Microsoft Confirms Entra ID Zero-Day Was Exploited Before the Fix Went Live
Microsoft has disclosed CVE-2026-69836, a maximum-severity deserialization flaw in Entra ID that attackers exploited in the wild before the company silently patched it server-side. There is no customer...
Critical MLflow Flaw Lets Attackers Steal Cloud Credentials via Webhook Redirects
A critical server-side request forgery flaw in MLflow, tracked as CVE-2026-64849 with a 9.3 CVSS score, lets unauthenticated attackers abuse the platform's webhook-testing endpoint to reach cloud metadata...
AWS Sets a Multi-Year Countdown to Kill Off Email-Based Certificate Validation
Amazon is phasing out email validation for public TLS certificates issued through AWS Certificate Manager, with new-Region restrictions starting in 2027 and a full industry-wide browser distrust deadline...
Zapscape Flaw Lets a Rogue Cloud Virtual Machine Seize Root on Its Host Server
A Linux kernel vulnerability nicknamed Zapscape and tracked as CVE-2026-64561 allows a malicious KVM guest running nested virtualization to escape its virtual machine entirely and take root control...
AWS AiTM Phishing Kit Bypasses MFA to Hijack Cloud Console Sessions in Real Time
A real-time adversary-in-the-middle phishing kit has been targeting AWS engineers, stealing credentials and MFA codes simultaneously to hijack cloud sessions before they expire. Standard MFA provides zero protection...
HazyBeacon APT Campaign Weaponizes AWS Lambda to Hide Command-and-Control Traffic
Qualys researchers have exposed HazyBeacon, a stealthy APT campaign targeting Southeast Asian governments that uses AWS Lambda Function URLs as covert command-and-control relays. By routing malicious traffic through...
Meet Pink: The New Extortion Group Using Vishing and Microsoft 365 Tools to Drain Enterprise Cloud Storage
A new extortion group called Pink (CL-CRI-1147) has emerged, targeting enterprise organizations through voice phishing to steal Microsoft 365 credentials and cloud files. With ties to the Com...
Attackers Exploit Docker and Kubernetes Misconfigurations to Escape Containers and Seize Host Control
Security researchers have documented a wave of attacks exploiting Docker and Kubernetes misconfigurations to break out of containers and take full control of host systems, including supply chain...