Secure Bulletin Navigating the cyber sea with knowledge
Home > Tag > Cloud Security
#Cloud Security

Microsoft Fixes CVSS 10 Azure AI Foundry Privilege-Escalation Flaw

19 September 2026  |  dark6  |  Vulnerability

Microsoft has remediated a maximum-severity authentication flaw in Azure AI Foundry that could allow an unauthenticated network attacker to gain elevated privileges. The cloud-side fix is complete, but...

>> read more

Mass Scanning of Exposed Vite Servers Targets AWS and Azure Secrets

15 September 2026  |  dark6  |  Vulnerability

Attackers are automatically probing internet-accessible Vite development servers for environment files, cloud credentials and infrastructure secrets. F5 telemetry recorded about 32,000 raw events in August, highlighting the risk...

>> read more

Cloud and SaaS Resilience Starts With Identity, Dependency Mapping and Tested Recovery

13 September 2026  |  dark6  |  Privacy

Cloud and SaaS adoption has replaced a clear network perimeter with overlapping identity and supplier dependencies. Organizations can limit cascading failures by mapping concentration risk, prioritizing exposed systems,...

>> read more

ChatGPT Sandbox Isolation Flaw Created a Hidden Route for Cross-Account Data Theft

9 September 2026  |  dark6  |  Privacy

Researchers found that a shared internal package service could act as a covert communication channel between isolated ChatGPT containers. The proof of concept combined hidden instructions and connected-app...

>> read more

AI-Assisted Intruder Reaches Enterprise Root Access in Less Than 10 Hours

8 September 2026  |  dark6  |  AI

An attacker reportedly used frontier models and agentic frameworks to compress a complex enterprise intrusion into less than ten hours. The incident shows how exposed services, embedded secrets...

>> read more

Leaked AWS Administrator Key Fuels Costly LLMjacking Through Bedrock and Marketplace

4 September 2026  |  dark6  |  Cybercrime

A leaked AWS IAM key with administrator privileges allowed an attacker to create a new identity, activate premium AI models and bill inference usage to the victim. The...

>> read more

BGP Hijack Poisoned Virtualizor Updates and Put Hosting Servers at Root-Level Risk

1 September 2026  |  dark6  |  Vulnerability

A routing hijack diverted Softaculous infrastructure and enabled a malicious Virtualizor update to reach a small number of hosting servers. Because update packages lacked cryptographic verification, valid TLS...

>> read more

Microsoft Confirms Entra ID Zero-Day Was Exploited Before the Fix Went Live

21 August 2026  |  dark6  |  Vulnerability

Microsoft has disclosed CVE-2026-69836, a maximum-severity deserialization flaw in Entra ID that attackers exploited in the wild before the company silently patched it server-side. There is no customer...

>> read more