Cloud & SaaS Security

31
Mar
Public S3 Bucket Leaks 2 Billion Records—Defenders Must Secure Cloud Storage

Public S3 Bucket Leaks 2 Billion Records—Defenders Must Secure Cloud Storage

An Amazon Web Services S3 bucket was mistakenly configured to allow public write access, turning it into an open data
1 min read
31
Mar
Google Cloud Rolls Out AI Security Add‑On to Guard Generative Models

Google Cloud Rolls Out AI Security Add‑On to Guard Generative Models

Google Cloud announced a new AI Security add‑on that sits in front of generative AI services hosted on its
1 min read
31
Mar
GPT‑4 Prompt Abuse Injects Hidden Backdoors into CI/CD Pipelines

GPT‑4 Prompt Abuse Injects Hidden Backdoors into CI/CD Pipelines

Security researchers have uncovered a new supply‑chain attack vector where threat actors feed carefully crafted prompts to GPT‑4.
1 min read
30
Mar

Critical Log4j 2.x Flaw Spurs Immediate Patch Push Across Cloud and Enterprise

A cascade of critical vulnerabilities in Apache Log4j 2.x has been publicly disclosed, prompting major cloud providers and enterprise
1 min read
27
Mar

Google Cloud Flags Public Vertex AI Misconfigurations Exposing Training Data

Google Cloud’s latest security advisory reveals that multiple high‑profile customers unintentionally left Vertex AI endpoints and storage buckets
26
Mar

3‑Million‑Plus Cybersecurity Talent Gap Threatens Defense Readiness

The (ISC)² Workforce Report 2026 shows the global shortage of qualified cybersecurity professionals has now exceeded three million—a record
26
Mar

Google Cloud IAM Slip Lets AI Service Read Customer Buckets

Google Cloud disclosed that an overly permissive Identity and Access Management (IAM) policy on its AI Platform inadvertently granted the
26
Mar

Supply‑Chain Breach Hits Popular Logistics SaaS, Spreads Backdoor to Customers

FireEye’s recent investigation uncovered a sophisticated supply‑chain attack targeting a widely adopted SaaS logistics platform. Threat actors infiltrated
25
Mar
Cloudflare’s New Account Abuse Protection Adds Email Risk Tiers for Faster Blocking

Cloudflare’s New Account Abuse Protection Adds Email Risk Tiers for Faster Blocking

Cloudflare has rolled out an Account Abuse Protection module that scores every inbound email address against three criteria: domain reputation,
1 min read
25
Mar
TeamPCP hijacks Trivy CI/CD to inject malicious LiteLLM builds

TeamPCP hijacks Trivy CI/CD to inject malicious LiteLLM builds

Security researchers discovered that the threat actor known as TeamPCP breached the Trivy CI/CD workflow that builds and publishes
1 min read