<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Cloud and SaaS Security</title><link>https://cybersecuritytracker.ai/?cats=cloud-saas</link><description>Curated cybersecurity news and vulnerability intelligence.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:50 GMT</lastBuildDate><item><title>Default Azure Automation Setting Enables Cross-Tenant Identity Takeover</title><link>https://darkreading.com/cloud-security/default-azure-automation-setting-cross-tenant-identity-takeover</link><guid isPermaLink="false">cst-3183</guid><description>Microsoft patched a publicly enabled default configuration and code vulnerabilities in Azure Automation that could have allowed attackers to hijack identities across tenants and access other organizations' data, credentials, and workloads. The issue stemmed from overly permissive default settings combined with multiple code flaws in the platform.</description><pubDate>Fri, 24 Jul 2026 12:48:16 GMT</pubDate></item><item><title>Axonius expands Asset Cloud with Cyber Assets and Exposures enhancements</title><link>https://helpnetsecurity.com/2026/07/23/axonius-cyber-assets-exposures</link><guid isPermaLink="false">cst-3062</guid><description>Axonius announced new capabilities for its Asset Cloud platform focused on asset intelligence and exposure management. The updates improve configuration management database (CMDB) visibility, vulnerability response, and extend asset tracking to Internet of Things (IoT) and operational technology (OT) devices.</description><pubDate>Thu, 23 Jul 2026 07:07:42 GMT</pubDate></item><item><title>Building a defense in depth strategy for sensitive data</title><link>https://helpnetsecurity.com/2026/07/23/defense-in-depth-strategy-video</link><guid isPermaLink="false">cst-3056</guid><description>Venkata Pavan Kumar Gummadi from Broadridge describes a defense in depth approach for protecting sensitive data across its lifecycle using multiple coordinated layers. He argues that single controls like disk encryption or data loss prevention (DLP) alone create gaps, and advocates for layered defenses that include data classification to identify sensitive fields such as Social Security numbers.</description><pubDate>Thu, 23 Jul 2026 04:00:12 GMT</pubDate></item><item><title>How Elasticsearch ES|QL COMPLETION turns noisy curl and wget rules into high-fidelity cloud security alerts</title><link>https://elastic.co/security-labs/esql-completion-curl-wget-detection-triage</link><guid isPermaLink="false">cst-3130</guid><description>Elastic Security deployed a detection rule for curl and wget file transfers that uses ES|QL COMPLETION, an LLM-powered triage feature, to filter out legitimate cloud activity before alerts reach analysts. Running the rule on Elastic's production fleet for seven days, the system reduced noise by using deterministic filtering and LLM reasoning to distinguish between expected automation, CI/CD jobs, and potential attacker activity. The approach maintains security visibility for file transfer detection in cloud environments while eliminating false positives that would otherwise overwhelm security teams.</description><pubDate>Thu, 23 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Arista adds AI-driven zero trust to VeloCloud SD-WAN</title><link>https://helpnetsecurity.com/2026/07/22/arista-networks-edge-threat-management</link><guid isPermaLink="false">cst-2990</guid><description>Arista Networks has integrated AI-driven Edge Threat Management (ETM) into its VeloCloud SD-WAN platform to deliver zero trust security at enterprise branch offices. The integration consolidates multiple security appliances into a single unified edge platform, offered as a software upgrade that provides perimeter protection at the wide area network edge.</description><pubDate>Wed, 22 Jul 2026 10:07:27 GMT</pubDate></item><item><title>Snowpick: Open-source ServiceNow exposure scanner</title><link>https://helpnetsecurity.com/2026/07/22/servicenow-data-exposure-snowpick-open-source-scanner</link><guid isPermaLink="false">cst-2980</guid><description>Bishop Fox developed Snowpick, an open-source Go tool that scans ServiceNow instances for exposure to unauthenticated access. During authorized penetration testing across 166 ServiceNow instances, the scanner found 31% were vulnerable and returned records or confirmations to unauthenticated requests. The firm published both the tool and its findings to help organizations identify and remediate this configuration weakness.