Cloud
Curated coverage and analysis in this editorial area.

Zapscape: Hyunwoo Kim's Third KVM Escape Raises Systemic Security Questions
CVE-2026-64561 is a use-after-free in the KVM/x86 shadow MMU discovered by Hyunwoo Kim. It allows a kernel-privileged L1 guest to brea…

TokenLover and YaksaLover: The PhaaS Kits That Measure Persistence With a 'Password Change Survival Rate'
Italy's ACN details two Phishing-as-a-Service toolkits that abuse the Device Code Flow and NGC keys to achieve persistence that surviv…

Broadcom Patches Five VMware Vulnerabilities: Three Critical Flaws Up to CVSS 9.8
Broadcom released patches on July 29, 2026 for five vulnerabilities in VMware vCenter, ESXi, Workstation, and Fusion. Three are critic…

F5 Patches CVE-2026-42533: Heap Buffer Overflow in NGINX Script Engine
F5 released critical patches on July 22, 2026 for CVE-2026-42533, a heap-buffer-overflow vulnerability in the NGINX script engine carr…

CVE-2026-56163: Microsoft Mitigates Critical AKS Flaw Without Customer Action
Microsoft assigned CVE-2026-56163 a maximum CVSS 10.0 score for a critical elevation-of-privilege vulnerability in Azure Kubernetes Se…

Infostealers Overtake Phishing and Exploits as Top Enterprise Cloud Access Vector
Infostealer malware logs have surpassed phishing and vulnerability exploits as the primary initial access vector for enterprise cloud…

Microsoft Dismantles StealC C2 Network, But Stolen Logs Keep Fueling Breaches
On June 24, 2026, Microsoft and Europol took down over 200 StealC and Amadey C2 domains. Yet years-old credential logs still circulate…

EncForge: JadePuffer Hits Irrecoverable AI Models With Agentic Ransomware
The agentic threat actor JadePuffer has deployed EncForge, ransomware purpose-built for AI/ML assets. Encrypted models cannot be recov…

NVIDIAScape: Container Escape in Three Lines of Code in the NVIDIA Toolkit
CVE-2025-23266, rated CVSS 9.0, affects 37% of AI cloud environments. An old-school bug in the NVIDIA Container Toolkit enables privil…

Accenture Confirms 'Isolated Matter' After Threat Actor '888' Lists 35GB of Data for Sale
Threat actor '888' claims to be selling roughly 35GB of Accenture data, including source code, Azure tokens, and SSH keys. Accenture a…

IngressNightmare: The Design Flaw That Breaches the Kubernetes Perimeter
CVE-2025-1974 in the Ingress NGINX Controller enables unauthenticated RCE and full cluster takeover. Over 6,500 clusters are publicly…

Agentic AI: A Lone Attacker Compromises Enterprise AWS in 72 Hours
Sygnia documents the first operational case of a lone threat actor using AI-assisted workflows to compress an enterprise AWS attack fr…