Visualização de leitura

The need to fortify cloud integrity as cracks increase

Over the course of his career, Jim Reavis has seen cloud and cloud security evolve, and it’s come a long way since being a niche technology in the early 2000s. Now it’s dominant in terms of being the IT foundation, he says, but while the tech is strong, the operating models is where things get messy. Cloud, security, and third-party risk teams look at different parts of the problem, of course, but challenges remain.

“Operational technology worries me a great deal,” he says. “A lot of those systems are isolated and not kept up to date. If we don’t modernize them, we’re going to have huge problems. In a lot of cases, things fall between the cracks and that’s where hackers like to exist.”

So much of what’s around the models is where cybersecurity has responsibility, rather than the provider covering everything. “Data, identity, and applications are shared responsibility areas, and in many cases, the tenant carries most of the control burden,” Reavis says. “If you use a hyperscaler, you may still have about 80% of the responsibility for the controls around what you build.”

And when it comes to AI, the model isn’t the whole problem. What matters is the context around it, the goals it’s given, and the oversight put in place, he says. “We need to think carefully about the harnesses we put around AI and the systems we use,” he adds.

The responsibility model, therefore, is a recurring issue in cloud security breaches tied to misconfiguration and accountability gaps, and some enterprises still aren’t clear about where responsibility begins and ends. “We spent a lot of time on a shared security responsibility model, but when this first started to gain popularity, there were a lot of organizations or SaaS providers you could work with who’d say it’s in the cloud, it’s at Amazon,” he says. “Look at their certifications and SOC2 and how they comply because they’re covering everything.” But when you look at the actual applications, data, and identity, he adds, there’s so much that’s shared responsibility, and the customer’s responsibility.

So how do we make sure information is encrypted properly so it doesn’t become a tenant issue? “There’s still a bit to do, and we think about this not only from whether it’s SaaS, infrastructure, or a particular provider, but at what level is it at the physical, network, or audit level,” he says. “And even from a role-based perspective, what’s the role of internal risk and role of providers?”

Reavis gives further detail about how AI adoption exposes weaknesses in identity, trust, and risk management, and the long-term implications of increasingly interconnected cloud ecosystems. Watch the full video below for more insights, and be sure to subscribe to the monthly Center Stage newsletter by clicking here.

On cloud risk management: When we had the Chat GPT moment, we knew it because AI had been around for a while, but that was a cloud delivered version of AI to the masses, so we saw this going to evolve and you could see it combining in many important areas.

But what we’ve learned is, because this is an interesting predictive rather than deterministic technology, we’re living in a world of two exponentials, and you’re seeing model capabilities growing so quickly. There’s this feeling from a security perspective that we have to look to the model itself and fix every hallucination and everything else when that’s built into how it works. It’s actually working as intended. So that’s a new lesson. Models are going to get more powerful, but it’s so much of what’s around the models where cybersecurity has responsibility, and we don’t rely on frontier model companies or using open-weight models. Rather, what’s the context, oversight, and information we’re providing them, what do we do in terms of goals we give them, and what are the harnesses we put around AI and the models we deal with?

These are going to be the big areas to think about, but we have to understand the parts we can control. We’ve got to think carefully about the harnesses, transparency, and using supply chain shared responsibility. SaaS and cloud providers are all AI enabled now. You’re not using any software of any significance that isn’t using AI to some degree.

On AI identity, trust, and control: One of the areas that we’ve championed is zero trust as a philosophy. It was initially more of a networking type of approach at the network layer, or an idea that you use identity to understand network access. But it’s evolved more to an idea that anything can be breached, so you assume that. Then you think about how to make systems resilient, and build up confidence and protection.

So zero trust tells us that with human identity, we can ask what our digital identity is, and now we’re in a very interesting area for identity management and associating that with agents and AI systems. People might have just one view of it, but agents are as diverse as humans. So we think about different identities and least privilege, and how to prevent them from escalating privileges. We need to introduce new concepts like least autonomy, and think about an agent that has certain tasks and use identity to make sure the actions it takes are within a defined scope. Because while we’ll see a lot of security incidents with AI, proportionately we’ll see more misconfiguration and bad things that happen because of broken processes. And the AI system just deletes things because it thought that’s what it’s supposed to do.

So it’s important to make strides in how we think about identity and agents, and the idea of digital workers. How do we manage and treat those? If we think about them too much in either one of those realms, we’re going to fail. So we have to understand what’s the right blend. It’s a new area and very exciting.

On risk and legacy systems: When I think about operational technology, sometimes systems are isolated and not kept up to date. That concerns me a great deal. We’re going to have huge problems there. We have concerns about existential risks, where people don’t want to use the latest technologies and be aggressive adopters of AI. I think that’s going to create real scale issues with organizations.