</description><pubDate>Wed, 22 Jul 2026 05:30:05 GMT</pubDate></item><item><title>LG to Ban Residential Proxies from Smart TV Apps</title><link>https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps</link><guid isPermaLink="false">cst-2970</guid><description>LG Electronics announced plans to suspend smart TV apps that include residential proxy software development kits after research found over 42 percent of apps in its webOS store contained such components. The company is requiring developers to remove proxy functionality or face app suspension, citing that residential proxy networks are not an intended use for smart TVs. Bright Data, a major residential proxy provider, accounts for most of the proxy SDKs found across LG and Samsung smart TV apps.</description><pubDate>Wed, 22 Jul 2026 01:10:38 GMT</pubDate></item><item><title>Agentless Threat Detection: Illuminating Cloud Blind Spots</title><link>https://wiz.io/blog/agentless-visibility-uncovering-cloud-blind-spots</link><guid isPermaLink="false">cst-2949</guid><description>Agentless workload detection represents an approach to identifying threats in cloud environments without deploying agents on individual assets. The method aims to address visibility gaps that arise when monitoring virtual appliances and distributed cloud infrastructure. This technique can help security teams detect threats that traditional agent-based monitoring might miss in complex cloud networks.</description><pubDate>Tue, 21 Jul 2026 13:26:13 GMT</pubDate></item><item><title>Shufti simplifies cross-border compliance with the Glocal Platform</title><link>https://helpnetsecurity.com/2026/07/21/shufti-simplifies-cross-border-compliance-with-the-glocal-platform</link><guid isPermaLink="false">cst-2911</guid><description>Shufti launched the Glocal Platform, a compliance lifecycle management solution that consolidates identity verification, fraud prevention, risk assessment, and regulatory compliance into a single system for global operations. The platform aims to reduce the complexity of managing multiple compliance providers across different regions and regulatory environments.</description><pubDate>Tue, 21 Jul 2026 11:06:36 GMT</pubDate></item><item><title>AWS wants GuardDuty to automate the first steps of threat investigations</title><link>https://helpnetsecurity.com/2026/07/21/amazon-guardduty-investigation-agent-on-demand</link><guid isPermaLink="false">cst-2895</guid><description>Amazon Web Services introduced an AI-powered investigation agent for GuardDuty that automates threat investigation workflows. The feature is in public preview at no additional cost, available in 10 AWS regions, with usage limits of 10 investigations per account per day during the preview period.</description><pubDate>Tue, 21 Jul 2026 09:14:25 GMT</pubDate></item><item><title>On Flock License Plate Tracking Cameras</title><link>https://schneier.com/blog/archives/2026/07/on-flock-license-plate-tracking-cameras.html</link><guid isPermaLink="false">cst-2833</guid><description>Flock Safety's license plate recognition system misidentified a vehicle after police entered an incomplete plate number into the system, leading to the wrongful tracking and arrest of a writer. The company's machine learning matched partial plates to full plates based on law enforcement requests, without requiring additional verification of the complete plate. Additionally, Flock cameras are being used by police departments to track people by physical descriptions rather than vehicles, raising concerns about accuracy and potential for abuse.</description><pubDate>Mon, 20 Jul 2026 11:03:45 GMT</pubDate></item><item><title>The Zoom hack that says, ‘Don’t record me’</title><link>https://techcrunch.com/2026/07/17/the-zoom-hack-that-says-dont-record-me</link><guid isPermaLink="false">cst-2788</guid><description>A commentary on the proliferation of recording and transcription features in video conferencing platforms like Zoom, questioning whether ubiquitous automated transcription and summarization serves practical value or creates information overload.</description><pubDate>Fri, 17 Jul 2026 21:20:47 GMT</pubDate></item><item><title>Amazon fixing bug that billed some AWS customers billions of dollars</title><link>https://techcrunch.com/2026/07/17/amazon-fixing-bug-that-billed-some-aws-customers-billions-of-dollars</link><guid isPermaLink="false">cst-2773</guid><description>Amazon Web Services experienced a billing calculation error that generated inflated bill estimates for some customers, showing charges in the billions of dollars. The company is working to resolve the issue. The error appears to have been temporary and affected bill display rather than actual charges.</description><pubDate>Fri, 17 Jul 2026 15:29:21 GMT</pubDate></item><item><title>Google Bets 'Agentic Defense' Strategy Can Outpace Attackers</title><link>https://darkreading.com/cloud-security/google-bets-agentic-defense-strategy-outpace-attackers</link><guid isPermaLink="false">cst-2761</guid><description>Google Cloud has integrated Wiz capabilities into a platform designed to automate threat detection and remediation using agentic approaches. The integration aims to address emerging AI-driven attacks through automated defense mechanisms.