Cybersecurity News
Filters
Filtered by tag: cloud security × Clear
NIST Warns of Unique Security Risks in Multi-Cloud Environments
NIST has identified 23 unique security challenges posed by multi-cloud environments, where organizations use services from multiple cloud providers simultaneously. The risks include increased attack surfaces, complex identity management, inconsistent security policies, and difficulties in data governance. NIST is calling on the cybersecurity community to develop solutions to address these emerging threats as multi-cloud adoption continues to grow.
Researchers Uncover Thousands of Leaked AWS Keys
Truffle Security researchers discovered more than 9,000 active, publicly exposed AWS key pairs on GitHub. The leaked credentials, embedded in public repositories, could allow attackers to access cloud resources and sensitive data. Many keys remained valid despite being public. The findings highlight ongoing risks from developers accidentally committing credentials to code repositories without proper secrets management practices.
Loan company breach sees nearly 750,000 users have financial info, SSNs leaked
Heights Finance disclosed a data breach affecting nearly 750,000 customers after attackers compromised a cloud account. Stolen data includes Social Security numbers, bank account details, and other sensitive financial information. The loan company is notifying affected individuals and has urged them to monitor their accounts for suspicious activity.
Komatsu Australia to move 4000 users to zero trust cloud security
Matched: Australia
Komatsu Australia is migrating around 4,000 users to a zero trust cloud security model, with a pilot phase beginning this month. The move aims to replace traditional perimeter-based security with identity-verified access controls, reducing risk as staff work across multiple locations and devices. The rollout reflects broader enterprise adoption of zero trust frameworks across Australian organisations.
Lessons Learned from CISA’s Recent GitHub Leak
CISA released a postmortem after a contractor accidentally exposed dozens of internal credentials, including AWS GovCloud keys, in a public GitHub repository for nearly six months. The leak went undetected until KrebsOnSecurity notified the agency. Security experts say the incident highlights critical gaps in credential monitoring and third-party contractor oversight that all security teams should learn from.
Conditional Access Misconfigurations Exposed 55 Orgs with MFA On
Huntress researchers found that Conditional Access misconfigurations left 55 organizations vulnerable despite having MFA enabled. Two real attack cases bypassed policies that appeared properly set up, exposing gaps invisible to standard reviews. Huntress's Managed Identity Security Posture Management tool is designed to detect these configuration flaws before attackers can exploit them.
