A $159 Circuit Can Make Encrypted Cloud Data Go Stale

Researchers say the DDRop hardware attack can silently drop memory writes on protected cloud servers, reusing older encrypted data without triggering the encryption checks.

Researchers say the DDRop hardware attack can silently drop memory writes on protected cloud servers, reusing older encrypted data without triggering the encryption checks.

Microsoft has reported two significant phishing campaigns targeting cloud accounts, utilizing advanced social engineering techniques and passkey-themed tactics.

AWS's approach to managing leaked credentials has come under scrutiny after reports revealed that numerous root keys remain active despite being exposed. Experts argue that the current quarantine policy may not adequately protect users.

Recent reports indicate that attackers are actively exploiting a critical SSRF vulnerability in MLflow, an open-source AI platform, to extract sensitive cloud credentials.

A researcher reported a significant vulnerability in Google Cloud's Kubernetes operator, which could allow unauthorized access to cloud resources. Despite initial acknowledgment, Google later denied a bug bounty and has yet to issue a fix.

A recent report highlights that compromised service accounts and forgotten API keys were responsible for 68% of cloud breaches in 2024. A webinar aims to address the risks associated with unmanaged non-human identities.

A new variant of the Chaos malware has emerged, specifically targeting misconfigured cloud deployments, according to cybersecurity researchers. This marks a significant evolution in the malware's targeting capabilities.

A recent webinar highlighted the challenges of cloud forensics and the necessity of modern techniques to investigate breaches effectively.

VoidLink, a newly identified Linux malware, has been largely generated by artificial intelligence, posing a significant threat to cloud infrastructures.

VoidLink, a newly discovered Linux malware, poses significant risks to cloud environments by enabling credential theft and stealthy operations.