< ciso
brief />
Tag Banner

All news with #cloud account compromise tag

70 articles

CISA Alerts: Active Exploitation of MLflow SSRF Bug

๐Ÿ”’ The Cybersecurity and Infrastructure Security Agency (CISA) warns that threat actors are actively exploiting a critical MLflow vulnerability (CVE-2026-64849) that enables a DNS-rebinding SSRF bypass in MLflow's outbound webhook delivery. The flaw, patched in MLflow 3.15.0, allows unauthenticated attackers to make the tracking server issue requests to internal and cloud-metadata endpoints and read responses, risking theft of cloud credentials. CISA added the issue to its KEV catalog and ordered federal agencies to remediate under BOD 26-04, urging all defenders to prioritize patching.
read more โ†’

Threat actor claims Azure employee data from firms

๐Ÿ›ก๏ธ A threat actor using the alias โ€œTheHatmanโ€ is advertising employee databases allegedly exfiltrated from Microsoft Azure tenants of multiple large companies, claiming a total of 3.64 million records. The posted dumps, beginning July 31, target organizations such as McDonaldโ€™s, Tata Consultancy Services, Gap Inc., Vodafone, HCL, IHG, and Kyndryl and include names, emails, titles, phone numbers, addresses, and tenant account details. Several affected firms say investigations show no evidence of current breaches and that much of the data appears dated and non-sensitive, while cyber intelligence firm Hudson Rock assessed the samples as authentic and noted presence of service and admin accounts that could enable targeted attacks.
read more โ†’

Compromised AWS Key Exposes Data of UK Charities

๐Ÿ”’ Beacon attributes a cyber-attack to a compromised AWS access key likely exposed in public Javascript build artifacts, allowing an attacker to download CRM data belonging to about 1,500 UK charities. The incident, identified in activity starting on July 27, saw data decrypted during download despite being encrypted at rest. Beacon has reset credentials, found no evidence of persistence, and instructed customers to report the breach to the ICO. Affected charities have been notified, and there is no confirmation that stolen data has been published or misused.
read more โ†’

UNC6671 vishing extortion targets enterprise identities

๐Ÿ”Ž Google and Mandiant attribute a recent wave of data extortion to UNC6671, which uses vishing to trick employees into spoofed login portals and capture credentials and MFA tokens. The group deploys automated scripts to exfiltrate data from cloud and SaaS environments, including Microsoft 365 and Okta, and operates multiple extortion brands. UNC6671 targets employeesโ€™ personal devices, spoofs help desk numbers, and registers adversary-controlled MFA devices to maintain persistence.
read more โ†’

Malware can abuse Windows Hello to gain cloud access

๐Ÿ”’ Entra ID researcher Dirk-jan Mollema demonstrated that malware running in a signed-in Windows session can silently invoke the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The technique lets an attacker obtain tokens, register devices, and gain long-term cloud access without extracting private keys, recovering PINs, or prompting biometrics on TPM-backed systems. Mollema published PoC scripts and recommends hunting for Hello sign-ins with empty device IDs while noting potential false positives.
read more โ†’

UNC6671 Targets Financial and Cloud Environments

๐Ÿ”Ž GTIG reports UNC6671 continues active compromises and data-theft extortion despite the alleged BlackFile retirement, diversifying into Redact, Pink, Helix, and Falcon. The actor uses targeted voice phishing (vishing) to lure employeesโ€”often on personal phonesโ€”to spoofed login portals with AiTM infrastructure to harvest credentials and MFA tokens, then deploys scripts to exfiltrate data from enterprise cloud apps like Microsoft 365 and Okta. The update details infrastructure linkages, evolving targeting focused on financial services and private equity, and offers hardening guidance to mitigate these identity-centric threats.
read more โ†’