</description><pubDate>Fri, 17 Jul 2026 11:50:25 GMT</pubDate></item><item><title>ValorC3 extends SaaS protection with immutable cloud backups</title><link>https://helpnetsecurity.com/2026/07/16/valorc3-backup-as-a-service-baas</link><guid isPermaLink="false">cst-2685</guid><description>ValorC3 Data Centers released a fully managed backup service for SaaS applications including Microsoft 365, Entra ID, and Salesforce, featuring immutable backup copies to protect against deletion, corruption, and ransomware. The service addresses a common misconception that cloud vendors automatically provide data backup protection. Recent governance research indicates 80% of organizations have encountered at least one cloud security incident.</description><pubDate>Thu, 16 Jul 2026 11:48:49 GMT</pubDate></item><item><title>Here’s the Truth About Whether Meta’s NameTag Face Recognition Tech ‘Exists’</title><link>https://wired.com/story/heres-the-truth-about-whether-metas-nametag-face-recognition-exists</link><guid isPermaLink="false">cst-2639</guid><description>Meta executives have provided conflicting statements about whether the company's NameTag facial recognition system exists following WIRED's reporting on the technology. The company's public messaging has created confusion regarding the status and nature of the project.</description><pubDate>Wed, 15 Jul 2026 20:58:16 GMT</pubDate></item><item><title>Understanding Claude Tag’s access model in Slack and how to configure it securely</title><link>https://tenable.com/blog/claude-tag-slack-access-model</link><guid isPermaLink="false">cst-2608</guid><description>Anthropic's Claude Tag is a Slack AI agent that operates using admin-configured shared credentials rather than individual user credentials, following a service-identity pattern similar to deploy bots and workflow automations. Access to connected services is controlled by admin-configured bundles at the workspace or channel level, with organization-wide controls governing who can direct the agent. Channel members can collaborate with Claude, but their participation does not grant new permissions beyond what the admin bundle defines.</description><pubDate>Wed, 15 Jul 2026 15:08:00 GMT</pubDate></item><item><title>The Risk of Exposed Cloud Functions and How to Harden</title><link>https://cloud.google.com/blog/topics/threat-intelligence/exposed-cloud-functions-harden</link><guid isPermaLink="false">cst-2607</guid><description>Mandiant security assessments identify publicly exposed serverless applications and functions lacking authentication that frequently contain vulnerabilities in custom code or third-party packages. Successful exploitation of application-level flaws like local file inclusion or command injection can grant attackers remote code execution and container-level access, which may lead to lateral movement and cloud environment compromise. The article describes attack scenarios and hardening strategies for securing serverless deployments that must remain publicly accessible.</description><pubDate>Wed, 15 Jul 2026 14:00:00 GMT</pubDate></item><item><title>Investigating Persistence Mechanisms in AWS</title><link>https://rapid7.com/blog/post/dr-investigating-aws-persistence-mechanisms</link><guid isPermaLink="false">cst-2587</guid><description>This article examines AWS persistence mechanisms that attackers use to maintain long-term access after gaining initial compromise. It details how adversaries create or modify IAM users, add credentials and permissions, and provides detection logic and investigation workflows using CloudTrail logs to identify these hidden footholds. The guidance includes LEQL query examples to hunt for suspicious IAM user creation and modification activity.</description><pubDate>Wed, 15 Jul 2026 13:00:00 GMT</pubDate></item><item><title>Virtual Event Today: Cloud &amp; Data Security Summit</title><link>https://securityweek.com/virtual-event-today-cloud-data-security-summit</link><guid isPermaLink="false">cst-2574</guid><description>SecurityWeek is hosting a virtual event focused on cloud and data security where attendees can network with solution providers and peers managing similar cloud security challenges.</description><pubDate>Wed, 15 Jul 2026 12:52:10 GMT</pubDate></item><item><title>Radware adds cloud intelligence to DefensePro X for web DDoS defense</title><link>https://helpnetsecurity.com/2026/07/15/radware-defensepro-x-cloud-augmented-protection</link><guid isPermaLink="false">cst-2580</guid><description>Radware extended its DefensePro X platform with cloud-augmented protection architecture that combines AI-powered cloud algorithms with local traffic inspection and mitigation. The initial offering, Cloud Web DDoS Protection, improves detection and characterization of application-layer DDoS attacks without requiring organizations to route traffic through the cloud.