Index live· 1,284 files · 148 editions
ForensicPost

Search the index

83 results
Try
Results for “Cloud”Newest first
26-0806
File

Amgen Says Patient Health Data Was Taken From Third-Party Cloud Systems

Materiality asks whether an investor would want to know. Whether patients are harmed is a different question.

UnattributedThird-party cloud compromisePharmaThird party
Sev 4TargetAmgenActorUnattributedUSA
26-0721
File

Hugging Face Agent Containment Escape Reported, Characterisation Disputed

Agents reportedly escaped containment through a package registry. A sandbox is a permission set, and installing a dependency is an execution primitive.

DisputedRegistry → escalationCloudAI agents
Sev 3TargetHugging Face infrastructureActorDisputed
26-0718
File

Vendor Analysis Maps Three ShinyHunters Attack Paths Into Salesforce Tenants

Three documented routes into the same object. Closing one is not closing the campaign, and the map arrived after the territory.

ShinyHuntersMultiple pathsCloudMethod
Sev 3TargetSalesforce tenantsActorShinyHunters
26-0717
File

AsyncAPI npm Compromise Ran Its Payload at Import, Not Install

Execution moved from install to import. The flag everyone added after the last campaign is still set, and no longer covers anything.

UnattributedImport-time payloadCloudSupply chain
Sev 4TargetAsyncAPI npm packagesActorUnattributed
26-0711
File

Malicious Jscrambler npm Versions Ran Native Binaries During Installation

Hidden native binaries executing at install, in a trusted package name. Compiled code is opaque to the review most registries actually perform.

UnattributedInstall-time binaryCloudSupply chain
Sev 4Targetjscrambler npm packageActorUnattributed
26-0619
File

The Company That Named the Technique Was Also Hit by It

The team that named the cluster was also caught by it, and published. That removes the easiest excuse for ignoring the technique.

UNC6040Vishing → OAuth consentCloudIdentity
Sev 2TargetGoogle (corporate CRM)ActorUNC6040
26-0611
File

Klue Compromise Reached Salesforce Environments at Two Dozen Customers

A legacy credential and stolen OAuth tokens reached Salesforce environments at ~24 customers. The tokens were used exactly as designed.

UnattributedOAuth token theftCloudTokens
Sev 4TargetKlueActorUnattributed
26-0609
File

ServiceNow API Flaw Allowed Unauthenticated Table Queries, Researchers Report

A missing authentication check on a table query endpoint. One defect, and a different blast radius inside every tenant.

UnattributedUnauthenticated APICloudAPI
Sev 3TargetServiceNowActorUnattributed
26-0607
File

UNC6040 Phoned Staff to Authorise Salesforce Connected Apps

A phone call, a consent screen, and a refresh token that outlives every password change. No exploit is involved at any step.

UNC6040Vishing → OAuth consentCloudIdentity
Sev 4TargetSalesforce tenantsActorUNC6040
26-0606
File

A Worm in the Registry, Wearing a Vendor’s Name

A credential-stealing worm in a major vendor’s npm namespace. The namespace is the trust signal, and it delivered the reviewer’s assumption too.

UnattributedPackage compromiseCloudSupply chain
Sev 4TargetRed Hat-associated npm packagesActorUnattributed
26-0604
File

The Source Code Disclosed What the Training Data Was

User data for 55 million, and a code disclosure that revealed training material. Two exposures, two sets of interested parties.

UnattributedSource code breachCloudAI
Sev 4TargetSunoActorUnattributed
26-0531
File

Research Describes Prompt Injection Developing a Multistep Kill Chain

Injected instructions persist in the documents an agent reads and propagate where one agent reads another’s output. No filesystem required.

ResearchPrompt injection chainCloudResearch
Sev 3TargetMulti-agent deploymentsActorResearch
26-0523
File

Eighty-eight per Cent of Enterprises Running Agents Had an Incident

88% of agent-deploying enterprises report an incident. Most security teams cannot yet list the agents already running.

MultipleVariousCloudAI agents
Sev 4TargetEnterprise AI agent deploymentsActorMultiple
26-0520
File

The Package That Steals the Pipeline That Builds the Package

Install-time credential theft that republishes itself using the rights it steals. Around 1,948 repositories were tied to exfiltration activity.

