Cloud & Enterprise
Cloud and enterprise IT covers identity, access, SaaS, hybrid infrastructure and corporate attack surfaces. The analysis helps readers follow risks, incidents and architectural decisions relevant to complex environments.

Akira in Safe Mode: Blind EDR and the Ransomware That Collapsed From Memory Starvation
An Akira affiliate disabled EDR by forcing a reboot into Safe Mode with Networking, but the ransomware payload crashed with "Out of Vi…

TeamPCP/UNC6780: Six Enterprise Breaches From Trivy to LiteLLM
The TeamPCP/UNC6780 campaign compromised Trivy to poison LiteLLM on PyPI. According to Hudson Rock, six enterprise breaches resulted w…

Digital Garbage Hits the Cloud Core: Indiscriminate Scanning
SANS Dean of Research Johannes Ullrich documented widespread, untargeted scanning against the Cloud Metadata Service address 169.254.1…

UNC6671: Personal Phones Become the Gateway to Steal SaaS Data
The UNC6671 group uses vishing on personal smartphones to bypass MFA and steal SaaS sessions. Google has tracked over $10 million in e…

NFV and 5G: The Paradox of European Digital Sovereignty
An intelligence report highlights systemic privilege-escalation vectors in European 5G SA networks. The MANO orchestration plane has b…

Parallels RAS Client: LPE to SYSTEM After 168 Days of Waiting
ZDI-26-556 reveals an exposed dangerous function in the RAS RDP Backend Service. Local escalation to SYSTEM after 168 days of coordina…

CVE-2026-19478: GitLab Patches Critical GraphQL Flaw CVSS 9.4 for Self-Managed Instances
GitLab issued an out-of-cycle patch on August 17, 2026 for CVE-2026-19478, a GraphQL vulnerability rated CVSS 9.4 that allows an unaut…

RingCentral Breach Exposes 1.6 Million Records via Vishing Call
ShinyHunters compromised RingCentral with a single phone call, exposing 1.6 million records and leaking 280 GB of data. The real-time…

Copilot Autofix Introduces Vulnerability in Snowflake CI/CD, Then an AI Agent Finds It
GitHub Copilot Autofix introduced a script injection flaw into a Snowflake GitHub Actions workflow. Five days later, Wiz's autonomous…

ZDI-26-573: Pre-Auth Linux Kernel KSMBD Vulnerability Scores CVSS 9.3
A critical flaw in the in-kernel KSMBD SMB server allows unauthenticated out-of-bounds reads leading to information disclosure and pot…

Rubrik Zero Labs Unveils RPE: From Word Document to Shell on Copilot
Remote Prompt Execution turns prompt injection into full enterprise identity compromise on Microsoft 365 Copilot. The five-stage chain…
Beacon CRM: The Cloud Revealed as a Lock With the Key Left in the Door
Beacon CRM confirmed the total theft of its customer database covering 1,500+ UK charities. The cause: an AWS access key exposed in pu…