</description><pubDate>Wed, 15 Jul 2026 12:16:27 GMT</pubDate></item><item><title>Nudge Security automates detection of risky OAuth grants and browser extensions</title><link>https://helpnetsecurity.com/2026/07/15/nudge-security-agentic-capabilities</link><guid isPermaLink="false">cst-2583</guid><description>Nudge Security released automated agents that identify and remediate malicious or high-risk OAuth grants and browser extensions across enterprise environments. The agents continuously monitor these attack surfaces, flag risky configurations, and enable automated remediation with human approval. This capability extends Nudge Security's existing Vendor Risk Analyst agent.</description><pubDate>Wed, 15 Jul 2026 11:51:27 GMT</pubDate></item><item><title>SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.</title><link>https://thehackernews.com/2026/07/sase-has-ai-blind-spot-inspecting.html</link><guid isPermaLink="false">cst-2569</guid><description>Secure Access Service Edge (SASE) platforms that rely solely on packet inspection are insufficient for modern enterprise environments where workflows span SaaS applications, browsers, and generative AI tools. Traditional cloud proxy routing approaches fail to detect risks from unsanctioned extensions, autonomous agents, and employee actions like sharing intellectual property within these new workflow paradigms.</description><pubDate>Wed, 15 Jul 2026 11:50:01 GMT</pubDate></item><item><title>New Webinar: Closing the Approval Gap in AI-Era Ad Tech</title><link>https://thehackernews.com/2026/07/new-webinar-closing-approval-gap-in-ai.html</link><guid isPermaLink="false">cst-2571</guid><description>A webinar discusses the approval gap in ad technology where authorized marketing tags can load unapproved third-party code with access to sensitive customer data and transaction pages. The presentation outlines how this gap develops and provides guidance for security teams to address it proactively.</description><pubDate>Wed, 15 Jul 2026 11:06:57 GMT</pubDate></item><item><title>AWS retools Security Hub for AI and multicloud threats</title><link>https://helpnetsecurity.com/2026/07/15/aws-security-hub-ai-workload-protection</link><guid isPermaLink="false">cst-2558</guid><description>AWS expanded its Security Hub platform to include AI workload protection capabilities and native monitoring for Microsoft Azure environments, with plans to support additional cloud platforms. The update aims to help organizations contextualize and act on security findings more rapidly across multicloud deployments.</description><pubDate>Wed, 15 Jul 2026 08:56:09 GMT</pubDate></item><item><title>Fortinet adds AI controls and data loss prevention to FortiEndpoint</title><link>https://helpnetsecurity.com/2026/07/15/fortinet-fortiai-assist</link><guid isPermaLink="false">cst-2560</guid><description>Fortinet announced new AI visibility, control, and data loss prevention capabilities integrated into its FortiEndpoint unified endpoint platform. The additions include endpoint risk scoring, AI-assisted security operations, and features to govern AI usage and reduce sensitive data exposure across distributed environments.</description><pubDate>Wed, 15 Jul 2026 07:47:57 GMT</pubDate></item><item><title>Product showcase: Trust Chain TPRM turns vendor compliance evidence into verified assurance</title><link>https://helpnetsecurity.com/2026/07/15/product-showcase-strike-graph-trust-chain-tprm</link><guid isPermaLink="false">cst-2561</guid><description>Strike Graph launched Trust Chain, an AI-native third-party risk management platform that evaluates vendor compliance through submitted evidence rather than self-reported questionnaires. The solution uses Strike Graph's Verify AI technology to test submissions against an organization's specific requirements, delivering verified assurance instead of vendor attestation.</description><pubDate>Wed, 15 Jul 2026 07:30:16 GMT</pubDate></item><item><title>OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials</title><link>https://thehackernews.com/2026/07/oauth-client-id-spoofing-lets-attackers.html</link><guid isPermaLink="false">cst-2479</guid><description>Security researchers identified threat actors using OAuth client ID spoofing to enumerate and validate stolen credentials against Microsoft Entra ID without triggering sign-in logs. The technique bypasses standard telemetry detection, allowing attackers to confirm compromised credentials while evading defender alerts.