Every story tagged Cloud Security, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
137 stories · open in the command center
A now-patched flaw in AWS Bedrock AgentCore shows how a single malicious prompt can turn an AI agent into a foothold for stealing temporary AWS credentials, accessing secrets, and potentially taking over all agents in an account and region. For CIOs, the strategic takeaway is that agentic AI can dramatically expand the blast radius of cloud misconfigurations, making least privilege, network isolation, and tight control over agent permissions essential to keeping AI from becoming a new control-plane risk. IT organizations should treat AI agents like privileged infrastructure components, not simple apps, and validate that vendor defaults do not create cross-agent lateral movement or secrets exposure.
Let’s Encrypt will shorten free TLS certificate lifetimes from 90 days to 64 days starting February 10, 2027, with even shorter periods likely to follow, accelerating the industry shift toward full certificate automation. For CIOs and IT leaders, this raises the operational bar: teams that still rely on manual renewals, fixed cron schedules, or vendor appliances with clunky certificate replacement workflows face a higher risk of outage and compliance exposure if they do not modernize now. The strategic implication is clear—certificate management must be treated as an automated infrastructure capability, with ACME/ARI support, monitoring, and renewal runbooks built into standard IT operations.
A malicious npm release of Tensorlake’s AI agent SDK shows how software supply-chain attacks are now reaching AI infrastructure, putting developer workstations, build systems, and cloud environments at risk before any AI code even runs. For CIOs and technology leaders, the key implication is that AI adoption expands the attack surface through third-party packages and install-time scripts, making dependency trust, secrets management, and rapid detection just as critical as model governance. Although the infected version was removed quickly, the incident reinforces the need to treat AI platform tooling as high-risk production software.
A high-severity Nvidia DCGM Exporter flaw shows how exposed GPU monitoring can become a business risk, not just a technical issue: attackers could use unauthenticated telemetry to map AI infrastructure and, in some cases, crash the monitoring service and disrupt AI training or inference workloads. For CIOs and technology leaders, the strategic takeaway is that AI platform observability must be treated as sensitive production infrastructure, with the same access controls and exposure management applied to core systems, especially as organizations invest heavily in GPUs and distributed AI clusters.
Asos’s breach shows how a compromise of a third-party customer communications platform can quickly become a brand, privacy, and operational crisis, especially when attackers can use the company’s own app to amplify pressure on users. For CIOs and technology leaders, the key implication is that identity protection, vendor risk management, and security controls around externally hosted data and notification channels are now as important as defending core systems, since exposed customer PII can trigger regulatory scrutiny, reputational damage, and costly response efforts.
CrowdStrike’s findings show that attackers are increasingly using agentic AI tools like Claude Code and ARTEX to accelerate financially motivated intrusions, with exposed AI session logs revealing operational details across multiple South Korean banks. For CIOs, the key implication is that AI-assisted adversaries can scale faster, move across targets more quickly, and leave new forms of telemetry and metadata that IT and security teams must be prepared to monitor, secure, and investigate.
LMCache through 0.5.5 contains a server-side request forgery vulnerability in its frontend monitoring service that allows unauthenticated attackers to bypass the proxy allowlist by registering arbitrary hosts. Attackers can add entries via POST /api/proxies and then use /proxy or /proxy2 to reach internal hosts, read responses, and tamper with nodes or stop the heartbeat.
Attackers exploited hijacked country-code top-level domains to alter DNS records and obtain fraudulent HTTPS certificates for Google and other organizations, enabling convincing impersonation without the usual browser warnings. For CIOs, this underscores a broader supply-chain and trust-boundary risk: even if core systems are not breached, compromised domain governance can expose customers to phishing, malware delivery, and traffic interception while damaging brand trust. IT organizations should treat DNS and certificate management as part of critical security operations, not just infrastructure administration, because browser-side protections alone are insufficient and may not cover all users or all affected domains.
State attorneys general suing TP-Link over alleged misleading security marketing and undisclosed China ties highlights growing regulatory and reputational risk around network infrastructure vendors. For CIOs and IT leaders, the case underscores the need to treat router and edge-device sourcing as a strategic risk decision—strengthening supplier due diligence, contract disclosures, and ongoing security validation rather than relying on vendor assurances alone.
PoeLLM shows that AI infrastructure is now a direct enterprise attack surface: attackers are exploiting vulnerable open source AI services and adjacent tools to hijack servers for cryptomining, turn them into scanners, and spread laterally across more than 3,000 systems. For CIOs and technology leaders, this raises the stakes for securing AI platforms with the same rigor as other critical production systems, including patching, exposure reduction, workload segmentation, and monitoring for unusual model- or GPU-related activity.
Information leak in Payments in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
SQL injection vulnerabilities in the web-based management interface of ClearPass Policy Manager could allow a low-privileged authenticated remote attacker to conduct SQL injection attacks against the ClearPass Policy Manager instance. Successful exploitation could allow an attacker to run arbitrary database commands.
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana could lead to cross-tenant data interception. In this context, "tenant" refers to a user or team sharing the same Kibana deployment, not a separate Elastic Cloud organization or customer. Kibana's Fleet package installation process allowed a user holding delegated Fleet package-management privileges, without direct Elasticsearch administrative privileges, to claim a data stream identifier already in use by another tenant. Because ownership of that identifier was not verified before Fleet applied the uploaded package's generated index and ingest-pipeline settings to already-existing infrastructure, an attacker could redirect an existing tenant's data stream through infrastructure under their control. This exposed the affected tenant's subsequently ingested data to unauthorized disclosure and modification, and prevented that data from reaching its intended destination. Interception could continue even after the malic...
Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision.
Operational security is now a business continuity issue, not just a cybersecurity issue: cyber incidents affecting OT/CPS environments are already causing multi-day downtime, million-dollar losses, and safety hazards across manufacturing, healthcare, data centers, and other critical operations. For CIOs, the strategic implication is clear—IT, security, and operations must move from siloed oversight to shared governance, with risk prioritized by operational criticality, third-party access tightly controlled, and AI adoption managed with the same rigor as other connected assets.
ASOS received a rogue in-app notification claiming its Snowflake environment had been compromised and threatening to leak data, but the claim has not been verified. Even without confirmed theft, the incident shows how a single security rumor can quickly trigger brand damage, customer anxiety, and a material market reaction, underscoring the business risk of cloud data platforms and the need for rapid, credible incident handling. For IT organizations, it reinforces the importance of strong identity controls, monitoring, and clear communication paths across security, data, and customer-facing teams.
Asos’ share price fell sharply after customers reportedly received alarming app notifications about a possible Snowflake compromise, underscoring how quickly a cyber incident can become a business, brand, and market-cap event. For CIOs and technology leaders, the takeaway is that cloud data platform exposure, customer-facing alerting, and incident communications all have strategic consequences; IT organizations need tighter third-party risk controls, faster validation/containment workflows, and clearer crisis-response coordination across security, legal, and customer support.
A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configuration (kubeconfig) secrets directly into the privileged control plane namespace without proper validation or sanitization. An authenticated user with cluster and secret creation permissions can exploit this vulnerability by supplying a configuration containing unauthorized executable plugins. When downstream controllers consume this configuration, an attacker can achieve arbitrary code execution within the control plane.
Plane is an open-source project management tool. Prior to 1.4.0, Plane validates GITEA_HOST only for its URL scheme and does not reject hosts that resolve to private or internal IP addresses. The four outbound requests in the Gitea OAuth flow are derived from this unvalidated host and do not call validate_url(). In addition, avatar_url is taken from the Gitea user's profile, where users can configure external avatar URLs. After an administrator enables Gitea OAuth for a legitimate instance, a Gitea user can set an internal URL as the profile avatar and log in through Gitea, causing Plane to fetch the internal target without validation. This issue is fixed in 1.4.0.
Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF in work-item link unfurling shipped in v1.2.2, remains incomplete in the v1.3.1 GA release. Any authenticated project member can make the server fetch attacker-selected internal targets, including cloud metadata at 169.254.169.254, and read the response body returned as the link title or favicon. Complete hardening exists on main in PR 9163 but was not included in an earlier released tag. This issue is fixed in 1.4.0.
A reported KVM guest-to-host escape would be a high-severity infrastructure risk because KVM underpins major public clouds and widely used enterprise virtualization platforms, meaning a single flaw could expose hosts and neighboring workloads across shared environments. For CIOs and IT leaders, the strategic implication is that virtualized and microVM-based isolation assumptions may need urgent review, with patching, live migration, and incident readiness becoming immediate priorities to reduce the chance of broad compromise or service disruption.
H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path traversal in the token parameter to upload a malicious JSP file into a web-accessible directory and then request it to achieve remote code execution as the web-server user. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-14.
Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles, via any request to the application API in a deployment where no identity provider is configured. To remediate this issue, users should upgrade to version 1.6.1 or later.
Server-side request forgery in the OAuth2 discovery handling in Loom for AWS before 1.7.0 might allow an authenticated remote user to obtain the access token of another user of the deployment and to cause the application to issue requests to arbitrary internal network locations, via a crafted discovery document address supplied when registering a tool server or remote agent configured for delegated authentication. To remediate this issue, users should upgrade to version 1.7.0 or later.
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used without validation to attach a file to the form's notification email (arbitrary file read), to write fetched content (arbitrary file write, leading to remote code execution when the external store is configured), and in a scheduled deletion (arbitrary file deletion). This makes it possible for unauthenticated attackers to read, write, or delete arbitrary files on the server. Exploitation requires the site to use the plugin's External File Upload (Amazon S3) action; the read variant additionally requires a form Email action configured to attach the uploaded file.
A high-severity vulnerability in Next.js image optimization affects versions 16.0.0 through 16.3.8, putting internet-facing applications at risk of operational disruption and potential abuse of a core web delivery feature. For CIOs and technology leaders, this is both a security and availability issue: organizations should treat their Next.js estate as part of the critical application stack, prioritize remediation, and verify that dependent customer-facing services can be upgraded without breaking performance or release schedules.
A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered container images, delete cached images, or access mirrored content.
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a validation bypass vulnerability in the community package installation handler for queue mode deployments. Attackers with Redis write access can bypass name validation, permission checks, checksum verification, and npm safety checks to install arbitrary npm packages across all cluster instances without authentication.
Allocation of resources without limits or throttling vulnerability in batch-requests plugin in Apache APISIX. An unauthenticated caller can drive a gateway worker into OOM via a route where the batch-requests plugin is used and the batch endpoint is publicly exposed. This issue affects Apache APISIX: from 1.3.0 through 3.18.0. Users are recommended to upgrade to version 3.19.0, which fixes the issue.
A 16-year-old researcher found a critical authentication flaw in Microsoft’s Titan internal analytics service that let him gain admin access and query metadata tied to a platform spanning an estimated 17.3 trillion rows. For CIOs and technology leaders, the key takeaway is that a single missing control—JWT signature verification—can expose internal data at massive scale, underscoring the need for defense-in-depth, rigorous identity validation, and continuous security testing even for non-customer-facing systems.