AWS Security Blog4m ago
Amazon Web Services (AWS) is pleased to announce that the Spring 2026 System and Organization Controls (SOC) 1, 2, and 3 reports are now available. The reports cover 188 services over the 12-month period from April 1, 2…
Microsoft Security Blog2d ago
A dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments. This report details the attack chain, observed tradecraft, and detection opportun…
Microsoft Security Blog3d ago
Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. The post Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection appeared first on Microsoft Sec…
Microsoft Security Blog3d ago
The Mini Shai-Hulud campaign used malicious npm packages to target cloud and CI/CD credentials across developer environments. This report details the attack chain, detection opportunities, and mitigation guidance to hel…
AWS Security Blog3d ago
AWS Network Firewall now supports native attachment to AWS Transit Gateway. Customers commonly use Transit Gateway to route traffic from Amazon Virtual Private Cloud (Amazon VPC) networks to a centralized inspection VPC…
AWS Security Blog3d ago
Network administrators face a persistent challenge: maintaining domain blocklists and allowlists that keep pace with the internet. New websites and services emerge daily, and keeping these lists current requires constan…
Microsoft Security Blog4d ago
Microsoft Threat Intelligence presents a comprehensive analysis of The Gentlemen, a Go-based ransomware deployed by affiliates of Storm-2697 that combines per-file ephemeral key encryption with an aggressive self-propag…
Microsoft Security Blog5d ago
Microsoft exposes a cryptojacking campaign using SEO poisoning and ScreenConnect to target high-performance PCs, with malicious sites also surfaced through AI chatbots. The post From poisoned search results to GPU minin…
AWS Security Blog5d ago
May 26, 2026: This post was originally published in July 2022. It has been updated to reflect current engagement options, new threat intelligence resources such as the Threat Technique Catalog for AWS (TTC), additional…
AWS Security Blog5d ago
There have been multiple notable supply chain attacks using the npm Registry since September: Shai-Hulud, Chalk/Debug, one abusing tea.xyz tokens, and recently axios. Thanks to community efforts involving the Amazon Ins…
Microsoft Security Blog1w ago
Microsoft has been recognized as a Leader in The Forrester Wave™: Workforce Identity Security Platforms, Q2 2026, receiving the highest scores in both the current offering and strategy categories. The post Microsoft rec…
Microsoft Security Blog1w ago
A multi-stage attack on Linux devices began with an exposed F5 BIG-IP edge appliance and pivoted to an internal Confluence server for credential theft and identity compromise. Learn how the threat actor attempted Kerber…
Microsoft Security Blog1w ago
How Frontier firms secure AI at scale: read how Microsoft customers embed governance, identity, and cloud security to make protection an enabler of AI growth. The post Microsoft Security success stories: How St. Luke’s…
AWS Security Blog1w ago
We’re excited to announce that Amazon Web Services (AWS) has completed the S&P Global Know Your Third Party (KY3P) assessment of its security posture. This assessment demonstrates our continued commitment to meet the he…
AWS Security Blog1w ago
Managing identities and access across complex environments has become more critical than ever. AWS Directory Service for Managed Microsoft Active Directory, also known as AWS Managed Microsoft AD, has added new capabili…
Microsoft Security Blog1w ago
Microsoft Security’s latest updates extend visibility, control, and protection across expanding ecosystems as organizations accelerate AI adoption. The post What’s new in Microsoft Security: May 2026 appeared first on M…
AWS Security Blog1w ago
Agents have agency: they adapt and find multiple ways to solve problems. This autonomy creates a fundamental security challenge: the large language model (LLM) at the heart of the agent is non-deterministic, and its dec…
Microsoft Security Blog1w ago
Compromised @antv npm packages deploy the Mini Shai-Hulud payload to steal CI/CD secrets from Linux-based automation environments. The malware executes during npm install and targets credentials across GitHub, AWS, Kube…
AWS Security Blog1w ago
Our largest security services customers started the same way every customer does – with a click. They enabled Amazon GuardDuty, Amazon Inspector, AWS WAF, and AWS Security Hub, experienced the benefits in real time, and…
Cloud Security Alliance1w ago
I have seen this movie three times in my career. First, in 2007, IT leaders tried to ban the iPhone to protect the "security" of the Blackberry. Later in 2015, CISOs argued that the "cloud thing" would never touch the e…
AWS Security Blog1w ago
The AWS Customer Incident Response Team works with customers to help them recover from active security incidents. As part of this work, the team often uncovers new or trending tactics used by various threat actors that…
Cloud Security Alliance1w ago
Since OpenAI released ChatGPT 3.5 in late 2022, language models have advanced at a remarkable pace. What began as tools for text generation have quickly evolved into systems capable of reasoning, supervision, and automa…
Cloud Security Alliance1w ago
TL;DR When a hybrid threat lands, the first question a SOC has to answer isn't “what happened?” It's “how far can this go?” That's the blast radius question — and getting to a fast, accurate answer is the difference bet…
Cloud Security Alliance1w ago
A Closer Look for Franchise and Multi-Location Operators Artificial intelligence has quickly become the centerpiece of modern cybersecurity marketing. Many Managed Detection and Response (MDR) vendors now promise "AI SO…
Cloud Security Alliance1w ago
The findings in this blog are taken from Darktrace's annual State of AI Cybersecurity Report 2026. AI is already embedded in day-to-day enterprise activity, with 78% of participants in one recent survey reporting that t…
Cloud Security Alliance1w ago
Executive Summary AI agents are approving loans, giving legal advice, triaging patients, and controlling physical systems. When they cause harm, courts ask: can you prove who authorized the agent, what it was permitted…
Cloud Security Alliance1w ago
TL;DR Coverage percentages make for nice slides. They don't stop cloud breaches. Here's how to use MITRE ATT&CK to build detection coverage that actually maps to how attackers operate in AWS, Azure, OCI, and GCP — and w…
Cloud Security Alliance1w ago
The shadow AI conversation that started two years ago was about data leakage. An employee pasted a customer list into ChatGPT. A developer dropped proprietary code into a chat window. The risk was real, but the shape of…
Cloud Security Alliance1w ago
Cybersecurity incidents are often framed as enterprise problems: contained within corporate systems, isolated to IT teams, and addressed through technical remediation. In reality, their impact is far broader. When a med…
Cloud Security Alliance1w ago
It’s hard to overstate how quickly generative AI is evolving and changing how we do business. Capabilities change weekly, making cloud computing look slow by comparison. In my 25 years in technology I’ve never seen such…