Root on One Kubernetes Node Could Become Every Workload on It

Cryptographic workload identities cannot prove which process asked for them if an attacker controls the node making that claim. Unit 42 demonstrated the risk in SPIFFE/SPIRE.

Cryptographic workload identities cannot prove which process asked for them if an attacker controls the node making that claim. Unit 42 demonstrated the risk in SPIFFE/SPIRE.

A working app can still expose a key to private systems. Anthropic describes a 1.8 million-APK credential hunt in Claude-assisted criminal operations, while separate cases show how quickly stolen tokens can become wider access.

The passkey was only the pretext. Microsoft says attackers are calling personal phones, capturing cloud sessions and quietly collecting files and email for hours or days.

Researchers reached a Vietnam-linked passenger-data cluster through a cloud path and default credentials. It contained 220,783,700 flight records, including passport details, but ownership and possible theft remain unconfirmed.

Attackers diverted Coder's trusted Terraform registry to malicious modules that searched provisioners for cloud keys, tokens, SSH credentials and secrets.

A breach at Aesto Health reached 9.5 million people across at least two dozen providers, exposing medical, financial and identity data stored in AWS.

Hasbro says a compromised employee account exposed personal and financial information. Massachusetts records identify 436 affected residents, while the worldwide total remains undisclosed.

Nutex Health has confirmed that an unauthorised party accessed its network and exfiltrated information from company servers. The healthcare operator knows that data left the environment. It does not yet know, or has not publicly disclosed, whether the stolen material…

A Heights Finance cloud-platform breach reached borrowers, applicants and people who only enquired. Data retention turned a past interaction into a present risk.

The login pages were real. The QR codes were real. The device-linking requests were real. That did not make them safe. Google Threat Intelligence Group has documented three suspected Russian cyber-espionage clusters that repeatedly turn legitimate authentication features into initial-access…