Cloud Security
AWS and cybersecurity vendors have made several announcements at the cloud giant’s re:Invent 2025 event.
Hi, what are you looking for?
A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.
AWS and cybersecurity vendors have made several announcements at the cloud giant’s re:Invent 2025 event.
Five flaws in the open source tool may lead to path traversal attacks, remote code execution, denial-of-service, and tag manipulation.
Intel and AMD have published advisories after academics disclosed details of the new TEE.fail attack method.
A vulnerability in RMP initialization allows the AMD processor’s x86 cores to maliciously control parts of the initial RMP state.
Authenticated attackers can exploit the security flaw to trigger a use-after-free and potentially execute arbitrary code.
Wiz has teamed up with Microsoft, Google and AWS and is inviting cloud security researchers to its Zeroday.Cloud competition.
Intel and AMD say the research is not in scope of their threat model because the attack requires physical access to a device.
New framework from the Cloud Security Alliance helps SaaS customers navigate the shared responsibility model with confidence.
The strength of responsible disclosure is that it can solve problems before they are actioned. The weakness is that it potentially generates a false...
L1TF Reloaded is a vulnerability combining the old L1TF and half-Spectre hardware flaws to bypass deployed software mitigations.
Exploiting incomplete speculative execution attack mitigations extended to the branch predictor state, VMScape leaks arbitrary memory.
The Midnight Blizzard cyberspies used compromised websites to trick users into authorizing devices they controlled.
Storm-0501 has been leveraging cloud-native capabilities for data exfiltration and deletion, without deploying file-encrypting malware.
A critical vulnerability in Docker Desktop allows attackers to modify the filesystem of Windows hosts to become administrators.
Silk Typhoon was seen exploiting n-day and zero-day vulnerabilities for initial access to victim systems.
AWS has addressed a vulnerability that could have been leveraged to bypass Trusted Advisor’s S3 bucket permissions check.
Wiz researchers discovered NVIDIAScape, an Nvidia Container Toolkit flaw that can be exploited for full control of the host machine.
Virtual event brings together leading experts, practitioners, and innovators for a full day of insightful discussions and tactical guidance on evolving threats and real-world...
Founded in 2015, the Tel Aviv based company has now raised more than $1 billion and claims more than 3,500 customers.
Cloud security startup Circumvent has raised $6 million to develop a network of agents for autonomous prioritization and remediation.