Domingo 12 Julio 2026 17:40:29 GMT+02:00

Netcrook

InicioManifiesto
Noticias
Techcrook
Geocrook
WikicrookEquipoAppContactoLogin
EnglishItaliano

Cloud, SaaS & Identity Security


GovCloud Credentials in a Public Repo: The Leak That Exposes Cloud Identity, Not Just Code

Published: 11 July 2026 08:02Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

CISA’s disclosure of an internal incident tied to AWS GovCloud credentials in a public repository is a reminder that the most sensitive cloud failures often begin with simple secret handling mistakes.

When a Cloud Identity Falls, AWS Can Move Fast From Access to Control

Published: 10 July 2026 06:08Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A reported AWS intrusion in roughly 72 hours shows how stolen credentials, weak identity controls, and exposed secrets can turn cloud security into a race the defender may already be losing.

When the AI Gateway Becomes the Prize

Published: 09 July 2026 19:05Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A cryptomining incident is a reminder that a gateway built to simplify AI access can also concentrate risk across models, cloud infrastructure, and IAM data.

Banking’s New Weak Spot Is Not the Firewall - It Is the Vendor Map

Published: 09 July 2026 16:27Category: Cloud, SaaS & Identity SecurityAuthor: AUDITWOLF

In finance, cyber risk is no longer confined to the bank’s own systems; the real exposure now stretches across SaaS tools, network gear, suppliers, and the quieter layers of the technology supply chain.

When a Mailbox Becomes an API Problem

Published: 09 July 2026 11:34Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A targeted campaign tied to ToddyCat shows how malware, installer lures, and cloud authorization abuse can turn Gmail from an inbox into an identity-risk surface.

Why a $2.9 Million Identity Bet Says More About Security Priorities Than Startup Money

Published: 09 July 2026 10:50Category: Cloud, SaaS & Identity SecurityGeo: Europe / SpainAuthor: SHADOWFIREWALL

8Layers’ extended pre-seed round is a small financing headline with a larger technical signal: buyers are still looking for better ways to see, score, and govern identity risk before attackers do.

Microsoft’s Device Code Flow Is Becoming a Rental Service for Account Takeovers

Published: 08 July 2026 18:06Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A late-June phishing run against Microsoft 365 shows how attackers are industrializing a legitimate sign-in method, turning trusted authentication into a reusable identity-abuse chain.

Passkeys Shift the Battle Line: Attackers Move From Password Dumps to Verification Flaws

Published: 08 July 2026 16:49Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

As password replay loses value in well-implemented passkey environments, account takeover pressure is migrating toward verification, recovery, and fallback paths that still decide who gets in.

The Real Microsoft Login That Handed Criminals a Session

Published: 08 July 2026 14:12Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A phishing kit called EvilTokens shows how attackers can abuse a legitimate OAuth path to collect valid Microsoft 365 tokens without stealing a password.

When a Preview Becomes a Breach Path: The Writer AI Session Leak Risk

Published: 07 July 2026 16:20Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A now-patched flaw in an enterprise AI workspace shows how a seemingly harmless preview layer can turn into a tenant-boundary problem if session handling slips.

WhatsApp’s New Handles Open a Fresh Front in Identity Abuse

Published: 07 July 2026 10:04Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

A move away from phone numbers can improve privacy, but it also shifts the fight toward impersonation, handle squatting, and first-contact trust.

The Hidden Identity Layer Powering AI: Why Machines Are Becoming the Hardest Users to Govern

Published: 06 July 2026 19:28Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A security article published on 2026-07-06 puts Non-Human Identities and AI agents in the spotlight, but the deeper issue is bigger: machine access is now a governance problem, not just a credential problem.

When the Login Page Is Real: The Device-Code Phishing Playbook Targeting Microsoft Accounts

Published: 06 July 2026 19:14Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A legitimate Microsoft sign-in path built for low-input devices is being repurposed as a phishing lure, shifting the attack from password theft to trusted-session abuse.

When a Browser Becomes the Break-In Tool

Published: 06 July 2026 04:02Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

A token-theft workflow tied to Umbrij shows how ordinary browser developer features can be turned into quiet access to corporate Gmail and other Google services.

Verified, Sponsored, and Still Dangerous: The Trust Signals Cybercriminals Are Learning to Hijack

Published: 04 July 2026 08:09Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

Two separate techniques show how attackers are leaning on user trust - one through a promoted macOS lure, the other through browser-based Microsoft 365 token abuse.

When Secrets Outnumber People, Identity Becomes the Real Attack Surface

Published: 04 July 2026 08:07Category: Cloud, SaaS & Identity SecurityAuthor: SHADOWFIREWALL

Non-human identities like service accounts, tokens, and secrets are often dozens of times more numerous than users, and that imbalance makes credential lifecycle management a core security problem.

The Quiet Power Struggle Behind Every Corporate Login

Published: 03 July 2026 18:04Category: Cloud, SaaS & Identity SecurityAuthor: AUDITWOLF

Identity controls decide who can act inside an organization, and the real risk often comes from access that lingers long after it is needed.

Europe’s Cloud Badge War: When Sovereignty Has to Pass an Audit

Published: 03 July 2026 16:19Category: Cloud, SaaS & Identity SecurityAuthor: SHADOWFIREWALL

Four providers entering a CISPE certification path shows how cloud sovereignty is shifting from branding to testable controls, with law and governance now part of the security stack.

When Agents Start Buying Software, the Real Battleground Becomes Identity, Not Interface

Published: 03 July 2026 10:08Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: SHADOWFIREWALL

Gartner’s forecast of US$234 billion in exposed SaaS spend is less about a software collapse than a shift in control, where permissions, contracts, and machine memory matter more than dashboards.

When the Consent Screen Becomes the Crime Scene

Published: 02 July 2026 18:37Category: Cloud, SaaS & Identity SecurityGeo: North America / USAAuthor: AUDITWOLF

ConsentFix and ClickFix show how a fake prompt and an OAuth flow can turn Microsoft 365 identity controls into a fast-moving token theft problem.