Wednesday 09 September 2026 14:44:27 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContact
EnglishItaliano

Cloud, SaaS & Identity Security


Root of the Problem: A Month of Password Spraying Put AWS’s Most Privileged Login in the Crosshairs

Published: 01 September 2026 10:26Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A sustained attempt against AWS root accounts shows how low-rate credential attacks still matter when the target is the one identity that can reach everything.

When a Browser Cookie Becomes the Back Door

Published: 31 August 2026 08:11Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

Session-cookie theft can sidestep 2FA in SaaS apps, turning a user’s signed-in browser into the weakest link in the chain.

When a Session Cookie Becomes the Skeleton Key to an AI Account

Published: 31 August 2026 08:06Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A credential-stealing campaign aimed at Claude accounts shows why modern account security is no longer just about passwords - it is about revoking live sessions before an attacker can replay them.

Stolen Claude Sessions Turn a User PC Into a Billing Weapon

Published: 30 August 2026 18:05Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

Anthropic’s warning points to a familiar but still underappreciated threat: endpoint malware can steal live SaaS sessions and let an attacker act as the authenticated user without ever learning the password.

The Quiet Security Layer That Could Rewire Cloud Identity

Published: 28 August 2026 16:48Category: Cloud, SaaS & Identity SecurityAuthor: AUDITWOLF

Identity fabric is emerging as a way to connect fragmented IAM systems, watch identity behavior in real time, and reduce the blind spots created by unmanaged machine accounts.

The Password Manager That Turned Identity Sprawl Into a Single Subscription

Published: 28 August 2026 08:32Category: Cloud, SaaS & Identity SecurityGeo: Europe / SwitzerlandAuthor: AUDITWOLF

A discounted bundle for encrypted passwords, passkeys, aliases, and leak alerts shows how consumer security is moving from isolated tools to layered identity control.

The Quiet Breach Path Inside Google Workspace

Published: 27 August 2026 16:28Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

The most dangerous entry points are often not exotic exploits, but a convincing message, a forgotten app grant, and a slow response window.

When Cloud Logs Start Telling the Same Story

Published: 27 August 2026 16:12Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

AWS defenders can turn CloudTrail, VPC Flow Logs, and Route 53 Resolver data into a single timeline that makes suspicious activity easier to interpret.

When One Alert Is Not Enough: The Hidden Trail of Cloud Intrusions

Published: 27 August 2026 14:21Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

AWS’s detection guidance spotlights a hard truth in cloud security: credential theft is often only the opening move, and the real story emerges when identity, storage, network, and DNS signals are read together.

Okta’s Rally Points to a Bigger Cyber Bet: Identity for AI Agents

Published: 27 August 2026 14:08Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

The earnings pop is only part of the story. The deeper signal is that buyers are treating machine identities and AI agents as security objects, not just automation tools.

The Cloud’s Soft Underbelly: How Logins Became the New Breach Path

Published: 27 August 2026 13:03Category: Cloud, SaaS & Identity SecurityGeo: Europe / RussiaAuthor: AUDITWOLF

Identity abuse, not malware, is doing the heavy lifting in a campaign built around OAuth, device-code phishing, and suspected reverse-proxy phishing infrastructure.

Snowflake’s password lockout exposes a deeper cloud problem: nobody knows what the service accounts still do

Published: 26 August 2026 18:41Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

Ending passwords for legacy machine identities is only the visible move; the harder task is finding every hidden integration, its owner, and the access it still deserves.

Why MFA Can Let the Wrong Person In

Published: 26 August 2026 14:27Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

The security lesson is not that multi-factor authentication fails, but that it can succeed at the wrong job if identity proofing and monitoring are treated as afterthoughts.

WhatsApp Hardens the Front Door: Passkeys, Stronger Recovery, and Call Clues

Published: 26 August 2026 12:40Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A new security update adds multiple passkeys, longer alphanumeric passwords, and caller context - a small set of changes that could matter a lot in a platform where trust is often tested before a message is even opened.

WhatsApp Tightens the Lock on Accounts and Scam Calls

Published: 26 August 2026 10:31Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

New security features point to a broader shift away from one-time codes and toward phishing-resistant authentication, with extra friction added before users trust an unknown caller.

WhatsApp’s Passkey Shift Raises the Cost of a Takeover

Published: 26 August 2026 08:19Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A new security rollout on the messaging giant pushes login away from shared secrets and toward phishing-resistant credentials, while also tightening fallback and scam cues.

WhatsApp Pushes Passkeys Past a Billion Users, Then Hardens the Weak Links Around Them

Published: 26 August 2026 08:09Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

The login story is only half the picture: WhatsApp is pairing passkeys with a stronger second-step secret and caller-context cues aimed at lowering phishing, recovery abuse, and scam pressure.

When Active Directory Falls, the SOC Becomes the Last Line of Defense

Published: 26 August 2026 08:06Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A CISA red-team lessons-learned advisory shows how identity compromise can become a business crisis when detection, escalation, and containment do not move fast enough.

WhatsApp Tightens the Lock: Passkeys, Stronger Recovery, and a New Layer Against Scam Calls

Published: 25 August 2026 18:04Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

WhatsApp is pushing account security toward device-bound login, tougher two-step verification, and more caller context on Android, a small interface shift with real anti-phishing value.

WhatsApp Hardens the Gate: Passkeys, Stronger 2SV, and a Small Dose of Caller Intel

Published: 25 August 2026 16:34Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

The app is tightening account access with multiple passkeys and a tougher second-step secret, while Android users get more context when an unknown number rings through.