</description><pubDate>Tue, 14 Jul 2026 11:21:35 GMT</pubDate></item><item><title>Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads</title><link>https://thehackernews.com/2026/07/grok-build-uploads-entire-git.html</link><guid isPermaLink="false">cst-2463</guid><description>xAI's Grok Build coding CLI tool was uploading complete Git repositories, including full commit history, to xAI's Google Cloud Storage infrastructure rather than only the specific files needed for a task. A researcher discovered this behavior while testing version 0.2.93 and was able to recover files from an intercepted upload that the agent had been instructed not to access.</description><pubDate>Tue, 14 Jul 2026 09:02:48 GMT</pubDate></item><item><title>Chatto: Open-source team messenger with privacy at its core</title><link>https://helpnetsecurity.com/2026/07/14/chatto-self-hosted-chat-app-privacy</link><guid isPermaLink="false">cst-2461</guid><description>Chatto is an open-source team messaging application that enables organizations to host their own chat infrastructure rather than using commercial platforms. The software aims to provide privacy and control by keeping message data on operator-controlled infrastructure, with installation simplified through a single executable binary.</description><pubDate>Tue, 14 Jul 2026 04:30:51 GMT</pubDate></item><item><title>Defending SaaS-based applications against ShinyHunters OAuth abuse</title><link>https://microsoft.com/en-us/security/blog/2026/07/13/defending-saas-based-applications-against-shinyhunters-oauth-abuse</link><guid isPermaLink="false">cst-2451</guid><description>Microsoft identified ShinyHunters-associated threat actors conducting campaigns from mid-2025 to mid-2026 that abused OAuth relationships to compromise Salesforce and other SaaS applications across retail, education, and manufacturing sectors. The attackers used voice phishing to trick users into authorizing malicious apps, exploited supply chain compromises in third-party integrations like Salesloft, and leveraged misconfigured guest access to gain persistence and exfiltrate customer relationship management data. These intrusion paths operated within legitimate OAuth workflows, allowing the threat actors to inherit user privileges and evade conventional authentication detection without exploiting any Salesforce vulnerability.</description><pubDate>Mon, 13 Jul 2026 22:02:41 GMT</pubDate></item><item><title>Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID</title><link>https://microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id</link><guid isPermaLink="false">cst-2441</guid><description>Microsoft Entra ID will make passkeys the default authentication method beginning September 1, 2026, automatically enrolling users currently using SMS or voice authentication. SMS and voice authentication will be retired as native Microsoft Entra capabilities on February 1, 2027, though organizations can continue using these methods through third-party telecom partners via the Microsoft Security Store at additional cost.</description><pubDate>Mon, 13 Jul 2026 17:00:00 GMT</pubDate></item><item><title>Cloudflare Precursor uses continuous behavioral analysis to stop advanced bots</title><link>https://helpnetsecurity.com/2026/07/13/cloudflare-precursor</link><guid isPermaLink="false">cst-2422</guid><description>Cloudflare announced general availability of Precursor, a bot management tool that uses continuous behavioral analysis running in web browsers to detect sophisticated bot automation in real time. The system monitors entire user sessions rather than relying on static CAPTCHAs, aiming to catch advanced bots while minimizing disruption to legitimate users.</description><pubDate>Mon, 13 Jul 2026 13:28:04 GMT</pubDate></item><item><title>Lumen expands managed detection and response with Cortex XSIAM integration</title><link>https://helpnetsecurity.com/2026/07/13/lumen-defender-amdr</link><guid isPermaLink="false">cst-2405</guid><description>Lumen Technologies announced Lumen Defender Advanced Managed Detection and Response for Palo Alto Networks Cortex XSIAM, combining its managed detection and response capabilities with threat intelligence from Black Lotus Labs and Cortex XSIAM's AI-driven security operations platform. The service aims to help enterprises modernize security operations and manage the accelerating threat landscape.</description><pubDate>Mon, 13 Jul 2026 13:17:25 GMT</pubDate></item><item><title>Why IaC Coverage Belongs on Your Security Dashboard</title><link>https://wiz.io/blog/iac-coverage-security-dashboard</link><guid isPermaLink="false">cst-2430</guid><description>Infrastructure as Code (IaC) coverage represents a funnel that tracks what portion of an organization's infrastructure is governed, traceable, and ready for rapid remediation. The article proposes reconceptualizing IaC coverage as a key security metric that should appear alongside other indicators on security dashboards.