Cloud & Enterprise
Cloud and enterprise IT covers identity, access, SaaS, hybrid infrastructure and corporate attack surfaces. The analysis helps readers follow risks, incidents and architectural decisions relevant to complex environments.

CareCloud Breach Balloons to 3.7 Million Victims: A Lesson in Regulatory Reporting Gaps
The CareCloud breach has surged from 350,000 to 3.75 million victims in five months, exposing how healthcare regulatory reporting can…

Kaltura Unpatched: RCE and File Read in mwEmbed, No Fix for Five Months
CERT/CC disclosed two critical unpatched vulnerabilities in Kaltura's mwEmbed library enabling remote code execution and arbitrary fil…

Citrix NetScaler: CVE-2026-19490, Critical Authentication Bypass with CVSS 9.3
Citrix has released patches for CVE-2026-19490, a critical authentication bypass in NetScaler ADC/Gateway carrying a CVSS 9.3 score. T…

CVE-2026-18963: Keycloak Account Takeover in Seconds, Bypassing MFA
A critical flaw in Keycloak's password-reset flow lets an unauthenticated attacker seize any account — including admins — in roughly f…

AMD Confirms Two TPM 2.0 Flaws: False Attestations on Ryzen from 3000 Series to AI
Two vulnerabilities in AMD's TPM 2.0 firmware jeopardize the hardware attestation chain on Ryzen processors. Patched firmware has been…

ShinyHunters Hits 100+ Universities with Oracle Zero-Day CVSS 9.8
The ShinyHunters group exploited CVE-2026-35273, an unauthenticated RCE in Oracle PeopleSoft, against more than 100 organizations befo…

CVE-2026-4342: A Five-Day Window, Technical Debt With No Exit
The ingress-nginx vulnerability CVE-2026-4342 (CVSS 8.8) was patched in March 2026 but remains unapplied in thousands of clusters. The…

Stripe: 1,033 Vendor API Keys Exposed, Satanic Claims ~20,000 Total
Threat actor Satanic published data from 669 Stripe vendors containing over 1,000 live API keys. Hudson Rock found no infostealer infe…

HollowGraph: APT Malware Turns M365 Calendars into Covert C2 Channel
HollowGraph exploits the Microsoft Graph API to transform compromised account calendars into bidirectional command-and-control channel…

Microsoft Corrects Course: CVE-2026-69836 Was CVSS 10, But Not Exploited
Microsoft reclassified CVE-2026-69836, a critical Entra ID flaw, retracting its initial claim of active exploitation. The episode rais…

CVE-2024-9042: SYSTEM-Level RCE on Kubernetes Windows Nodes via a Single curl Request
A vulnerability in Kubernetes' Log Query feature enables remote code execution with SYSTEM privileges on every Windows node in a clust…

Cl0p Exploits PTC Windchill Zero-Day to Steal 100+ GB from Shell and Philips
The Cl0p ransomware group claims theft of over 100 GB of industrial data from Shell and Philips by exploiting CVE-2026-12569. The camp…