AWS Bedrock Guardrails Now Feed Into Security Lake

🟡 Medium | Source: AWS Security Blog AWS has introduced an integration that routes Amazon Bedrock Guardrails intervention events — such as blocked prompt injections and PII redactions — directly into Amazon Security Lake. This allows security teams to query AI safety events alongside existing identity, network, and application telemetry in a unified data store. The capability improves visibility into AI-related threats and simplifies incident investigation for organisations deploying generative AI workloads. ...

6 August 2024 Â· ZX Cloud Security

Apple iCloud Private Relay IP Leak via WebKit Bypass

🟡 Medium | Source: The Hacker News A security flaw in Apple’s iCloud Private Relay allows a user’s real IP address to be exposed through WebKit proxy bypass techniques, undermining the privacy guarantees of the service. iCloud Private Relay, available since iOS 15, is designed to anonymise Safari traffic by routing it through two separate relay hops so no single party can identify the user’s origin. This bypass defeats that protection, potentially allowing websites or threat actors to correlate user identities and locations. ...

6 August 2024 Â· ZX Cloud Security

Ransom Cartel Creator Sentenced to 16 Years in Prison

🟡 Medium | Source: The Hacker News Maksim Silnikau, the creator of the Ransom Cartel ransomware-as-a-service (RaaS) platform, has been sentenced to 16 years in federal prison for orchestrating attacks against at least 18 organisations between 2021 and 2023. Ransom Cartel operated as a subscription-style criminal enterprise, enabling affiliates to deploy ransomware without building their own tooling. The conviction is a significant law enforcement milestone, demonstrating that RaaS operators face serious long-term legal consequences. ...

6 August 2024 Â· ZX Cloud Security

OpenAI Bans ChatGPT Accounts in Cambodia Scam Network

🟡 Medium | Source: The Hacker News OpenAI has banned a coordinated network of ChatGPT accounts linked to a Cambodia-based fraud operation in Poipet, which was using generative AI to power investment scams, romance fraud, gambling schemes, and impersonation of law enforcement. The operation is believed to originate from Southeast Asia, a region increasingly associated with large-scale, technology-enabled fraud compounds. This highlights the growing abuse of legitimate AI platforms to automate and scale social engineering attacks. ...

5 August 2024 Â· ZX Cloud Security

AI Fuels Record $20M Microsoft Bug Bounty Programme

🟡 Medium | Source: The Register — Security Microsoft’s bug bounty programme is on course for a record $20 million payout, driven in part by AI-assisted vulnerability research and expanded bounty scope. Researchers are increasingly using AI tools to discover and report flaws at greater speed and volume, raising the bar for both hunters and defenders. This signals a broader shift in how vulnerabilities are found and disclosed across major cloud and software platforms. ...

4 August 2024 Â· ZX Cloud Security

CAF Bank Online Service Restored After 10-Day Outage

🟡 Medium | Source: The Register — Security CAF Bank has restored online banking services after more than ten days of downtime, though customers have been warned that further outages and traffic throttling may occur. The extended disruption raises questions about the resilience and incident recovery capabilities of the bank’s underlying infrastructure. For a financial institution, prolonged unavailability of customer-facing services signals significant gaps in business continuity planning or points to a serious underlying incident. ...

4 August 2024 Â· ZX Cloud Security

AI Fake CVEs Pollute Vulnerability Database Pipeline

🟡 Medium | Source: The Register — Security AI-generated fake vulnerability reports are increasingly polluting the CVE pipeline, creating noise that makes it harder for security teams to identify genuine threats. With NIST still working through a significant backlog in the National Vulnerability Database, there is limited capacity to catch and filter out bogus submissions. This undermines trust in a critical piece of global security infrastructure that practitioners rely on for patch prioritisation. ...

3 August 2024 Â· ZX Cloud Security

UK Gov Investment Arm Leaks Staff Contacts for 40 Hours

🟡 Medium | Source: The Register — Security A UK government investment body exposed an internal file containing officials’ contact details for approximately 40 hours after an employee failed to follow established security policy. The data was publicly accessible during that window, constituting a personal data breach likely reportable under UK GDPR. While no cloud-specific vulnerability was involved, the incident highlights persistent risks from misconfigured access controls on internal documents. Security Architect’s Take: Review your organisation’s data classification and access control policies for internal management files stored on cloud platforms or collaboration tools — ensure default sharing settings are restrictive, and implement automated posture checks (e.g. CSPM rules) that alert on publicly accessible files containing personal or sensitive data. ...

3 August 2024 Â· ZX Cloud Security

Claude Opus 5 Leads on Prompt Injection Resistance

🟡 Medium | Source: Schneier on Security Anthropic’s Claude Opus 5 model demonstrates significantly improved resistance to indirect prompt injection (IPI) attacks, reducing attacker success rates to 2.0% within 15 attempts compared to over 20% for the best-performing GPT 5.6 variant. Prompt injection is a key attack vector against AI-powered applications, where malicious instructions embedded in external content attempt to hijack model behaviour. These benchmark results matter because organisations deploying LLMs in agentic or automated workflows face real exposure if their chosen model is susceptible. ...

31 July 2024 Â· ZX Cloud Security

AI Agent Security Risks: Anthropic vs OpenAI

🟡 Medium | Source: The Register — Security Both Anthropic and OpenAI are deploying increasingly autonomous AI agents capable of taking independent actions across systems, raising serious concerns about unintended or adversarial behaviour. The competitive pressure between the two firms appears to be accelerating capability development at the expense of safety guardrails. This matters because agentic AI systems with broad permissions can cause significant damage if they act outside intended boundaries, whether through misuse, prompt injection, or emergent misbehaviour. ...

31 July 2024 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options