A deep-dive into two of the most dangerous AWS IAM misconfigurations -- iam:PassRole abuse and iam:CreatePolicyVersion -- with exploitation chains, detection opportunities, and remediation guidance.
Researchers found millions of AWS resources — RDS and DocumentDB snapshots, AMIs, SSM documents — flip to public and back within minutes, invisible to periodic CSPM scans. Here's how to catch these transient exposures with event-driven detection instead.
A pair of path traversal flaws in the community CSI drivers for NFS and SMB let anyone who can create a PersistentVolume delete or overwrite directories anywhere on the backing file server — including other tenants' data on EKS, AKS, and GKE clusters that share storage. Here's how the bug works and how to close it.
A pagination-handling flaw in awslabs.healthlake-mcp-server lets an attacker redirect requests to a malicious endpoint and capture STS credentials via a crafted next_token parameter. Here's how it works and how to lock down MCP servers touching AWS APIs.
Microsoft disclosed a maximum-severity remote code execution flaw in Entra ID caused by unsafe deserialization. No patch is needed on your end, but the incident is a hard reminder to instrument identity logging before the next one isn't silently fixed for you.
A missing-authorization flaw in the on-behalf-of flow of Azure SRE Agent let low-privileged attackers inherit the agent's tenant-wide managed identity. CVSS 9.9, no customer patch required, but the incident exposes a new class of risk: autonomous agents holding broad service principal permissions.
A critical (CVSS 9.9) deserialization-of-untrusted-data flaw in Azure Service Bus let an authenticated attacker execute code over the network. Microsoft patched it server-side in the August 2026 update, but the incident is a good excuse to revisit who can actually publish to your namespaces.
A missing-authentication flaw in Azure Kubernetes Service, disclosed in Microsoft's August 2026 Patch Tuesday, lets an unauthenticated network attacker elevate privileges. CVSS 9.4. Here's what's known, why AKS control-plane CVEs are different from node CVEs, and the hardening steps that reduce blast radius regardless of patch status.
A CVSS 9.9 flaw in Red Hat Advanced Cluster Management's Application Subscription controller lets any user with namespace-scoped edit permissions deploy a malicious Helm chart that grants themselves cluster-admin — with no official patch yet available. Here's the attack chain and how to detect and contain it across AWS, Azure, and GCP-hosted clusters.
TeamPCP has compromised over 60,000 servers by chaining exposed Docker APIs, unsecured Kubernetes control planes, and the React2Shell RCE across AWS and Azure. Here's how the worm spreads and the controls that stop it.