Cloud Security Wire
AWS Azure GCP RSS
Featured
AWS Misconfiguration critical

AWS IAM Privilege Escalation: PassRole and CreatePolicyVersion Attack Paths

A deep-dive into two of the most dangerous AWS IAM misconfigurations -- iam:PassRole abuse and iam:CreatePolicyVersion -- with exploitation chains, detection opportunities, and remediation guidance.

By Cloud Security Wire · Read analysis →
Coverage
AWS 47
Azure 39
GCP 30
Total 98

Latest Analysis

View all →
Azure CVE Analysis critical

CVE-2026-69836: Inside the CVSS 10.0 Entra ID Deserialization RCE

Microsoft disclosed a maximum-severity remote code execution flaw in Entra ID caused by unsafe deserialization. No patch is needed on your end, but the incident is a hard reminder to instrument identity logging before the next one isn't silently fixed for you.

Editorial Team ·
Read →
Azure CVE Analysis critical

CVE-2026-62830: When Your AI Ops Agent's Identity Becomes the Attack Path

A missing-authorization flaw in the on-behalf-of flow of Azure SRE Agent let low-privileged attackers inherit the agent's tenant-wide managed identity. CVSS 9.9, no customer patch required, but the incident exposes a new class of risk: autonomous agents holding broad service principal permissions.

Cloud Security Wire ·
Read →
Azure CVE Analysis critical

CVE-2026-50516: Critical Unauthenticated Privilege Escalation in Azure Kubernetes Service

A missing-authentication flaw in Azure Kubernetes Service, disclosed in Microsoft's August 2026 Patch Tuesday, lets an unauthenticated network attacker elevate privileges. CVSS 9.4. Here's what's known, why AKS control-plane CVEs are different from node CVEs, and the hardening steps that reduce blast radius regardless of patch status.

Editorial Team ·
Read →
AWSAzure CVE Analysis critical

CVE-2026-10090: Red Hat ACM Subscription Flaw Turns Namespace Edit Access Into Cluster-Admin

A CVSS 9.9 flaw in Red Hat Advanced Cluster Management's Application Subscription controller lets any user with namespace-scoped edit permissions deploy a malicious Helm chart that grants themselves cluster-admin — with no official patch yet available. Here's the attack chain and how to detect and contain it across AWS, Azure, and GCP-hosted clusters.

Cloud Security Wire ·
Read →
Azure Hardening Guide medium

Azure Policy as a Security Guardrail: Preventing Misconfigurations Across Subscriptions

Azure Policy is one of the most underused security controls in Azure environments. Correctly deployed at management group scope, it prevents the misconfigurations that cause cloud breaches — public storage access, unencrypted disks, open network security groups, and resources deployed without logging. This guide covers the policy effects that matter, the built-in policies worth assigning today, and how to build custom guardrails for organisation-specific requirements.

Cloud Security Wire ·
Read →
Topics
#entra-id#azure-ad#CVE-2026-69836#deserialization#identity-security#conditional-access#sentinel#CWE-502#Azure SRE Agent#CVE-2026-62830#privilege escalation#managed identity#OBO flow#AI agents#CWE-862#Azure Service Bus
Stay informed

Cloud security analysis to your RSS reader.

Subscribe via RSS