws let a network attacker run code on vCenter with no login, and escape a VM onto the host

VMware's VMSA-2026-0006 patches two 9.8 vCenter flaws that add up to unauthenticated code execution, plus a 9.3 ESXi VM escape. Patch vCenter first.

Security news

cPanel security update fixes three flaws rated up to High, including one in the bundled Exim mail server

cPanel and WHM's new security release fixes CVE-2026-58047, CVE-2026-58048 and an Exim flaw, rated up to High. Patched versions for every branch, what to do.

Security news

A 'read-only' role in Red Hat OpenShift Virtualization lets one tenant copy another tenant's data

CVE-2026-17527 lets a low-privileged OpenShift Virtualization tenant copy other tenants' data across namespaces through a read-only role. No fix yet; audit now.

Security news

Oracle's July update fixes unauthenticated 10.0 code-execution flaws in WebLogic, HTTP Server, and Coherence

Oracle's July 2026 update ships 1,449 fixes, including unauthenticated CVSS 10.0 remote code execution in WebLogic, Oracle HTTP Server, and Coherence.

Security news

One missing setting lets a stranger join an OpenShift cluster's private tunnel and read its traffic

CVE-2026-16242 (CVSS 9.4): a missing certificate check in OpenShift hosted control planes lets a remote attacker intercept control-plane-to-node traffic.

Security news

NadMesh turns exposed AI servers into cloud-key harvesters

NadMesh, a new Go botnet, scans exposed self-hosted AI tools like Ollama and ComfyUI to steal cloud keys and Kubernetes tokens.

Security news

A single Envoy Gateway policy can hand a user the keys to your Kubernetes cluster

CVE-2026-53713 (CVSS 9.1): a path check in Envoy Gateway misses double slashes, letting a submitted Lua policy read the controller's Kubernetes token and TLS

Security news

A booby-trapped Linux app can escape its sandbox through the audio server and run on your system

CVE-2026-5674 lets a sandboxed Linux app abuse PipeWire's PulseAudio layer to load a malicious library and run code outside the sandbox.

Security news

GhostLock turns any Linux foothold into host root, and containers don't stop it

GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel flaw that turns any local foothold into host root and escapes containers. Who is exposed, how to patch.

Security news

A Google chatbot 'edit' permission was really a code-execution grant

Google's Dialogflow CX let one edit permission run code across every chatbot in a project.

Security news

Gitea's Docker image trusts a login header from anyone, and probing has started

A default in Gitea's Docker image trusts the X-WEBAUTH-USER header from any IP, so anyone can log in as any user.

Security news

SUSE Rancher patched critical flaws that turn a small foothold into full control of your Kubernetes clusters

SUSE Rancher and Fleet patched critical flaws that let a leaked token or one tenant account seize whole Kubernetes clusters.

Security news

Argo CD can be taken over from inside your cluster, and there is no patch to wait for

Argo CD's repo-server runs code for unauthenticated callers and can take over your Kubernetes cluster. No patch or CVE exists yet, so isolate and watch it now.

Security news

Adobe's six max-severity ColdFusion flaws have no exploit yet, and that is the countdown

Adobe patched six unauthenticated CVSS 10.0 code-execution flaws in ColdFusion (bulletin APSB26-68).

Security news

MFA did not stop the Azure CLI password spray. A retired login flow is why.

A password spray beat Conditional Access at 64 organizations by abusing ROPC, a retired Azure login flow that never triggers an MFA prompt. What to fix now.

Security news

Open the wrong repo and Amazon Q ran its config file as you, AWS keys included

Amazon Q Developer ran a repo's MCP config file as you, with AWS keys attached. CVE-2026-12957 is patched in 1.69.0. What to verify and hunt for now.

Security news

One setting in Red Hat OpenShift Virtualization can expose your VMs to any pod on the cluster

CVE-2026-13325: enabling disableTLS for faster live migration in Red Hat OpenShift Virtualization drops authentication, letting any pod reach another tenant’s

Security news

Two flaws in Unraid's control panel let a logged-in user seize the whole server

Two command injection flaws in Unraid's web panel, CVE-2026-9772 and CVE-2026-9773, let any logged-in user run code as www-data.

Security news

A rigged container image can seize root on the host running Docker's AI agent tools

CVE-2026-55887 lets a malicious container image escape Docker's MCP Gateway and run code as root on the host. Rated 8.7.

Security news

Crawl4AI shipped its server unlocked by default. It took three patches to close the door.

Crawl4AI's Docker API shipped unauthenticated by default, exposing 51,000+ deployments to remote code execution and cloud-metadata SSRF. Upgrade to 0.9.0 now.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.