Cloud Security
Threat actors have been observed abusing Kubernetes RBAC to create backdoors and hijack cluster resources for cryptocurrency mining.
Hi, what are you looking for?
A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.
Threat actors have been observed abusing Kubernetes RBAC to create backdoors and hijack cluster resources for cryptocurrency mining.
The Series A funding round was led by Storm Ventures and brings the total raised by Dasera to $20 million.
When every environment is treated the same, teams get consistent visibility, a unified view, and a common language to describe what’s happening for detection,...
Microsoft Azure shared key authorization can be exploited to access business data and achieve remote code execution.
California startup Trustle banks a $6 million seed round to join the competitive cloud access management technology space.
Cisco is set to acquire Israel-based cloud security company Lightspin for a reported $200-250 million.
A high-severity vulnerability in Azure Service Fabric Explorer could have allowed a remote, unauthenticated attacker to execute arbitrary code.
An Azure Active Directory (AAD) misconfiguration leading to Bing.com compromise earned Wiz researchers a $40,000 bug bounty reward.
The U.S. government’s cybersecurity agency ships a new tool to help network defenders hunt for signs of compromise in Microsoft’s Azure and M365 cloud...
CISA this week announced it is seeking public input on draft guidance for securing cloud business applications.
Join SecuityWeek and LogRhythm as we dive into security risks associated with SaaS, as well as best practices for mitigating these risks and protecting...
Cisco announced plans to acquire Valtix, an early-stage Silicon Valley startup in the cloud network security business.
Cloud security company Wiz has raised $300 million in a Series D funding round that brings the total raised by the company to $900...
Microsoft and Proofpoint are warning organizations that use cloud services about a recent consent phishing attack that abused Microsoft’s ‘verified publisher’ status.
VMware vRealize Log Insight vulnerability allows an unauthenticated attacker to take full control of a target system.
A CSRF vulnerability in the source control management (SCM) service Kudu could be exploited to achieve remote code execution in multiple Azure services.
Many developers and security people admit to having experienced a breach effected through compromised API credentials.
Orca Security published details on four server-side request forgery (SSRF) vulnerabilities impacting different Azure services.
Electric car maker Tesla is using the annual Pwn2Own hacker contest to incentivize security researchers to showcase complex exploit chains that can lead to...
Hack The Box Raises $55 Million in Funding Round Led by Carlyle