Skip to content
feed: live
>_ 0dayNews
Vendor

Cloud

Attacks against cloud identity and productivity platforms — Microsoft 365, Google Workspace, Azure, AWS — including OAuth consent phishing, device-code abuse, token theft, and the "identity-first" intrusion patterns that treat the tenant, not the endpoint, as the ground floor.

Articles
~/articles/2026-07-18-nadmesh-go-botnet-shodan-comfyui-ollama-3811-aws-keys
NadMesh botnet raids exposed AI tools for 3,811 AWS keys
cloud

NadMesh botnet raids exposed AI tools for 3,811 AWS keys

A Go botnet called NadMesh, active since early July, feeds a Shodan queue into ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio. Operator dashboard claims 3,811 AWS keys.

read →
~/articles/2026-07-15-rapid7-blazek-aws-persistence-iam-lambda-federated-hunt-runbook
AWS persistence: four patterns to hunt after an incident
Analysis
cloud

AWS persistence: four patterns to hunt after an incident

Rapid7's Jan Blažek maps four AWS persistence classes — new IAM users, assume-role edits, Lambda backdoors, federated tokens — with the CloudTrail signals to hunt for each.

read →
~/articles/2026-07-14-rabbitmq-miggo-oauth-secret-cross-tenant-cve-2026-57219
Miggo: RabbitMQ leaked OAuth secret via obsolete endpoint
cloud

Miggo: RabbitMQ leaked OAuth secret via obsolete endpoint

Miggo disclosed two RabbitMQ flaws today: an obsolete /api/auth endpoint exposed the broker's OAuth client secret, and a bug bypassed vhost boundaries.

read →
~/articles/2026-07-13-cisa-github-leak-postmortem-nine-alerts-six-months
CISA postmortem: nine alerts ignored, six months exposed
Analysis
cloud

CISA postmortem: nine alerts ignored, six months exposed

CISA's postmortem on its own six-month GitHub credential leak faults slow key rotation and nine ignored GitGuardian alerts — signal without intake.

read →
~/articles/2026-07-08-writeout-writer-ai-cross-tenant-session-sand-security
WriteOut: One Preview Link Took Over Writer AI Accounts
cloud

WriteOut: One Preview Link Took Over Writer AI Accounts

SAND Security's WriteOut let a Writer AI agent preview link steal a signed-in user's session cookie across tenants. Writer has patched — the pattern hasn't.

read →
~/articles/2026-07-08-gitlost-github-agentic-workflows-noma-security-private-repos
GitLost: Public Issue Leaks Private GitHub Repo Data
cloud

GitLost: Public Issue Leaks Private GitHub Repo Data

Noma Security's GitLost shows how a public GitHub issue can trick Agentic Workflows into leaking private repos. Not patchable — scope your agent tokens today.

read →
~/articles/2026-07-08-dialogflow-cx-rogue-agent-shared-exec-varonis
Dialogflow's Rogue Agent Flaw Is a Very Old Bug Class
Analysis
cloud

Dialogflow's Rogue Agent Flaw Is a Very Old Bug Class

Varonis' Rogue Agent finding in Google Dialogflow CX is a shared-runtime exec() escape — a bug class old enough to have graduated shared hosting.

read →
~/articles/2026-07-04-toddycat-umbrij-oauth-gmail-kaspersky
Umbrij: ToddyCat Hijacks Gmail OAuth via Browser
cloud

Umbrij: ToddyCat Hijacks Gmail OAuth via Browser

Kaspersky Securelist detailed Umbrij, a ToddyCat post-compromise tool that self-grants Google Workspace OAuth tokens by driving a logged-in Chromium session. Nothing to patch. Plenty to audit.

read →
~/articles/2026-07-04-artoken-eviltokens-m365-device-code-phishing-talos
ARToken PhaaS Targets M365 Device-Code Phishing
cloud

ARToken PhaaS Targets M365 Device-Code Phishing

Cisco Talos exposed ARToken, a React-panel phishing-as-a-service tied to EvilTokens. Device code flow is the mechanic. Conditional Access is the fix, and most tenants still haven't turned it on.

read →
~/articles/2026-07-04-consentfix-clickfix-m365-oauth-consent-phishing
ConsentFix + ClickFix: M365 Grants Outlive Resets
cloud

ConsentFix + ClickFix: M365 Grants Outlive Resets

BleepingComputer covered two M365 hijack patterns and Opera's Paste Protect defense this week. The clipboard lane can be closed. The OAuth grant substrate underneath is unchanged.

read →
~/articles/2026-07-03-argo-cd-repo-server-unauth-rce-unpatched
Unpatched Argo CD Flaw Lets Unauth Cluster Takeover
cloud

Unpatched Argo CD Flaw Lets Unauth Cluster Takeover

Synacktiv disclosed an unpatched code-execution flaw in Argo CD's repo-server component. No fix, no CVE. Reachability of the internal port is the whole game.

read →