So we have to understand where we are, where we’re going, and have a vision that serves something between human and technology, maybe a hybrid, but we’ve got to make our peace with it and understand the appropriate harnesses and direction where humans should always be in the loop with control. But it’s appearing in some new areas of cybersecurity where we haven’t traditionally thought about. Software development looks very different now than it did 12 months ago, and 12 months from now, cybersecurity is going to be really different, too.

On cloud security and implementation: Cloud security is cybersecurity for all intents and purposes. We have so much tooling and technology that’s really good, but there’s a lot of inconsistencies with the operating models organizations have. Even way back with CSA and NIST defining this, it was clear that SaaS was a layer on top of infrastructure as a service. But we diverged, and you see in a lot of enterprises there’s diffused ownership where you have cloud and security teams, and then you have third-party risk that deals with the SaaS team. Then there are inconsistencies in how risks are managed, so internal development and expectations from our partners can really diverge. They have a lot of regulations to deal with, so it creates vetting and investment challenges while striving for consistent models.

Some security teams might still use older checklists to talk to their cloud teams, but scaling with new tech becomes an issue if you’re not thinking about operations. It ends up being a human and a structure problem that makes it harder to take advantage of all the great technology that’s out there.

Fake OpenAI, Anthropic and DeepSeek Crawlers Target .env Files and Cloud Credentials

Threat actors are impersonating AI web crawlers from organizations such as OpenAI, Anthropic, DeepSeek, Google, Perplexity, and Amazon to scan internet-facing servers for exposed secrets, according to a GreyNoise research report published on August 28, 2026. This activity involves automated scanners that use forged crawler user-agent strings to request sensitive files, including .env configurations, AWS […]

The post Fake OpenAI, Anthropic and DeepSeek Crawlers Target .env Files and Cloud Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Kyndryl, Broadcom expand partnership to push private clouds for AI work

Kyndryl and Broadcom on Thursday rolled out new consulting services for VMware Cloud Foundation (VCF), tweaking the initiative to be an AI program and pledging to invest in the skills development of several thousand certified Kyndryl consultants, architects, and delivery specialists to enable agentic workflows.

“Against the backdrop of rising sovereignty demands, enterprises are rationalizing their hybrid and private cloud environments, and they require a pragmatic, outcome-driven approach,” said Giovanni Carraro, global strategic alliances leader at Kyndryl, in a news release. “By expanding our partnership with Broadcom and investing in VCF skills, we will help customers build modern, resilient, private clouds that enable AI adoption, support data modernization, address the risk of AI-identified vulnerabilities and deliver real business value.”

Analysts and consultants said the partnership expansion was fairly mundane in itself, but they did think there was meaningful potential in the consultant program.

Mike Leone, a VP/principal analyst at Moor Insights & Strategy, thought that the significant part of the partnership is in the skills investment.

“Enterprises moved onto VCF pretty quickly, and now they’re at the harder stage of actually modernizing it,” he said. “More companies than you think have lost their deep VMware talent, so that work stalls out. Broadcom putting real money behind training a few thousand Kyndryl consultants is a direct answer to that.”

He noted that it isn’t glamorous, but delivery capacity is usually what decides whether a platform gets used well. “Kyndryl’s a logical partner for it too,” he said. “They already run a huge amount of VMware for customers, so this resources a relationship that was already there.”

But Sanchit Vir Gogia, chief analyst at Greyhound Research, questioned how much is really new with this announcement. 

“This is neither a new alliance nor a new platform. Kyndryl and VMware expanded their partnership in November 2021, and managed-services status followed in August 2023, so the relationship is old and the packaging is new,” Gogia pointed out. “What has been announced is scaffolding: consulting, certification, and managed operations built around VMware Cloud Foundation 9.1, with no disclosed financial commitment, no exclusivity, and no named launch customer.”

Gogia said this shows strong interest in private clouds from these two vendors, but he questioned how much enterprise interest exists today in private clouds.

 “No broad enterprise migration from public cloud back to private cloud is visible, and this announcement does not establish that one is needed,” Gogia said. “The defensible reading is selective workload placement. The announcement does not prove that enterprises must shift to private cloud, it proves that Broadcom and Kyndryl want a larger role when enterprises decide where workloads run.”

Justin Greis, CEO of consulting firm Acceligence, disagreed, and said that he found the announcement interesting, “because they are trying to make that private portion of the equation behave more like cloud rather than simply resurrecting the old corporate data center. Automation, policy as code, container support, developer experience, AI inference and agent governance are all part of that proposition.”

However, he said that the boost in personnel is potentially significant. 