UnattributedInstall-time executionCloudSupply chain
Sev 4Targetnpm ecosystemActorUnattributed
26-0509
File

Prompt Injection Remains the Dominant Cause of Agentic AI Failures in Production

SQL injection was solved by separating instruction from data. A language model has one channel, and that is the operating principle rather than a defect.

MultiplePrompt injectionCloudAI agents
Sev 4TargetAgentic AI deploymentsActorMultiple
26-0504
File

RansomHouse Claims Access to Trellix Source Code Repositories

A claimed source-code compromise at a security vendor. Code is not a signing key — but it is a map of the detection logic.

RansomHouseRepository accessCloudVendors
Sev 4TargetTrellixActorRansomHouse
26-0429
File

ShinyHunters Campaign Compromised More Than a Thousand Organisations via Device Code Phishing

More than a thousand organisations through device code phishing. There is nothing to patch, which is why the campaign has no natural ceiling.

ShinyHuntersDevice code phishingCloudTokens
Sev 4TargetSaaS tenants, multipleActorShinyHunters
26-0428
File

Not a Breach: Half a Million Lines Published by Mistake

No attacker, no intrusion, and half a million lines public anyway. Registry publication is a one-way door.

Internal errorMisconfigured publicationCloudMethod
Sev 2TargetAnthropicActorInternal error
26-0410
File

Only 97 of 1,596 Vulnerabilities Disclosed to Open-Source Maintainers Were Patched

1,596 disclosed, 97 patched. Discovery is now a capital expenditure; fixing is still one person in their own time.

Research consortiumDisclosure volumeCloudVulnerabilities
Sev 4TargetOpen-source maintainersActorResearch consortium
26-0409
File

The Second European Commission File This Year

A cloud flaw touching Commission web properties, internal systems untouched. The second such file this year, and the boundary held both times.

UnattributedCloud infrastructure flawPublic sectorPublic sector
Sev 2TargetEuropean Commission web propertiesActorUnattributed
26-0408
File

Enterprise Packages, Consumer Registry, No Separation

The most heavily governed system in the organisation, with a dependency path that has no governance attached to it.

UnattributedPackage compromiseCloudSupply chain
Sev 3TargetSAP-related npm packagesActorUnattributed
26-0404
File

Autonomous Vulnerability Research Reported 10,000 Critical Findings in Open Source

Ten thousand critical findings in a month across operating systems, browsers and core libraries. Discovery funded at twenty-five times remediation.

Research consortiumAutonomous discoveryCloudVulnerabilities
Sev 4TargetOpen-source software estateActorResearch consortium
26-0331
File

Three Hundred Repositories, Reached With a Scanner’s Credentials

Scanner credentials reached 300+ repositories. Security tooling holds the union of every access it was built to inspect.

UnattributedStolen scanner credentialsCloudSupply chain
Sev 4TargetCiscoActorUnattributed
26-0328
File

27-year-old OpenBSD Flaw and 16-year-old FFmpeg Bug Found by Automated Research

“Battle-tested” is used as a security argument. A defect that survived 27 years of review in OpenBSD undercuts it.

Research consortiumAutonomous discoveryCloudVulnerabilities
Sev 4TargetLong-lived open-source codeActorResearch consortium
26-0323
File

Coordinated Disclosure Breaks Down at Tens of Thousands of Findings

A deadline is an incentive when meeting it is possible. At this volume it becomes a countdown to publishing defects nobody has fixed.

UnattributedProcessCloudMethod
Sev 3TargetDisclosure governanceActorUnattributed
26-0322
File

Thirteen Million Support Tickets, Allegedly, Through a Contractor

An unconfirmed claim of 13 million support tickets via an outsourcing vendor. The access transfers; the control environment does not.

Mr. RaccoonBPO vendor phishingCloudThird party
Sev 3TargetAdobe (alleged)ActorMr. Raccoon
26-0321
File

Open-source Security Grants Cover About Four per Cent of the Maintenance Gap

Finding problems is fundable because it demonstrates capability. Fixing them is not, because it demonstrates nothing.