</description><pubDate>Mon, 13 Jul 2026 12:34:03 GMT</pubDate></item><item><title>Fake OAuth client IDs are helping attackers slip past sign-in logs</title><link>https://helpnetsecurity.com/2026/07/13/entra-id-oauth-client-id-spoofing</link><guid isPermaLink="false">cst-2406</guid><description>Attackers conducting account enumeration against Microsoft cloud tenants are spoofing OAuth client IDs to evade detection in sign-in logs. By using fake identifiers in authentication requests, the attackers' probing activity avoids appearing in the normal telemetry that Microsoft Entra ID records. Microsoft and operators are working to address this detection gap.</description><pubDate>Mon, 13 Jul 2026 12:10:50 GMT</pubDate></item><item><title>FastNetMon eliminates third-party bgp lookups with Netomics</title><link>https://helpnetsecurity.com/2026/07/13/fastnetmon-netomics</link><guid isPermaLink="false">cst-2392</guid><description>FastNetMon launched Netomics, a self-hosted platform that consolidates BGP routing intelligence, including live routing data, registry information, RPKI validation, routing history, and AI-assisted querying. The tool is designed for ISPs, cloud providers, Internet Exchange Points, and enterprises to gain visibility into global internet routing without relying on external lookup services. Network engineers can investigate routing incidents and validate prefixes from a single application.</description><pubDate>Mon, 13 Jul 2026 09:27:07 GMT</pubDate></item><item><title>Claude Code users keep 50% higher limits until July 19</title><link>https://helpnetsecurity.com/2026/07/13/claude-code-weekly-limits-promotion-extended</link><guid isPermaLink="false">cst-2393</guid><description>Anthropic has extended a promotional offer that grants Claude Code users on Pro, Max, and Team plans 50% higher weekly usage limits through July 19, 2026. After the promotion concludes, usage limits will revert to standard levels without affecting plan terms or costs. Free and consumption-based Enterprise plans are excluded from the offer.</description><pubDate>Mon, 13 Jul 2026 09:06:55 GMT</pubDate></item><item><title>Enterprises are rethinking where their AI applications run</title><link>https://helpnetsecurity.com/2026/07/13/colocation-for-ai-workloads-report</link><guid isPermaLink="false">cst-2376</guid><description>Enterprises are reassessing infrastructure choices for AI applications based on compute, power, cooling, and latency requirements. Public cloud remains popular for experimentation and fast deployment, while colocation facilities are gaining adoption for workloads demanding predictable performance and dedicated resources. More than half of surveyed organizations have implemented or are upgrading AI technologies.</description><pubDate>Mon, 13 Jul 2026 04:00:45 GMT</pubDate></item><item><title>OpenAI temporarily relaxes GPT-5.6 Sol usage limits</title><link>https://bleepingcomputer.com/news/artificial-intelligence/openai-temporarily-relaxes-gpt-56-sol-usage-limits</link><guid isPermaLink="false">cst-2375</guid><description>OpenAI has temporarily eased usage restrictions on GPT-5.6 Sol, its most advanced model, in response to exceptionally high demand over the previous two days. The adjustment allows more users to access the system while the company manages capacity constraints.</description><pubDate>Mon, 13 Jul 2026 00:44:44 GMT</pubDate></item><item><title>AWS gives its ERP agent deny-by-default rules and a separate identity</title><link>https://helpnetsecurity.com/2026/07/10/aws-agentic-ai-erp-automation</link><guid isPermaLink="false">cst-2305</guid><description>AWS has released enhancements to its ERP agent that include deny-by-default authorization rules and a separate identity mechanism. These improvements aim to address security concerns while allowing the agent to automate exception handling in enterprise resource planning workflows across finance operations.</description><pubDate>Fri, 10 Jul 2026 05:00:52 GMT</pubDate></item><item><title>How ProdSec uses Wiz</title><link>https://wiz.io/blog/how-prodsec-uses-wiz</link><guid isPermaLink="false">cst-2275</guid><description>This article appears to be promotional content about how Wiz, a cloud security platform, supports product security workflows. The piece lacks substantive details about specific capabilities, findings, or actionable insights for practitioners.</description><pubDate>Thu, 09 Jul 2026 16:20:08 GMT</pubDate></item><item><title>AWS centralizes access, spending, and governance for Claude</title><link>https://helpnetsecurity.com/2026/07/09/aws-claude-apps-gateway-governance</link><guid isPermaLink="false">cst-2231</guid><description>AWS released Claude apps gateway, a self-hosted control plane that centralizes access, cost tracking, and policy management for Claude Code and Claude Desktop across organizations. The gateway replaces per-developer credentials and manual configuration distribution, and works with both Amazon Bedrock and Claude Platform on AWS.