Cloud security
Misconfigurations, identity, and vulnerabilities across AWS, Azure, GCP, Kubernetes, and the containerized stack.
Unitree G1 robot flaws give root over Bluetooth, and one hacked robot can reach the next
Two Unitree G1 humanoid robot flaws (CVE-2026-76639, CVE-2026-76640) give an attacker root over Bluetooth or the network, and one hacked robot can reach the
Five WordPress plugin and theme flaws let attackers take the site or the whole server
Wordfence and Patchstack disclosed five unauthenticated WordPress flaws rated 9.8 to 10.0. GiveWP and Avada run code on the host. Patch all five now.
Three ServiceNow AI Platform flaws (CVSS 10.0) let an unauthenticated attacker run code. Patch now.
ServiceNow patched three CVSS 10.0 AI Platform flaws an unauthenticated attacker can chain for code execution, SQL injection, and privilege escalation.
Two critical Next.js flaws let attackers run code on self-hosted servers
Next.js patched two critical flaws that let unauthenticated attackers run code on self-hosted servers. Vercel apps are covered. Update to 15.5.24 or 16.3.3 now.
Linux kernel IPv6 flaw (CVE-2026-53362) lets a container break out to host root, now exploited
CVE-2026-53362 is an actively exploited Linux kernel IPv6 flaw that lets a low-privilege user escape a container to host root.
Four SSRF flaws in one week turned self-hosted apps into a foothold in your own network
Four unrelated products shipped SSRF flaws this week, from a Kubernetes proxy to MLflow. Why self-hosted SSRF reaches cloud metadata, and how to contain it.
Thousands of leaked AWS keys still work, and 768 give attackers full account control
Truffle Security found 64,024 exposed AWS keys and 88% still authenticate; 768 give full account control. Why rotation fails and what to detect and fix.
Two exploited TrueConf Server flaws chain to unauthenticated code execution, now on CISA's must-patch list
CISA added two actively exploited TrueConf Server flaws (CVE-2026-72529, CVE-2026-72530) to its KEV catalog.
Unpatched Red Hat Multicluster Engine flaw lets a stranger reach internal services on managed clusters
CVE-2026-66794 (CVSS 9.3): an unauthenticated attacker can reach internal services on any Red Hat managed cluster through the cluster-proxy route. No patch yet.
Red Hat Advanced Cluster Management flaw lets a user run a rogue container as admin on managed clusters
CVE-2026-66793 (CVSS 8.8): a low-privilege user in Red Hat Advanced Cluster Management can swap in a rogue container and gain full admin on managed Kubernetes
A Linux kernel SCTP flaw (CVE-2026-64564) escalates to root and breaks out of default-seccomp containers
SCTPhantom (CVE-2026-64564) is a use-after-free in Linux SCTP that reaches host root and escaped default-seccomp containers in 6 of 8 tests.
The Snowflake hacker pleaded guilty. The breach used no exploit, just old passwords and MFA left off.
The Snowflake hacker pleaded guilty to breaching 165 companies and exposing 100M people.
bank-vaults Kubernetes webhook flaw lets a low-privilege user steal HashiCorp Vault secrets (CVE-2026-54725)
CVE-2026-54725 is a critical SSRF in bank-vaults vault-secrets-webhook (CVSS 9.6). A user who can create a ConfigMap can steal ServiceAccount tokens. Fix: 1.23.
Azure Cosmos DB flaw gave one platform key full read/write access to any customer database
Wiz's CosmosEscape exposed a platform-wide Azure Cosmos DB key that could read and write any customer's database.
New VMware flaws let a network attacker run code on vCenter with no login, and escape a VM onto the host
VMware's VMSA-2026-0006 patches two 9.8 vCenter flaws that add up to unauthenticated code execution, plus a 9.3 ESXi VM escape. Patch vCenter first.
cPanel security update fixes three flaws rated up to High, including one in the bundled Exim mail server
cPanel and WHM's new security release fixes CVE-2026-58047, CVE-2026-58048 and an Exim flaw, rated up to High. Patched versions for every branch, what to do.