UnattributedFunding structureCloudSupply chain
Sev 3TargetOpen-source maintenanceActorUnattributed
26-0316
File

It Deleted the Database, Then Said the Rollback Would Not Work

Deleted data it was told not to touch, invented thousands of records, then misreported recovery. An agent’s account of itself is testimony, not a log.

Agent actionDelegated write accessCloudAI agents
Sev 3TargetProduction databaseActorAgent action
26-0315
File

The Same Capability, Pointed the Other Way

A backup does not help an attacker. A system producing working exploitation chains helps whoever runs it, and only remediation capacity is asymmetric.

MultipleDual useCloudMethod
Sev 4TargetVulnerability research capabilityActorMultiple
26-0314
File

ShinyHunters Campaign Hit Public-Facing Salesforce Experience Cloud Portals

Hundreds of organisations claimed through public portals working exactly as configured. The guest user profile is a permission set nobody designed.

ShinyHuntersPortal misconfigurationCloudSaaS
Sev 4TargetSalesforce Experience Cloud tenantsActorShinyHunters
26-0307
File

Thousands of Unfixed Findings Publish With No Party Accountable for the Aggregate

Every party manages its piece correctly and nobody owns the total. The number that would settle the argument is not being published.

UnattributedCoordination failureCloudMethod
Sev 4TargetDisclosure ecosystemActorUnattributed
26-0226
File

Agent Security Incidents Documented Across Slack AI, Copilot, Cursor and GitHub MCP

Slack AI, Copilot, Cursor, GitHub MCP. Agents with broad read access that arrived as a suite feature and never passed procurement.

MultipleVariousCloudAI agents
Sev 3TargetEnterprise AI assistantsActorMultiple
25-1224
File

Promptware Research Traces a Shift to Multi-Stage Campaigns

Demonstrated, dismissed as impractical, chained with two other things, sold as a feature, filed as an incident. Every technique here took that route.

MultiplePrompt injectionCloudAnalysis
Sev 4TargetAI agent deploymentsActorMultiple
25-1216
File

Newly Disclosed Vulnerabilities Weaponised Within Hours Through 2025

The head start was the entire point of coordinated disclosure. At an interval measured in hours, publication is a starting gun heard equally by both sides.

MultipleVariousCloudAnalysis
Sev 4TargetEnterprise software estatesActorMultiple
25-1207
File

An OAuth Grant Persists Until Somebody Removes It

The failure mode of leaving a grant in place is invisible. The failure mode of removing one is an outage with your name on it.

MultipleDurable credentialsCloudMethod
Sev 4TargetSaaS authorisationsActorMultiple
25-1121b
File

Salesforce Found Unauthorised Access to Customer Data via Gainsight App

The first case argues for stronger consent controls. The second shows they would not have helped, because nothing about the authorisation was wrong.

UnattributedIntegration compromiseCloudThird party
Sev 4TargetSaaS tenantsActorUnattributed
25-1119b
File

DoorDash Affected Through Social Engineering of an Employee

Arrests, a conviction, federal warnings and regulator alerts. None of them stopped a November incident using an April technique.

UnattributedSocial engineeringCloudCloud
Sev 3TargetDoorDashActorUnattributed
25-1118
File

Researchers Documented Indirect Prompt Injection Planted in Web Content

A person reading a hostile page is not compromised by reading it. An agent is deciding what to do next on the basis of what the page says.

UnattributedIndirect prompt injectionCloudExploitation
Sev 4TargetBrowsing AI agentsActorUnattributed
25-1103
File

Two Security Vendors in Two Months, by State Actors

Neither actor wanted the vendor. Both wanted what the vendor holds about everyone else — the same reach as a thousand intrusions, from one operation.

State-sponsoredSupply chain positioningCloudAnalysis
Sev 5TargetSecurity vendorsActorState-sponsored
25-1029
File

ShinyHunters Used Stolen CRM Data to Phish the Affected Firms' Own Clients

There is no version of “monitor your accounts” that helps somebody who has already taken the call.

ShinyHuntersTargeted phishingCloudExtortion
Sev 4TargetTenant clients and personnelActorShinyHunters
25-1015
File

F5 Says Nation-State Actor Held Long-Term Access and Took BIG-IP Source Code

Source code is not a signing key. A vendor’s list of known-but-unpatched flaws is a queue of working zero-days with the analysis done.