“I think the investment in thousands of trained Kyndryl people may ultimately be more consequential than some of the technology language in the announcement,” Greis noted. “Enterprise infrastructure is already incredibly complicated. Add AI agents, multiple models, new governance requirements and hybrid infrastructure, and the skills required to operate all of it become a major constraint. Technology vendors can build increasingly sophisticated platforms, but enterprises still need people capable of turning those platforms into reliable operating environments.”

Shashi Bellamkonda, a principal research director at Info-Tech Research Group, added he saw another element in the statement.

“I see a double-edged irony in this. Broadcom’s post-acquisition VMware pricing is itself what pushed many tech leaders into pain and dependency, and the product it now sells is the antidote,” Bellamkonda said. “VCF, marketed as the route to sovereignty from governments and hyperscalers, leaves buyers just as dependent on Broadcom commercially as they were before. Sovereignty from a jurisdiction is not the same as independence from a vendor.”

This article originally appeared on NetworkWorld.

Mars consolidates complex data infrastructure in hybrid cloud

Brands like Snickers, M&M’s, and Twix are familiar to most consumers, but Mars Inc. doesn’t just produce snacks. The family-owned company, with a revenue of approximately $65 billion, is also one of the largest manufacturers of pet food and ready meals, and its more than 100 production facilities operate around the clock. Of course, this places considerable demands on its IT.

“Our team must ensure that every system, including production lines, runs at maximum performance so we can continuously deliver the products and services our customers value,” says Luciano Batista, the company’s VP of enterprise services delivery.

However, Batista and his team realized that the existing data infrastructure could no longer reliably support operations, especially during peak periods such as Halloween and the pre-Christmas shopping season. So with the support of hybrid, multi-cloud data storage service Everpure, Mars is rebuilding its data and IT infrastructure.

“The Everpure platform met all our requirements,” says Batista. “It’s a scalable platform that futureproofs our operations and integrates seamlessly with our hybrid cloud infrastructure.”

Unified storage environment 

Mars initially consolidated its complex network of storage systems for business-critical databases like Oracle and applications like SAP onto a single Everpure Flash Array system. These software-defined, all-flash storage arrays are available in versions for different workloads, and typical use cases include databases, virtualized environments, SAP applications, and AI and analytics applications. 

Mars has since expanded its flash array infrastructure and now supports mixed workloads, including VMware, Windows, and Linux in areas of production, development, and quality assurance. It also uses Everpure Flash Blade as the basis for the global SAP file system. And while Flash Array is optimized for structured data, the scale-out systems of the Flash Blade series are designed for unstructured information.

“At peak times, Everpure supports up to 300,000 IOPS without any performance degradation,” says Lincoln Silva, product owner for Linux and on-prem storage at Mars. From his perspective, another point speaks favorably of the new platform in that he estimates his team saves approximately three months of planning time thanks to the Evergreen subscription model. This is because the vendor provides regular updates for the storage platform’s hardware and software. As a result, Mars’ IT professionals can focus on more critical tasks. 

Basis for hybrid cloud strategy

Mars also works with choice vendors to implement its approach to cloud. Dedicated local storage capabilities, for instance, are being integrated into Microsoft Azure cloud workloads, which simplifies restore processes and increases resilience.

Snapshots from the local environment can be replicated to the cloud, too. Recovery point objectives (RPEs) of four to 24 hours are available, depending on system priority. “Our success is also the success of our partners,” Batista says. “We embrace a spirit of reciprocity to get the most out of our collaboration.”

The hybrid cloud allows Mars to run VMware workloads and extend its IT infrastructure to the cloud as needed. And the company aims to expand its use of cloud-native applications via Microsoft Azure at a lower cost.

“We’re seeing a data reduction ratio of 18 to one. That’s nine times the expected compression rate,” Batista adds. “This puts us on track to save up to 50% on cloud storage costs. We can now work more efficiently and make better decisions thanks to intelligent solutions and automation.”

Fewer racks and lower power consumption

By consolidating on the flash platform, Mars has also reduced the space requirements and power consumption of its data centers so they only use one sixth of the power, and the number of racks has decreased significantly.

“We’re shaping a sustainable future by changing the way we work,” says Batista. “The decisions we make today will impact the world we leave behind, and Everpure aligns with our commitment to thinking in generations, not just business quarters.”

SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild

Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch.

A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just days after SAP released a patch. The flaw stems from insufficient authorization checks and input validation.

“SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation.” reads the advisory. “Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.”

An unauthenticated attacker can abuse a default authentication client and send crafted input to vulnerable functions, potentially achieving arbitrary code execution and compromising internal components.

Researchers at Defused Cyber observed exploitation attempts against honeypots only three days after the patch was released. The researchers pointed out that this vulnerability has no public PoC and had not been known to be exploited prior to their discovery.