AI Token Jacking: Rising Threat to Cloud AI Spend

๐Ÿ”’ Unit 42 details the surge in AI token jacking, where attackers steal API keys (tokens) to consume expensive AI model resources and sell access via proxy "transfer stations." The report explains token mechanics, attack vectors including stolen keys and malicious npm packages, and demonstrates how rapid abuse can cause catastrophic billing. It outlines mitigations such as spending limits, short-term tokens, AI gateways, and secure developer practices.
read more โ†’

Health-ISAC warns of rising ShinyHunters data theft

๐Ÿ”’ Health-ISAC warns healthcare and medtech organizations of an uptick in successful attacks by the extortion group ShinyHunters, which leverages supply-chain and identity attacks to breach cloud SaaS and storage platforms. Attacks commonly begin with vishing and social engineering to compromise SSO accounts (Okta, Microsoft Entra, Google), granting access to services like Salesforce, Microsoft 365, SharePoint, and others. The advisory urges hardening helpdesk and SSO procedures, adopting phishing-resistant MFA, treating SSO as Tier 0, and centralizing audit logs to detect large-scale cloud data theft.
read more โ†’

AI-Driven Breaches Force Rethink of Incident Response

๐Ÿ›ก๏ธ Enterprises face a new class of attacks as threat actors leverage AI agents to automate entire intrusion chains, dramatically compressing the time from initial access to deep compromise. Reports from Sygnia and Sysdig document AI-enabled campaigns that harvest credentials, map services, and persist across cloud environments, often exploiting known vulnerabilities rather than zero-days. Experts warn that traditional, human-speed incident response and hunting are often too slow, and emphasize the need for integrated, AI-assisted defenses and rigorous hygiene: fast patching, secrets rotation, least privilege, segmentation, and automated response playbooks.
read more โ†’

Novel OAuth Client ID Spoofing Targets Cloud

๐Ÿ”’ Cyber-attackers are increasingly using OAuth client ID spoofing to access cloud environments by abusing Microsoft Entra ID (formerly Azure AD). Proofpoint researchers found threat actors issuing ROPC token requests to the OAuth 2.0 endpoint, producing AADSTS error codes that reveal valid usernames and authentication controls. The technique produces blank or spoofed application IDs in Entra signโ€‘in logs, making detection difficult and enabling large-scale campaigns targeting millions of accounts.
read more โ†’

AI-Accelerated Cloud Attack Exploits Management Gaps

๐Ÿ”Ž A Sygnia report details how a lone threat actor leveraged AI to complete in 72 hours what would normally take weeks, using established cloud attack techniques rather than novel exploits. The attacker obtained an AWS access key via an internet-facing app and used agentic AI workflows to search for secrets, establish persistence, exfiltrate RDS data, and perform impact actions. The report highlights gaps in secrets management, identity governance, deployment workflows and visibility, and provides containment recommendations for defenders.
read more โ†’

Massive Microsoft 365 password spray attack exposed

๐Ÿ”’ Microsoft users experienced a large-scale automated password spray campaign that targeted accounts indiscriminately, including clients of security firm Huntress. Huntress reported 81 million login attempts against its customers between June 12 and 26, with at least 78 successful compromises. Attack traffic originated from an IPv6 range tied to LSHIY LLC, which has since cut service to the offending customer. The attackers abused the OAuth ROPC flow to replay valid credentials, bypassing protections where MFA was not enforced for all cloud apps or all user groups.
read more โ†’

High-severity Amazon Q MCP flaw enables cloud theft

๐Ÿ›ก๏ธ A high-severity flaw in Amazon Q Developer allowed a malicious repository to spawn MCP servers and execute commands, exposing a developer's cloud credentials. Wiz Research discovered the issue and demonstrated that a single config file (.amazonq/mcp.json) in a cloned repo could trigger AWS credential theft. Amazon patched the vulnerability, tracked as CVE-2026-12957 (CVSS 8.5), and updated Language Servers for AWS and IDE plugins to require explicit consent for untrusted MCP servers.
read more โ†’

