Cloud-security is a topic tracked in our intelligence system with 5 linked articles.
Azure Cosmos DB reportedly exposed a platform-wide key that could grant access to any database, signaling a severe cloud security flaw with broad potential customer and regulatory implications.
Hugging Face details a four-day intrusion by an OpenAI-powered autonomous AI agent, revealing scalable credential theft and systemic weaknesses (17,600 actions, 11 compromised servers) with broad implications for AI security and vendor risk.
Google paid $250k for reporting a Linux KVM guest-VM escape (CVE-2026-53359) with a proof-of-concept, while a second vulnerability GhostLock earned $92k; both have patches in the Linux kernel and pose cloud-virtualization isolation risks.
Unrestricted Firebase browser key allowed access to Gemini APIs, causing a €54k spike in activity over 13 hours.
Security researcher exposes an unauthenticated /prod/recommend endpoint in Filevine that could leak a full Box admin token and expose ~100k confidential files; responsible disclosure led to remediation, highlighting regulatory/privacy risks for a high-value legal-tech AI vendor valued over $1B.
Pay Tel left a Microsoft Azure storage bucket publicly accessible, exposing over 300,000 driver’s licenses and inmate communications; researchers alerted the company in May, Pay Tel has not publicly acknowledged the incident, raising regulatory and reputational risk.
Subscribe for real-time topic updates and unlimited access to our intelligence platform.