threat-intel [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI This virtual event focuses on the growing challenges of securing cloud assets in an era increasingly influenced by AI. Experts will explore strategies and tools for managing security across multi-cloud environments, addressing the gaps many enterprises face in protecting their cloud infrastructure. Dark Reading · 2026-11-12 Info cloudsecurityai
vulnerability Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth A security researcher discovered two separate root remote code execution (RCE) vulnerabilities in Unitree's G1 and G1 EDU humanoid robots. One vulnerability, accessible via Bluetooth, allows attackers to gain root access… The Hacker News · 2d ago High CVE-2026-76639CVE-2026-76640roboticsrcebluetooth
vulnerability MLflow Vulnerability Exploited for Cloud Credential Theft A vulnerability in MLflow, a popular AI engineering platform, has been exploited by threat actors to steal cloud credentials and secrets. The flaw, tracked as CVE-2026-64849, allows unauthenticated SSRF attacks, leading… SecurityWeek · Aug 20, 2026 Critical CVE-2026-64849ssrfcloudmlflow
threat-intel Simple Scans for Cloud Metadata Service, (Wed, Aug 19th) A widespread scan targeting the Cloud Instance Metadata Service (IMDS) at 169.254.169.254 is being observed, potentially indicating a broader effort to exploit SSRF vulnerabilities. This service, traditionally used by vi… SANS Internet Storm Center · Aug 19, 2026 Medium ssrfmetadatacloud
vulnerability Multiples vulnérabilités dans Microsoft Azure (12 août 2026) Multiple vulnerabilities have been discovered within Microsoft Azure, potentially allowing an attacker to elevate privileges, compromise data confidentiality, and bypass security policies. These vulnerabilities affect va… CERT-FR · Aug 12, 2026 High CVE-2026-47299CVE-2026-57104CVE-2026-65806azurevulnerabilitysecurity
vulnerability Metabase Patches Vulnerability Exploited as Zero-Day Metabase has released critical patches to address a zero-day SQL injection vulnerability that was actively exploited in the wild. Attackers gained unauthorized access to Metabase Cloud instances, potentially stealing dat… SecurityWeek · Aug 10, 2026 Critical sql injectionzero-daypatch
threat-intel Oligo Raises $60 Million for Runtime Security Oligo Security, a runtime security company, secured $60 million in a new funding round, bringing their total investment to $140 million. The company’s platform focuses on providing deep runtime visibility and real-time p… SecurityWeek · Aug 4, 2026 Medium ISruntime securityvulnerabilityai
threat-intel How legitimate cloud platforms enable phishers to bypass MFA Threat actors are increasingly leveraging legitimate cloud platforms – like Cloudflare, Vercel, Netlify, and GitHub Pages – to conduct sophisticated phishing attacks. These attacks utilize multi-stage adversary-in-the-mi… Securelist · Aug 4, 2026 High phishingaitmbitb
vulnerability Critical Flaw Led to Azure Cosmos DB Pwnage A critical vulnerability, dubbed CosmosEscape, in Azure Cosmos DB allowed attackers to obtain a platform-wide key, enabling them to compromise all databases on the service. Wiz researchers exploited this flaw by bypassin… SecurityWeek · Jul 31, 2026 Critical vulnerabilitycode executiondatabase
vulnerability Default Azure Automation Setting Enables Cross-Tenant Identity Takeover A critical vulnerability in Microsoft's Azure Automation service, stemming from a default public configuration for automation account identities, could have allowed attackers to take over another tenant's identity and ac… Dark Reading · Jul 24, 2026 Critical CVE-2025-29827identitycloudautomation
threat-intel Palo Alto Networks to Acquire Observability Platform Provider Embrace Palo Alto Networks is acquiring Embrace, a user-focused observability platform, to bolster its Observability platform with Real User Monitoring (RUM) and proactively validate application performance globally. This acquis… SecurityWeek · Jul 22, 2026 Info observabilityrumdigital experience
vulnerability Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities Microsoft released its July 2026 security update, containing 622 vulnerabilities, with 57 classified as critical. Several of these, including those affecting Active Directory Federation Services, SharePoint Server, and v… Cisco Talos · Jul 14, 2026 High CVE-2026-56155CVE-2026-56164CVE-2026-50370vulnerabilityrceeop
threat-intel Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads xAI's Grok Build coding CLI has been uploading entire Git repositories, including commit history and sensitive data like API keys and passwords, to a Google Cloud Storage bucket. The issue was discovered by cereblab, who… The Hacker News · Jul 14, 2026 High data-breachgitcredentials
vulnerability Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns Progress Software has instructed ShareFile customers to immediately shut down their Storage Zone Controller servers due to a credible security threat. The company suspects that vulnerabilities, previously addressed in Ma… SecurityWeek · Jul 13, 2026 Critical CVE-2026-2699CVE-2026-2701vulnerabilityremote code executioncve
threat-intel URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Progress Software has instructed ShareFile customers to immediately shut down their Storage Zone Controllers due to a "credible external security threat." The company has disabled access to affected accounts and is inves… The Hacker News · Jul 10, 2026 High CVE-2023-24489vulnerabilitysecuritycloud
threat-intel AI Gateways Offer Attackers the Keys to the Kingdom A cryptomining incident highlighted how AI gateways, increasingly used to manage access to AI models and cloud infrastructure, are becoming attractive targets for attackers. The attacker gained initial access via brute-f… Dark Reading · Jul 9, 2026 High aigatewaycloud
threat-intel Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours A lone attacker successfully breached a large Amazon Web Services (AWS) environment in 72 hours using AI to accelerate reconnaissance, tool development, and command structure, ultimately extorting a global enterprise. Th… Dark Reading · Jul 8, 2026 High aicloudransomware
vulnerability Google Dialogflow CX Bug Allowed Attackers to Hijack AI Conversations A vulnerability in Google Cloud’s Dialogflow CX service allowed attackers to silently control agents, manipulate conversations, and exfiltrate sensitive information. The flaw stemmed from a permissive configuration withi… SecurityWeek · Jul 8, 2026 High aicloudpython
threat-intel 'Djinn' Stealer Targets Cloud, AI Credentials The ‘Djinn’ stealer, delivered via a SimpleHelp vulnerability (CVE-2026-48558), is targeting cloud and AI credentials, specifically focusing on developer and administrator environments. Blackpoint Cyber’s APG tracked an… Dark Reading · Jun 29, 2026 High CVE-2026-48558DKaicredentialsstealer
threat-intel Phishing Attack Volume Down 20%, but Risk Still Rising The volume of phishing attacks has decreased by 20% across multiple industries, despite a shift towards more sophisticated attacks utilizing AI. Threat actors are prioritizing targeted campaigns with higher conversion ra… Dark Reading · Jun 12, 2026 High CAESAUphishingaicloud