Cloud
Curated coverage and analysis in this editorial area.

BRICKSTORM: CISA and NSA Alert on Evolving Rust Backdoor Targeting vSphere
Cybersecurity agencies have updated their Malware Analysis Report for BRICKSTORM, a sophisticated ELF backdoor targeting VMware vSpher…

Multi-Ecosystem Sleeper Packages Target CI Pipelines for Credential Theft and Persistence
At least two distinct campaigns have deployed malicious sleeper packages across RubyGems, npm, and Go modules to harvest developer cre…

Vimeo Data Breach: 119,200 Emails Exposed via Anodot Integration
In May 2026, the ShinyHunters threat group published a 106 GB Vimeo archive stolen via the anomaly detection platform Anodot. The leak…

Vishing and AiTM Bypass MFA: Invisible Extortion in SaaS
Criminal groups like Cordial Spider use vishing and AiTM to bypass MFA and target SaaS environments. Protect your corporate data from…

CVE-2026-41940: cPanel Bypass Risk and Mitigations
Analysis of CVE-2026-41940, a critical cPanel vulnerability with CVSS 9.8. Exploited for months, here is its impact on millions of ser…

Linux Copy Fail Risk: The Invisible 4-Byte Root Exploit
The Linux Copy Fail vulnerability allows root escalation in 4 bytes, corrupting only RAM. Discover the impact on Kubernetes and how to…

SAP npm Supply Chain Attack: Malware Targets CAP Packages
The Mini Shai-Hulud campaign compromises SAP npm packages, stealing credentials and establishing persistence via AI agents. Learn how…

NPM Supply Chain Attack: Malware Found in Claude Code and VS Code Extensions
A new SAP npm package supply chain attack targets AI coding agent configurations. Discover how mini Shai-Hulud steals credentials and…

Vercel Breach: The Risks of Shadow AI OAuth Exposed
The Vercel breach highlights the danger of Shadow AI integrations: how a forgotten OAuth token opened corporate doors. Here is what yo…

Critical cPanel Vulnerability: Urgent Patch and Hosting Access Blocks
A critical cPanel authentication vulnerability forced providers to block access. Learn about the security risks and the importance of…

Entra ID Vulnerability: Patch for Agent ID Privilege Escalation
Microsoft fixed a vulnerability in Entra ID's Agent ID Administrator role. The bug allowed high-privilege service principal takeover.…