Cloud bucket hijacking risks across major providers

๐Ÿ”’ Unit 42 researchers describe a bucket hijacking technique that exploits globally unique storage bucket names across major cloud providers. By deleting a target bucket and recreating it under an attacker-controlled account with the same name, data streams (logs, Pub/Sub, replication, transfer jobs, etc.) can be silently rerouted to an adversary. The team validated the attack across Google Cloud, AWS and demonstrated cross-subscription scenarios in Azure, and has shared findings with the affected vendors.
read more โ†’

Infinite Campus Salesforce Breach Exposes Staff Data

๐Ÿ”’ Infinite Campus disclosed a Salesforce data theft in March that exposed personal information for school staff across its Kโ€‘12 customer base. The attacker, linked to groups known for targeting Salesforce instances, allegedly leaked a 1.2GB archive. Have I Been Pwned found data from 137,100 accounts, including names, emails, job titles and contact details. Infinite Campus said most exposed items appear to be directory information commonly published by schools.
read more โ†’

Attackers Exfiltrate Exchange Executive Mailbox

๐Ÿ“ง Symantec and Carbon Black disclosed that unknown attackers maintained quiet access to a senior executive's Outlook mailbox at a major global stock exchange for at least five months, repeatedly copying messages and routing them through Dropbox and OneDrive to blend with normal cloud activity. The intruders used a mailbox stealer built on Aspose, ran binaries impersonating legitimate updaters and OneDrive, and staged additional backdoors before access likely ended in March 2026. Indicators point to espionage-focused credential theft and tunneling tooling rather than a financially motivated campaign.
read more โ†’

When Identity Becomes the Primary Attack Path in the Cloud

๐Ÿ” This article examines how identities โ€” user, machine, and AI agent credentials โ€” have become primary attack paths across hybrid environments. It uses real-world examples like cached access keys and forgotten role assignments to show how isolated identity weaknesses chain into exploitable routes. The piece explains why traditional IGA and PAM tools miss these cross-boundary paths and calls for unified mapping of identity, permissions, and environment context to prevent breaches.
read more โ†’

Preventing Unauthorized AWS Organizations Account Removal

๐Ÿ”’ The AWS Customer Incident Response Team describes a tactic where attackers use credentials with the organizations:LeaveOrganization permission to remove a member account from an AWS Organization, bypassing inherited safeguards such as Service Control Policies and centralized management. After removal, the account is disentangled from consolidated billing, organization-wide CloudTrail trails, and delegated GuardDuty findings, reducing visibility. The post urges deploying the DenyLeaveOrganizationSCP, enforcing least privilege, securing root users with MFA and centralized root management, and updating detection and response workflows to monitor related CloudTrail events.
read more โ†’

Storm-2949 Abuses SSPR and MFA to Exfiltrate Azure Data

๐Ÿ” Microsoft reports that a threat actor tracked as Storm-2949 is abusing Self-Service Password Reset (SSPR) and social engineering to steal Microsoft Entra ID credentials and bypass MFA for privileged users. The attackers trick targets into approving authentication prompts, reset passwords, remove MFA, and enroll Microsoft Authenticator on attacker devices. Using Microsoft Graph and custom scripts they enumerate tenants, exfiltrate files from OneDrive and SharePoint, and pivot into Azure to harvest secrets from Key Vaults, storage accounts, and SQL databases. Microsoft recommends least privilege, conditional access, phishing-resistant MFA for admins, limiting RBAC, and extended Key Vault logging to mitigate these attacks.
read more โ†’

Storm-2949: Identity Compromise Leads to Cloud Breach

๐Ÿ” Microsoft Threat Intelligence details how Storm-2949 converted targeted identity compromise into a broad cloud breach, exfiltrating data from Microsoft 365 and production workloads in Azure. The actor abused SSPR-based social engineering to bypass MFA, performed directory discovery via Graph API, and leveraged management-plane operations to retrieve Key Vault secrets and download large volumes of data. Organizations should adopt behavior-based detections such as Microsoft Defender and tighten RBAC and administrative controls to detect and mitigate similar identity-driven cloud attacks.
read more โ†’