ProBackend
Cloud Security Incidents

Cloud Security Incidents

Articles about cloud security breaches, credential theft, and incident response

cloud security incidentsJun 23, 20265 min

Critical Exploited Zero-Day Found in Oracle PeopleSoft Applications

Oracle has issued emergency mitigations for CVE-2026-35273, a critical zero-day in PeopleSoft PeopleTools currently being exploited by the ShinyHunters extortion group to facilitate large-scale data theft.

cloud security incidentsJun 23, 20263 min

Active Exploitation of Path Traversal in Langflow AI

Exploitation of CVE-2026-5027, a critical path traversal vulnerability in Langflow, is underway, allowing unauthorized file uploads on exposed servers.

cloud security incidentsJun 23, 20263 min

Rogue Firmware Reflashing on Creative Soundbars Permits Host Takeovers via Bluetooth

A vulnerability in Creative's Sound Blaster Katana V2X gaming soundbar allows unauthenticated local attackers to reflash the device's firmware via always-on Bluetooth, enabling keystroke injection on connected hosts.

cloud security incidentsJun 23, 20263 min

Path-Divergence Vulnerability in Starlette Exposes Python-Based AI Agents to Data Breaches

An in-depth look at CVE-2026-48710 (BadHost), a critical path-divergence vulnerability in the Starlette ASGI framework that allows authentication bypasses and security control evasion across the Python AI ecosystem.

cloud security incidentsJun 23, 20265 min

When the Body Silences Its Signals: How Self-Model Collapse May Shape Near-Death Experiences

A neuroscientific hypothesis proposes that near-death experiences arise when the brain’s continuous integration of bodily signals breaks down under extreme physiological stress, causing a simplified self-model to emerge in the absence of normal interoceptive input.

cloud security incidentsJun 23, 20263 min

The Rise of Search Your Target

A deep look into the underground market where attackers pay others to filter billions of stolen credentials for specific targets—transforming noisy infostealer dumps into precise attack payloads.

cloud security incidentsJun 23, 20265 min

BadHost Vulnerability CVE-2026-48710 Exposes Millions of AI Agents to Authentication Bypass

A critical Starlette vulnerability (CVE-2026-48710, nicknamed BadHost) allows attackers to bypass authentication via malformed Host headers, impacting FastAPI-based AI systems including vLLM, LiteLLM, and MCP gateways. The flaw affects Starlette versions prior to 1.0.1.

cloud security incidentsJun 22, 20265 min

How a Developer Token Compromise Sparked a Global Pharma Data-Extortion Crisis

Novo Nordisk recent massive data breach: Investigating the impact of a developer token compromise on pharma data security, research, and manufacturing.

cloud security incidentsJun 22, 20263 min

CISA Orders Agencies to Patch Critical Check Point VPN Flaw

CISA has mandated that U.S. government agencies patch a critical vulnerability in Check Point security gateways following reports of its exploitation in zero-day attacks by the Qilin ransomware gang.

cloud security incidentsJun 22, 20265 min

Apple’s Siri AI Partnership with Google: Balancing Performance and Privacy

Apple's long-delayed Siri upgrade, "Siri AI," integrates Google's Gemini models while emphasizing Apple's commitment to user privacy through its Private Cloud Compute architecture.

cloud security incidentsJun 22, 20263 min

Red Hat npm Packages Compromised in Supply-Chain Attack Distributing Miasma Malware

More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack distributing the Shai-Hulud credential-stealing malware, dubbed "Miasma."

cloud security incidentsJun 18, 20264 min

Chinese Espionage Group UNC5221 Deploys Brickstorm Backdoor to Maintain Persistent Access to Microsoft 365 Environments

Analysis of UNC5221's Brickstorm backdoor campaign targeting Microsoft 365 environments, including technical details, attribution to Chinese APT groups (APT31, APT41), and defensive recommendations for enterprise security teams. Also covers related incidents including the Fortinet credential harvesting campaign affecting 30K devices.