🚨 First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots – 3 days after patch day.

This vulnerability has no public PoC and is not known to be exploited.

View the full payload 👉https://t.co/GXFaqggV8a pic.twitter.com/zMJuo45Ahx

— Defused (@DefusedCyber) August 14, 2026

The attackers behind the current exploitation remain unknown. However, previous critical SAP flaws have been exploited by China-linked APT groups, including UNC5221 and UNC5174, and ransomware gangs.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, SAP Commerce Cloud)

Apple Challenges UK Demand For Access To Encrypted iCloud Data

Apple is challenging a UK order reportedly requiring access to encrypted iCloud data, reviving a wider dispute over privacy, security, and lawful access.

The post Apple Challenges UK Demand For Access To Encrypted iCloud Data appeared first on TechRepublic.

CareCloud Breach Exposes Medical and Financial Data of 345,000

CareCloud disclosed a breach affecting 345,000 people after hackers stole medical and financial data from its AWS-hosted systems.

TechCrunch reports that CareCloud, the New Jersey-based health tech company that stores patient records for more than 45,000 providers across the US, is finally notifying people impacted by a breach the firm first disclosed back in March. New disclosures put the number affected so far at nearly 350,000, and that number is still climbing as more states get their filings.

CareCloud is a U.S. healthcare technology company that provides cloud-based electronic health records (EHR), medical practice management, revenue cycle management, billing, and AI-powered software for hospitals and medical practices. It employs approximately 3,650 people, and reported $120.5 million in revenue and $10.8 million in GAAP net income for fiscal year 2025.

CareCloud handles the kind of data that makes a breach genuinely dangerous rather than just annoying. Doctors’ offices, hospitals, and medical practices around the country feed patient records into its systems, which means a hit on CareCloud is really a hit on everyone those providers see. The company stayed mostly quiet for four months after its initial admission, and it took a batch of state filings to fill in the actual details.

According to a data breach notice filed with California’s attorney general’s office this week, threat actors had access to one of CareCloud’s electronic health record data stores for at least six days, from March 10 to March 16.

“The investigation determined that, between March 10 and March 16, 2026, an unauthorized third party accessed one of CareCloud’s AWS environments and claimed to have exfiltrated data from databases within that environment.” reads the data breach notice. “There is no evidence of unauthorized activity within CareCloud’s environment since March 16, 2026.”

The notice states that an attacker claimed to have exfiltrated data from databases.” CareCloud hasn’t provided technical details about the security breach.

At this time, nobody has publicly claimed responsibility for the attack. What the filings do confirm is the technical detail TechCrunch had already reported back in March: the attackers broke into data storage that CareCloud hosted on Amazon Web Services.

Compromised info may include names, home addresses, and Social Security numbers, along with government ID numbers like passports and driver’s licenses. Bank account details and payment card numbers were exposed too, on top of a substantial amount of medical and health information, the exact combination identity thieves and health insurance fraudsters both want.

In March, Cognizant’s TriZetto Provider Solutions disclosed a breach affecting 3.4 million people, and just last week, billing software provider Craneware confirmed hackers stole a significant volume of data belonging to its hospital and pharmacy clients.

These incidents demonstrate how healthcare data keeps ending up in the wrong hands, and the public usually finds out well after the fact. If there’s a silver lining here, it’s that California’s disclosure rules are the reason we know any of this at all this soon. Without a state forcing the paperwork, “we’ll notify affected patients eventually” would probably still be the entire update.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

AWS Billion-Dollar Software Bug Explained

An AWS software bug showed some customers billing estimates in the billions and trillions. Here is what failed, why invoices were unaffected, and what IT teams should know.

The post AWS Billion-Dollar Software Bug Explained appeared first on TechRepublic.

Apple Sued Over Hide My Email Privacy Claims

Apple faces a proposed class action alleging a Hide My Email flaw could expose users’ real addresses despite the company’s privacy claims.

The post Apple Sued Over Hide My Email Privacy Claims appeared first on TechRepublic.

Azure CLI Password Spray Attack Exposes Microsoft 365 MFA Gap

A password spray campaign targeting Azure CLI sign-ins exposed how narrow Conditional Access policies can leave Microsoft 365 accounts vulnerable even when MFA is enabled.

The post Azure CLI Password Spray Attack Exposes Microsoft 365 MFA Gap appeared first on TechRepublic.

Apple’s £3B iCloud Lawsuit Could Affect 40M UK Users

Apple lost a bid to narrow a UK iCloud lawsuit from Which?, keeping a £3 billion competition claim on track for an October 2028 trial.

The post Apple’s £3B iCloud Lawsuit Could Affect 40M UK Users appeared first on TechRepublic.

❌