23 Mar Microsoft to shut down 50 cloud services for Russian businesses Microsoft plans to limit access to over fifty cloud products for Russian organizations by the end of March as part of the sanctions requirements against the country issued by EU regulators last December. […]
21 Feb Hackers abuse Google Cloud Run in massive banking trojan campaign Security researchers are warning of hackers abusing the Google Cloud Run service to distribute massive volumes of banking trojans like Astaroth, Mekotio, and Ousaban. […]
12 Feb Ongoing Microsoft Azure account hijacking campaign targets executives A phishing campaign detected in late November 2023 has compromised hundreds of user accounts in dozens of Microsoft Azure environments, including those of senior executives. […]
04 Feb Leaky Vessels flaws allow hackers to escape Docker, runc containers Four vulnerabilities collectively called “Leaky Vessels” allow hackers to escape containers and access data on the underlying host operating system. […]
13 Jan Hacker spins up 1 million virtual servers to illegally mine crypto A 29-year-old man in Ukraine was arrested this week for using hacked accounts to create 1 million virtual servers used to mine $2 million in cryptocurrency. […]
28 Nov Hackers start exploiting critical ownCloud flaw, patch now Hackers are exploiting a critical ownCloud vulnerability tracked as CVE-2023-49103 that exposes admin passwords, mail server credentials, and license keys in containerized deployments. […]
24 Nov Critical bug in ownCloud file sharing app exposes admin passwords Open source file sharing software ownCloud is warning of three critical-severity security vulnerabilities, including one that can expose administrator passwords and mail server credentials. […]
06 Nov QNAP warns of critical command injection flaws in QTS OS, apps QNAP Systems published security advisories for two critical command injection vulnerabilities that impact multiple versions of the QTS operating system and applications on its network-attached storage (NAS) devices. […]
05 Oct Amazon to make MFA mandatory for ‘root’ AWS accounts by mid-2024 Amazon will require all privileged AWS (Amazon Web Services) accounts to use multi-factor authentication (MFA) for stronger protection against account hijacks leading to data breaches, starting in mid-2024. […]
04 Sep Hackers exploit MinIO storage system to breach corporate networks Hackers are exploiting two recent MinIO vulnerabilities to breach object storage systems and access private information, execute arbitrary code, and potentially take over servers. […]