Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > Cloud Security
#Cloud Security

Zapscape Flaw Lets a Rogue Cloud Virtual Machine Seize Root on Its Host Server

9 August 2026  |  dark6  |  Vulnerability

A Linux kernel vulnerability nicknamed Zapscape and tracked as CVE-2026-64561 allows a malicious KVM guest running nested virtualization to escape its virtual machine entirely and take root control...

>> read more

AWS AiTM Phishing Kit Bypasses MFA to Hijack Cloud Console Sessions in Real Time

29 June 2026  |  dark6  |  Phishing

A real-time adversary-in-the-middle phishing kit has been targeting AWS engineers, stealing credentials and MFA codes simultaneously to hijack cloud sessions before they expire. Standard MFA provides zero protection...

>> read more

HazyBeacon APT Campaign Weaponizes AWS Lambda to Hide Command-and-Control Traffic

22 June 2026  |  dark6  |  Cybercrime

Qualys researchers have exposed HazyBeacon, a stealthy APT campaign targeting Southeast Asian governments that uses AWS Lambda Function URLs as covert command-and-control relays. By routing malicious traffic through...

>> read more

Meet Pink: The New Extortion Group Using Vishing and Microsoft 365 Tools to Drain Enterprise Cloud Storage

10 June 2026  |  dark6  |  Cybercrime

A new extortion group called Pink (CL-CRI-1147) has emerged, targeting enterprise organizations through voice phishing to steal Microsoft 365 credentials and cloud files. With ties to the Com...

>> read more

Attackers Exploit Docker and Kubernetes Misconfigurations to Escape Containers and Seize Host Control

2 June 2026  |  dark6  |  Vulnerability

Security researchers have documented a wave of attacks exploiting Docker and Kubernetes misconfigurations to break out of containers and take full control of host systems, including supply chain...

>> read more

Vercel Confirms April 2026 Breach: ShinyHunters Accessed Source Code, API Keys, and Employee Data via AI Tool Compromise

20 April 2026  |  dark6  |  Databreach

Cloud development platform Vercel confirmed a security breach traced to a compromised employee account at third-party AI platform Context.ai. The ShinyHunters group claims to have stolen source code,...

>> read more

ShinyHunters Breaches Rockstar Games via Third-Party Vendor, Threatens to Leak GTA VI Contracts

15 April 2026  |  dark6  |  Databreach

ShinyHunters has breached Rockstar Games by exploiting authentication tokens from third-party analytics vendor Anodot to access Snowflake data warehouses. The stolen data reportedly includes financial records and confidential...

>> read more

European Commission Suffers 91.7 GB Cloud Data Breach via Trivy Supply-Chain Compromise

14 April 2026  |  dark6  |  Databreach

CERT-EU has documented a cloud breach at the European Commission stemming from a supply-chain compromise in the Trivy container scanner. Approximately 91.7 GB of sensitive EU institutional data...

>> read more