Cloud-security is a topic tracked in our intelligence system with 5 linked articles.
Google paid $250k for reporting a Linux KVM guest-VM escape (CVE-2026-53359) with a proof-of-concept, while a second vulnerability GhostLock earned $92k; both have patches in the Linux kernel and pose cloud-virtualization isolation risks.
Unrestricted Firebase browser key allowed access to Gemini APIs, causing a €54k spike in activity over 13 hours.
Security researcher exposes an unauthenticated /prod/recommend endpoint in Filevine that could leak a full Box admin token and expose ~100k confidential files; responsible disclosure led to remediation, highlighting regulatory/privacy risks for a high-value legal-tech AI vendor valued over $1B.
Pay Tel left a Microsoft Azure storage bucket publicly accessible, exposing over 300,000 driver’s licenses and inmate communications; researchers alerted the company in May, Pay Tel has not publicly acknowledged the incident, raising regulatory and reputational risk.
Investigation finds about 5,000 vibe-coded web apps with minimal security, exposing sensitive corporate and personal data, across tools like Lovable, Replit, Base44, and Netlify.
Researchers demonstrate Rowhammer GPU attacks on Nvidia Ampere GPUs (RTX 3060/6000) that can achieve full host compromise by corrupting GPU page tables, with mitigations including IOMMU or ECC.
Subscribe for real-time topic updates and unlimited access to our intelligence platform.