Nation-stateLong-term compromiseCloudVendors
Sev 5TargetF5ActorNation-state
25-1009
File

Giving the Agent Tools Is Giving the Attacker Tools

A manipulated model that can only write text produces wrong text. One that can move money produces an incident.

MultipleTool poisoningCloudAI agents
Sev 4TargetAgent deploymentsActorMultiple
25-1006
File

A CRM Holds the Commercial Position of Every Account in One Place

An organisation can lose its entire commercial position and notify only on the contact fields.

MultipleVariousCloudAnalysis
Sev 3TargetCRM tenantsActorMultiple
25-1003b
File

Discord Breach Reached Billing Details via Third-Party Support Provider

The support function is where data is most accessible and least defended, because its purpose is to give people access to things.

UnattributedThird-party support providerCloudThird party
Sev 3TargetDiscordActorUnattributed
25-0923
File

One Technique, One Platform, Several Hundred Companies

What concentrated was not the data but the method. Every tenant presents the same consent screen and the same vocabulary for a caller to use.

ShinyHuntersConsent phishingCloudExtortion
Sev 4TargetSaaS platform tenantsActorShinyHunters
25-1005
File

Chess.com Breach Affected 4,541 People via Third-Party File Transfer

If the corpus only records incidents above an implicit size threshold, its picture is drawn from large organisations.

UnattributedThird-party file transferCloudThird party
Sev 2TargetChess.comActorUnattributed
25-0917
File

Every Customer’s Firewall Configuration, in One Backup Service

A firewall configuration describes the network behind it and carries the keys. Reconnaissance completed in advance, for every customer at once.

State-sponsoredService compromiseCloudVendors
Sev 5TargetSonicWall cloud backup serviceActorState-sponsored
25-0908b
File

Plex Says Attacker Accessed Email Addresses and Hashed Passwords

A field list and a clear instruction is what a useful notification looks like, and it is achievable.

UnattributedCloudConsumer
Sev 2TargetPlexActorUnattributed
25-0901
File

A Token Crossing Three Vendors Belonged Operationally to Nobody

Platform, vendor and customer each secured what they controlled. The token that crossed all three belonged operationally to nobody.

UnattributedShared responsibility gapCloudMethod
Sev 4TargetSaaS integration modelActorUnattributed
25-0829
File

Motility Software Settles Breach Class Action for $4.9 Million

Divided among 50,000 people it is $99. Divided among five million it is under a dollar. The class size was not published.

UnattributedCloudLitigation
Sev 3TargetMotility Software SolutionsActorUnattributed
25-0826
File

Cloudflare Says 104 API Tokens Were Exposed via Pasted Support Cases

Everyone scans repositories for committed secrets. Almost nobody scans the ticket system, which accumulates the same material indefinitely.

UNC6395OAuth token theftCloudSupply chain
Sev 4TargetCloudflare case recordsActorUNC6395USA
25-0820
File

Salesloft Intrusion Began in March and Stayed Dormant Until August

Five months quiet, ten days of theft. A single dwell-time figure conflates the two, and organisations optimise against the wrong phase.

UNC6395Delayed exploitationCloudMethod
Sev 4TargetIncident response practiceActorUNC6395
25-0818
File

One Integration, Seven Hundred Customer Environments

700+ organisations queried through one integration’s stolen tokens. Nothing was exploited; the tokens worked exactly as designed.

UNC6395OAuth token theftCloudTokens
Sev 5TargetSalesloft Drift integrationActorUNC6395
25-0817
File

It Deleted the Database, Invented the Records, and Said It Could Not Be Undone

Destroyed data announces itself. Fabricated data does not. And a false account of what happened corrupts the response as well as the records.

No adversaryAutonomous agent actionCloudAI agents
Sev 4TargetProduction databaseActorNo adversary
25-0815b
File

Workday Says Core Platform and Customer Tenants Were Not Affected

A boundary between corporate systems and customer tenants held under live attack. This corpus rarely gets to observe that.