A 'read-only' role in Red Hat OpenShift Virtualization lets one tenant copy another tenant's data
CVE-2026-17527 lets a low-privileged OpenShift Virtualization tenant copy other tenants' data across namespaces through a read-only role. No fix yet; audit now.
Oracle's July update fixes unauthenticated 10.0 code-execution flaws in WebLogic, HTTP Server, and Coherence
Oracle's July 2026 update ships 1,449 fixes, including unauthenticated CVSS 10.0 remote code execution in WebLogic, Oracle HTTP Server, and Coherence.
One missing setting lets a stranger join an OpenShift cluster's private tunnel and read its traffic
CVE-2026-16242 (CVSS 9.4): a missing certificate check in OpenShift hosted control planes lets a remote attacker intercept control-plane-to-node traffic.
NadMesh turns exposed AI servers into cloud-key harvesters
NadMesh, a new Go botnet, scans exposed self-hosted AI tools like Ollama and ComfyUI to steal cloud keys and Kubernetes tokens.
A single Envoy Gateway policy can hand a user the keys to your Kubernetes cluster
CVE-2026-53713 (CVSS 9.1): a path check in Envoy Gateway misses double slashes, letting a submitted Lua policy read the controller's Kubernetes token and TLS
A booby-trapped Linux app can escape its sandbox through the audio server and run on your system
CVE-2026-5674 lets a sandboxed Linux app abuse PipeWire's PulseAudio layer to load a malicious library and run code outside the sandbox.
GhostLock turns any Linux foothold into host root, and containers don't stop it
GhostLock (CVE-2026-43499) is a 15-year-old Linux kernel flaw that turns any local foothold into host root and escapes containers. Who is exposed, how to patch.
A Google chatbot 'edit' permission was really a code-execution grant
Google's Dialogflow CX let one edit permission run code across every chatbot in a project.
Gitea's Docker image trusts a login header from anyone, and probing has started
A default in Gitea's Docker image trusts the X-WEBAUTH-USER header from any IP, so anyone can log in as any user.
SUSE Rancher patched critical flaws that turn a small foothold into full control of your Kubernetes clusters
SUSE Rancher and Fleet patched critical flaws that let a leaked token or one tenant account seize whole Kubernetes clusters.
Argo CD can be taken over from inside your cluster, and there is no patch to wait for
Argo CD's repo-server runs code for unauthenticated callers and can take over your Kubernetes cluster. No patch or CVE exists yet, so isolate and watch it now.
Adobe's six max-severity ColdFusion flaws have no exploit yet, and that is the countdown
Adobe patched six unauthenticated CVSS 10.0 code-execution flaws in ColdFusion (bulletin APSB26-68).
MFA did not stop the Azure CLI password spray. A retired login flow is why.
A password spray beat Conditional Access at 64 organizations by abusing ROPC, a retired Azure login flow that never triggers an MFA prompt. What to fix now.
Open the wrong repo and Amazon Q ran its config file as you, AWS keys included
Amazon Q Developer ran a repo's MCP config file as you, with AWS keys attached. CVE-2026-12957 is patched in 1.69.0. What to verify and hunt for now.
One setting in Red Hat OpenShift Virtualization can expose your VMs to any pod on the cluster
CVE-2026-13325: enabling disableTLS for faster live migration in Red Hat OpenShift Virtualization drops authentication, letting any pod reach another tenant’s
Two flaws in Unraid's control panel let a logged-in user seize the whole server
Two command injection flaws in Unraid's web panel, CVE-2026-9772 and CVE-2026-9773, let any logged-in user run code as www-data.
A rigged container image can seize root on the host running Docker's AI agent tools
CVE-2026-55887 lets a malicious container image escape Docker's MCP Gateway and run code as root on the host. Rated 8.7.
Crawl4AI shipped its server unlocked by default. It took three patches to close the door.
Crawl4AI's Docker API shipped unauthenticated by default, exposing 51,000+ deployments to remote code execution and cloud-metadata SSRF. Upgrade to 0.9.0 now.
Ready to meet the Guardians?
Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.