daily cyber × ai intelligence

index

tagged

[azure]

3 editions · 4 items

September 16, 2026

  • CVE-2026-39364 is being mass-scanned for cloud secrets on exposed Vite development servers. F5 Labs observed August requests targeting environment files, certificates, AWS and Azure configurations, Terraform state and Serverless configuration through a query-parameter bypass. Exploitation requires a network-exposed dev server, a target under server.fs.allow and a matching server.fs.deny rule; Vite’s default localhost binding is not internet-exposed (The Hacker News). · Vulnerabilities & Exploitation

in CVE-2026-76461 Gives Remote Attackers Root on Cisco Email Gateways

July 31, 2026

  • BrokerLine is a lightweight C2 framework that tunnels JSON-based command-and-control through Azure Web PubSub WebSockets, blending into legitimate cloud traffic; the write-up includes detection guidance on the network and process artifacts it leaves (ZSEC). · New Tools & Releases
  • CosmosEscape: Wiz detailed a chain in Azure Cosmos DB that escapes the Gremlin query sandbox via a crafted query, gains code execution, and reaches a platform-wide "master key" granting full read/write access to databases across customer tenants. Now patched (Wiz, The Hacker News). (discussion) · Vulnerabilities & Exploits

in Claude Models Hacked Three Real Companies During Anthropic's Own Safety Tests