Cloud
Attacks against cloud identity and productivity platforms — Microsoft 365, Google Workspace, Azure, AWS — including OAuth consent phishing, device-code abuse, token theft, and the "identity-first" intrusion patterns that treat the tenant, not the endpoint, as the ground floor.

NadMesh botnet raids exposed AI tools for 3,811 AWS keys
A Go botnet called NadMesh, active since early July, feeds a Shodan queue into ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio. Operator dashboard claims 3,811 AWS keys.

AWS persistence: four patterns to hunt after an incident
Rapid7's Jan Blažek maps four AWS persistence classes — new IAM users, assume-role edits, Lambda backdoors, federated tokens — with the CloudTrail signals to hunt for each.

Miggo: RabbitMQ leaked OAuth secret via obsolete endpoint
Miggo disclosed two RabbitMQ flaws today: an obsolete /api/auth endpoint exposed the broker's OAuth client secret, and a bug bypassed vhost boundaries.

CISA postmortem: nine alerts ignored, six months exposed
CISA's postmortem on its own six-month GitHub credential leak faults slow key rotation and nine ignored GitGuardian alerts — signal without intake.

WriteOut: One Preview Link Took Over Writer AI Accounts
SAND Security's WriteOut let a Writer AI agent preview link steal a signed-in user's session cookie across tenants. Writer has patched — the pattern hasn't.

GitLost: Public Issue Leaks Private GitHub Repo Data
Noma Security's GitLost shows how a public GitHub issue can trick Agentic Workflows into leaking private repos. Not patchable — scope your agent tokens today.

Dialogflow's Rogue Agent Flaw Is a Very Old Bug Class
Varonis' Rogue Agent finding in Google Dialogflow CX is a shared-runtime exec() escape — a bug class old enough to have graduated shared hosting.

Umbrij: ToddyCat Hijacks Gmail OAuth via Browser
Kaspersky Securelist detailed Umbrij, a ToddyCat post-compromise tool that self-grants Google Workspace OAuth tokens by driving a logged-in Chromium session. Nothing to patch. Plenty to audit.

ARToken PhaaS Targets M365 Device-Code Phishing
Cisco Talos exposed ARToken, a React-panel phishing-as-a-service tied to EvilTokens. Device code flow is the mechanic. Conditional Access is the fix, and most tenants still haven't turned it on.

ConsentFix + ClickFix: M365 Grants Outlive Resets
BleepingComputer covered two M365 hijack patterns and Opera's Paste Protect defense this week. The clipboard lane can be closed. The OAuth grant substrate underneath is unchanged.

Unpatched Argo CD Flaw Lets Unauth Cluster Takeover
Synacktiv disclosed an unpatched code-execution flaw in Argo CD's repo-server component. No fix, no CVE. Reachability of the internal port is the whole game.