NadMesh Botnet Targets Exposed AI Services for Cloud Credentials and Kubernetes Tokens
A new Go-based botnet named NadMesh has been discovered actively hunting exposed AI services to steal cloud credentials and Kubernetes tokens. First…
A new Go-based botnet named NadMesh has been discovered actively hunting exposed AI services to steal cloud credentials and Kubernetes tokens. First…
A security researcher publishing under the handle tokay0 has disclosed an unpatched vulnerability in SharkNinja's Shark robot vacuum cleaners that could allow…
For years, routing traffic through cloud proxies was sufficient for enterprise security. However, the shift to browser-based work, SaaS applications, and generative…
Qualys offers cloud-based vulnerability management, policy compliance, and web application scanning solutions, used in the article as an example of a vulnerability…
SAP has released its July 2026 security updates, addressing multiple vulnerabilities including a critical out-of-bounds write flaw in SAP NetWeaver Application Server…
Microsoft Entra ID (formerly Azure Active Directory) is a cloud-based identity and access management service. It was affected by CVE-2026-69836, a critical…
Proofpoint has uncovered a novel evasion technique called OAuth client ID spoofing, exploited by at least two threat actors to validate stolen…
Security researcher cereblab discovered that xAI's Grok Build coding CLI (version 0.2.93) was uploading entire Git repositories—including full commit history—to a Google…
Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths Swati KhandelwalJul 14, 2026SaaS Security / Identity Security Attackers whose methods line…