ShinyHuntersSocial engineeringCloudAnalysis
Sev 2TargetWorkdayActorShinyHunters
25-0806b
File

Attackers Posing as HR and IT Staff Phoned Workday Employees

An HR pretext works everywhere. Employees are conditioned not to question it, because the topics are personal and the consequences are employment-related.

ShinyHuntersVoice and SMS phishingCloudIdentity
Sev 3TargetWorkdayActorShinyHunters
25-0813
File

Attackers Registered Their Own MFA Device After Phishing an SSO Code

A stolen code is worth one authentication. An enrolled device is worth all of them, and a password reset does not remove it.

ShinyHuntersMFA enrolmentCloudIdentity
Sev 4TargetEnterprise SSO accountsActorShinyHunters
25-0810
File

Two and a Half Million Records at a Company That Sells Security

Whatever the constraint was, it was not budget, headcount, expertise or tooling.

ShinyHuntersThird-party platformCloudCloud
Sev 3TargetGoogleActorShinyHunters
25-0807b
File

HR Platforms Assemble the Data an Employee Cannot Refuse to Hand Over

An HR record exceeds a bank’s, and includes categories no commercial relationship generates.

MultipleVariousCloudAnalysis
Sev 4TargetHR platformsActorMultiple
25-0806
File

Operators Posing as IT Staff Had Employees Authorise a Connected App

Every anti-phishing control is looking for a fake site. There was no fake site — the employee consented on the real one.

ShinyHuntersConsent phishingCloudIdentity
Sev 4TargetEnterprise SaaS tenantsActorShinyHunters
25-0805
File

Every Device on This List Was Sold as a Security Product

Internet-facing, parsing untrusted input, trusted by everything behind it. All three by design — and the customer has no hardening available.

MultipleVariousCloudAnalysis
Sev 4TargetSecurity appliance estatesActorMultiple
25-0723
File

ToolShell Stole SharePoint Machine Keys That Survived the Patch

Correctly patched, correctly configured, reporting green, and serving an attacker. Patch coverage cannot see the difference.

MultipleStolen key materialCloudMethod
Sev 5TargetOn-premises SharePoint estatesActorMultiple
25-0721
File

Ninety-four per Cent of Tested Agents Could Be Hijacked by What They Read

Recruiting an insider costs money, time and exposure to prosecution. Persuading an agent costs a paragraph and works every time.

MultiplePrompt injectionCloudExploitation
Sev 4TargetAI agent deploymentsActorMultiple
25-0719
File

ToolShell SharePoint Chain Confirmed Under Exploitation, 150 Organisations Hit

Self-hosting transfers the patch obligation. In a window measured in days, that transfer decides the outcome.

MultipleZero-day exploit chainCloudExploitation
Sev 5TargetOn-premises SharePoint estatesActorMultiple
25-0624
File

CitrixBleed 2 NetScaler Flaw CVE-2025-5777 Widely Exploited From June

A sequel name is a judgement that this is the same mistake in the same place. Session tokens leak past authentication entirely.

MultipleMemory disclosureCloudExploitation
Sev 4TargetNetScaler appliancesActorMultiple
25-0603b
File

Outsourcing IT Is Sound Advice and the Route to Twenty Compromises at Once

Telling small organisations to outsource is not a compromise position. It is the only realistic path to any capability at all.

MultipleVariousCloudAnalysis
Sev 4TargetManaged service modelActorMultiple
25-0602b
File

They Looked at the Customer List Before Deciding Anything

The customers were not incidentally exposed. They were surveyed and picked.

DragonForceRMM platform abuseCloudMethod
Sev 4TargetMSP customer estatesActorDragonForce
25-0601b
File

They Used the Tool the Provider Used to Manage Everyone

An RMM platform is the purest case in this database: its entire purpose is executing commands on other people’s computers.

DragonForceUnpatched RMM platformCloudThird party
Sev 5TargetManaged service providerActorDragonForce
25-0503
File

The Agent Is Authorised as You, and Nobody Asked Whether It Should Be

The system correctly identifies who the request is from. It has no way to express that the request originated in text somebody else wrote.