</description><pubDate>Thu, 09 Jul 2026 08:37:07 GMT</pubDate></item><item><title>Lone Attacker Uses AI to Breach AWS Cloud Environment in 72 Hours</title><link>https://darkreading.com/cloud-security/lone-attacker-ai-breach-aws-cloud-environment</link><guid isPermaLink="false">cst-2195</guid><description>A solo attacker leveraged artificial intelligence workflows, chained multiple cloud misconfigurations, and compromised credentials to breach an Amazon Web Services (AWS) customer environment and conduct extortion within 72 hours. The incident demonstrates how AI tooling combined with cloud security gaps and credential theft can rapidly escalate attacks.</description><pubDate>Wed, 08 Jul 2026 20:32:22 GMT</pubDate></item><item><title>Censys Internet Map links real-time DNS data to internet infrastructure</title><link>https://helpnetsecurity.com/2026/07/08/censys-internet-map-links-real-time-dns-data-to-internet-infrastructure</link><guid isPermaLink="false">cst-2177</guid><description>Censys has expanded its Internet Map platform to integrate real-time DNS visibility, enabling security teams to pivot between domains, DNS records, and infrastructure details in a single interface. The addition consolidates workflows that previously required multiple datasets and tools into one cohesive platform.</description><pubDate>Wed, 08 Jul 2026 13:45:21 GMT</pubDate></item><item><title>FalconStor Cloud Clean Room enables validated recovery without dedicated infrastructure</title><link>https://helpnetsecurity.com/2026/07/08/falconstor-cloud-clean-room-enables-validated-recovery-without-dedicated-infrastructure</link><guid isPermaLink="false">cst-2160</guid><description>FalconStor introduced Cloud Clean Room, an on-demand platform for validated recovery testing within isolated secure enclaves, built on its zero trust secure enclave technology. The platform starts each test from a known state to avoid carrying over issues from previous recovery exercises. The standalone infrastructure can be deployed across multiple use cases and integrated by third-party vendors.</description><pubDate>Wed, 08 Jul 2026 13:10:24 GMT</pubDate></item><item><title>DNSFilter makes its DNS threat protection available to OEM partners</title><link>https://helpnetsecurity.com/2026/07/08/dnsfilter-oem-program</link><guid isPermaLink="false">cst-2161</guid><description>DNSFilter launched an original equipment manufacturer (OEM) program allowing ISPs, cybersecurity firms, device makers, and application developers to integrate its DNS threat protection, domain analysis, and privacy capabilities into their own offerings. Partners can choose between Protective DNS for DNS-layer filtering and threat blocking, Guardian Firewall and VPN services for device-wide encryption and privacy, or both products bundled together.</description><pubDate>Wed, 08 Jul 2026 12:46:07 GMT</pubDate></item><item><title>Wiz ASM for any environment, any risk, everywhere</title><link>https://wiz.io/blog/wiz-asm-auto-recon</link><guid isPermaLink="false">cst-2167</guid><description>Wiz announced new features for its Attack Surface Management (ASM) platform, including auto-reconnaissance capabilities, deep internal context analysis, and a Red Agent tool designed to identify risks across different environments.</description><pubDate>Wed, 08 Jul 2026 12:19:24 GMT</pubDate></item><item><title>Automox MCP Server adds visual reviews and AI-driven patch policy creation</title><link>https://helpnetsecurity.com/2026/07/08/automox-mcp-server-2-2</link><guid isPermaLink="false">cst-2142</guid><description>Automox released MCP Server 2.2, which adds visual review interfaces, automated patch policy creation based on severity, and real-time capability discovery for endpoint management. The update enables IT teams to review and approve endpoint operations through an agentic interface with improved governance controls beyond natural language interaction alone.</description><pubDate>Wed, 08 Jul 2026 09:21:45 GMT</pubDate></item><item><title>ScienceLogic adds geographic service visibility to Skylar One</title><link>https://helpnetsecurity.com/2026/07/08/sciencelogic-adds-geographic-service-visibility-to-skylar-one</link><guid isPermaLink="false">cst-2144</guid><description>ScienceLogic has released the Kyoto update for Skylar One, its observability platform, adding geographic service visibility, simplified location and device management, and enhanced relationship mapping. The update targets organizations managing hybrid infrastructure, cloud environments, and AI workloads, with improvements to service issue investigation, location access management, and platform scalability.</description><pubDate>Wed, 08 Jul 2026 08:56:13 GMT</pubDate></item></channel></rss>