Crestvale Newsroom

Bucket hijacking silently reroutes cloud audit logs

5 min · Eilen
jakson Bucket hijacking silently reroutes cloud audit logs kansikuva

Kuvaus

A new cloud attack pattern is quietly undermining one of the most trusted parts of your security stack: logging. By deleting and recreating storage buckets, attackers can reroute audit logs without triggering alerts, leaving teams blind while data continues to flow. This matters because detection, response, and forensics all depend on trustworthy telemetry. At the same time, access to advanced AI security models is becoming restricted by governments, creating uneven capabilities across organizations. Add in a breach that disrupted core insurance risk calculations, and the pattern is clear: control over data and tools is becoming a primary risk surface. We also cover consolidation in industrial security, AI orchestration trends, and the rise of automated exploit discovery. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Kommentit

0

Ole ensimmäinen kommentoija

Rekisteröidy nyt ja liity Crestvale Newsroom-yhteisöön!

Aloita maksutta

14 vrk ilmainen kokeilu

Kokeilun jälkeen 7,99 € / kuukausi. · Peru milloin tahansa.

  • Podimon podcastit
  • 20 kuunteluaikaa / kuukausi
  • Lataa offline-käyttöön

Kaikki jaksot

156 jaksot

jakson Bucket hijacking silently reroutes cloud audit logs kansikuva

Bucket hijacking silently reroutes cloud audit logs

A new cloud attack pattern is quietly undermining one of the most trusted parts of your security stack: logging. By deleting and recreating storage buckets, attackers can reroute audit logs without triggering alerts, leaving teams blind while data continues to flow. This matters because detection, response, and forensics all depend on trustworthy telemetry. At the same time, access to advanced AI security models is becoming restricted by governments, creating uneven capabilities across organizations. Add in a breach that disrupted core insurance risk calculations, and the pattern is clear: control over data and tools is becoming a primary risk surface. We also cover consolidation in industrial security, AI orchestration trends, and the rise of automated exploit discovery. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

Eilen5 min
jakson Amazon Q repo bug steals AWS creds kansikuva

Amazon Q repo bug steals AWS creds

AI developer tools and modern supply chains are introducing new paths to credential theft and account compromise. Today's episode focuses on how routine actions like opening a repository or running a build can now trigger silent execution and expose sensitive access. For security and IT leaders, the shift is structural. Trust boundaries are moving closer to developer workflows, build systems, and browser sessions. That means traditional controls like MFA, dependency scanning, and perimeter defenses are no longer enough on their own. The focus needs to move toward execution paths, session integrity, and tighter control over tooling behavior. We also cover a new coordinated effort to secure open source dependencies before they are exploited, along with emerging phishing techniques that render MFA ineffective. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

27. kesä 20266 min
jakson Five Eyes: frontier AI cyber risk soon kansikuva

Five Eyes: frontier AI cyber risk soon

Frontier AI is collapsing the time between vulnerability discovery and exploitation, and security teams are running out of buffer. This episode breaks down the latest warning from Five Eyes cyber agencies and what it means for how quickly organizations need to act. The shift is not about new tools. It is about speed, identity control, and treating cyber risk as a core business function. When attackers can automate discovery and movement, delays in patching and weak access controls become immediate exposure. The episode also explains why credential theft remains the primary entry point for most attacks and how that shapes defensive priorities. We also cover Operation Endgame disrupting infostealer infrastructure, a Cisco SD WAN zero day with control plane impact, and new federal guidance pushing SASE under TIC 3.0. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

25. kesä 20265 min
jakson White House sets 2030, 2031 PQC deadlines kansikuva

White House sets 2030, 2031 PQC deadlines

Post-quantum cryptography just moved from long-term planning into near-term compliance. The US government has set firm deadlines that will ripple across contractors, vendors, and global standards, forcing organizations to confront how little they actually know about their own cryptographic footprint. This matters because most teams are not prepared for the operational side of this shift. Inventorying cryptography, managing keys, and migrating systems under deadline pressure will expose gaps in visibility and control. At the same time, attackers are exploiting identity layers like OAuth tokens and firewall-level credential capture, while AI pushes security teams toward automated patching as the new baseline. Also covered: the Klue breach and OAuth token risk, OpenAI's move into automated remediation, FortiBleed turning firewalls into credential harvesters, and key updates from GitHub, FinCEN, and others. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

24. kesä 20266 min
jakson OpenAI Daybreak moves from bugs to patches kansikuva

OpenAI Daybreak moves from bugs to patches

Security is shifting from finding vulnerabilities to fixing them at machine speed. OpenAI's latest moves signal that automated remediation is becoming the new baseline, not an advantage. For security and IT leaders, this changes how teams should operate. Backlogs are no longer acceptable, and tools that cannot generate and apply fixes will fall behind. At the same time, AI is moving into enforcement layers, supply chain breaches are exposing sensitive data outside traditional perimeters, and a live zero-day in Microsoft Defender highlights how quickly risk can evolve. Also covered: Check Point embedding AI into production defenses, the Tata Electronics breach impacting Apple and Tesla data, and active exploitation trends across widely used platforms. Learn more at https://crestvale.io Support the show [https://www.buzzsprout.com/2602483/support]

23. kesä 20265 min