Security News

VMware: Plug critical Aria Automation hole immediately! (CVE-2023-34063)
2024-01-18 10:04

A critical vulnerability affecting VMware Aria Automation and VMware Cloud Foundation can be exploited by attackers to gain access to remote organizations and workflows, VMware has warned.Patches are available and VMware recommends upgrading to VMware Aria Automation 8.16.

Jira down: Atlassian outage affecting multiple cloud services
2024-01-18 09:47

Multiple Atlassian Jira products are experiencing an ongoing outage as of this morning. BleepingComputer can confirm that Jira services are experiencing connection issues since this morning, at least as of 3:45 AM Eastern time.

Enter the era of platform-based cloud security
2024-01-18 09:35

"These types of solutions offer an integrated platform approach to cloud security that allows security teams to save time and gain visibility, leading to operational efficiencies, tool consolidation, and streamlined compliance," it concludes. The report highlights how Trend Vision One delivers an integrated platform that meets the needs of both cloud and security teams, with functionality including cloud-native application protection platform capabilities, that provide comprehensive, automated and connected protection across cloud environments.

Combination of cheap .cloud domains and fake Shark Tank news fuel unhealthy wellness scams
2024-01-17 06:29

Scammers are buying up cheap domain names to host sites that sell dodgy health products using fake articles, according to cybercrime disruption outfit Netcraft. Some of the stories suggest that judges on entrepreneurial reality shows Shark Tank and Dragons' Den have backed the products.

29-Year-Old Ukrainian Cryptojacking Kingpin Arrested for Exploiting Cloud Services
2024-01-13 10:01

A 29-year-old Ukrainian national has been arrested in connection with running a “sophisticated cryptojacking scheme,” netting them over $2 million (€1.8 million) in illicit profits. The person was...

Cloud security predictions for 2024
2024-01-12 05:30

As we reflect on the cybersecurity landscape and the trajectories of threat vectors, it's evident that we're on the cusp of a paradigm shift in cloud security. It's a reminder that even with advancements in cloud security, fundamental principles like IAM can't be overlooked.

New Python-based FBot Hacking Toolkit Aims at Cloud and SaaS Platforms
2024-01-11 14:00

A new Python-based hacking tool called FBot has been uncovered targeting web servers, cloud services, content management systems (CMS), and SaaS platforms such as Amazon Web Services (AWS),...

Android game dev’s Google Drive misconfig highlights cloud security risks
2023-12-31 15:09

Japanese game developer Ateam has proven that a simple Google Drive configuration mistake can result in the potential but unlikely exposure of sensitive information for nearly one million people over a period of six years and eight months. Setting Google Drive to "Anyone with the link can view" makes it viewable only to those with the exact URL, typically reserved for collaboration between people working with non-sensitive data.

Hospitals ask courts to force cloud storage firm to return stolen data
2023-12-29 20:20

Two not-for-profit hospitals in New York are seeking a court order to retrieve data stolen in an August ransomware attack and now stored on the servers of a Boston cloud storage company. The LockBit ransomware gang claimed responsibility for breaching and stealing sensitive files from their systems in late August, with a press release published by the hospitals one week later saying the incident forced them to redirect patients requiring urging care to other hospitals' emergency departments.

Google Cloud Resolves Privilege Escalation Flaw Impacting Kubernetes Service
2023-12-28 13:20

Google Cloud has addressed a medium-severity security flaw in its platform that could be abused by an attacker who already has access to a Kubernetes cluster to escalate their privileges. "An...