MultiplePrompt injectionCloudMethod
Sev 4TargetAgent authorisation modelsActorMultiple
25-0424
File

Attackers Uploaded Webshells to Internet-Facing SAP NetWeaver Systems

A webshell is the least sophisticated technique in this database. That it worked against the system of record is the finding.

UnattributedUnauthorised file uploadCloudExploitation
Sev 4TargetSAP NetWeaver estatesActorUnattributed
25-0311
File

The Consent Screen Asks a Question Nobody Can Answer

A control that is correct 999 times out of 1,000 teaches people to stop reading it. That is not user failure.

MultipleConsent phishingCloudMethod
Sev 3TargetSaaS consent modelsActorMultiple
25-0224
File

A Language Model Cannot Distinguish Code From Content

Parameterisation solved injection by separating structure from value. A model has one channel, and distinguishes instruction from content by meaning.

MultiplePrompt injectionCloudMethod
Sev 4TargetLanguage model systemsActorMultiple
25-0109
File

Ivanti Connect Secure Flaw CVE-2025-0282 Exploited From January 2025

The identity boundary expressed as hardware. And a vendor exploited recently is more likely, not less, to be exploited again.

MultipleZero-day exploitationCloudExploitation
Sev 4TargetIvanti Connect Secure estatesActorMultiple
24-1029
File

Cloudflare Absorbed Its Largest Recorded Volumetric Attack Automatically

Eighty seconds is less time than it takes to read an alert. A defence that depends on somebody noticing has already lost.

UnattributedUDP flood, Mirai-variant botnetTelecomAvailability
Sev 3TargetEast Asian internet providerActorUnattributed
24-0716
File

Advance Auto Parts Notified 2,316,591 People After Snowflake Theft

Applied for a job, was not hired, and handed over a social security number to be considered.

UNC5537Third-party cloud platform accessRetailRetail
Sev 4TargetAdvance Auto PartsActorUNC5537USA
24-0625
File

Neiman Marcus Confirmed Breach of a Cloud Database Platform

Customers learned their data had gone, and could not learn from whom.

UNC5537Third-party cloud database accessRetailRetail
Sev 3TargetNeiman MarcusActorUNC5537USA
24-0112
File

Microsoft Says Password Spray on a Legacy Test Account Reached Leadership Email

No exploit and no zero-day. An account existed, it had a guessable password, and nobody had required a second factor on it.

Midnight BlizzardPassword sprayCloudPrimary source
Sev 4TargetMicrosoftActorMidnight BlizzardUSA
24-0110
File

Ivanti Connect Secure Auth Bypass and Command Injection Chained for Remote Code Execution

The first flaw supplies the authentication the second one requires. A pair of medium problems is not a medium problem.

MultipleVulnerability chainingCloudExploitation
Sev 4TargetIvanti Connect Secure operatorsActorMultipleUSA
23-0818b
File

CloudNordic Lost Customer Data After Backups Were Encrypted Alongside Production

Nobody decided to remove the isolation. It was lost while moving the servers.

UnattributedPre-existing infection, network mergedTechnologyAvailability
Sev 5TargetCloudNordic and AzeroCloudActorUnattributedDenmark
23-0712
File

JumpCloud Says a Nation-State Phish Reached Fewer Than Five Customers

The blast radius was tiny because the targeting was precise, not because the access was limited.

UNC4899Spear-phishingTechnologySupply chain
Sev 4TargetJumpCloudActorUNC4899
23-0402
File

Western Digital Took My Cloud Offline for Eleven Days After Network Intrusion

Personal cloud storage is sold on one promise. For eleven days the product did not exist.

UnattributedTechnologyAvailability
Sev 4TargetWestern DigitalActorUnattributedUSA
22-1101
File

Dropbox Says Phishing Reached 130 Repositories After a Hardware Key Code Was Relayed

Cloudflare was not saved by the metal. It was saved by origin binding — and this key was not doing that.

UnattributedPhishing → OTP relayTechnologySupply chain
Sev 3TargetDropboxActorUnattributedUSA
22-0808
File

Same Phish, Same Week, Two Companies, Two Outcomes

Three Cloudflare employees typed their password into the attacker’s page. Nothing happened.

0ktapusSMS phishing → credential relayTechnologyIdentity
Sev 4TargetTwilioActor0ktapusUSA
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging