Cloud Security
10 articles RSS
Chrome and Firefox Retire DigiCert's G1 Root Certificates, Closing the Book on a Two-Decade-Old WebPKI Anchor
On April 15, 2026, Mozilla and Google removed DigiCert's legacy G1 root certificates from their trust stores, forcing holdouts on legacy chains to reissue TLS certificates or face untrusted errors.
Back-to-Back API Security Reports Reveal That 92 Percent of Organizations Cannot Defend Their AI Agents as Authenticated Attacks Dominate the Threat Landscape
Salt Security and KushoAI release dueling reports on the same day showing API security has become the critical blind spot of the agentic AI era, with nearly all attacks now originating from authenticated sources.
IoT Security Regulation Accelerates on Both Sides of the Atlantic as NIST Rewrites Federal Guidance and the EU CRA's First Deadline Approaches
NIST is overhauling its IoT cybersecurity guidance for federal agencies while the EU Cyber Resilience Act's first enforcement deadline in September 2026 forces manufacturers to build vulnerability reporting infrastructure from scratch.
Passkeys Gain Regulatory Momentum as India Mandates Two-Factor Authentication and NIST Formalizes Syncable Credentials
India's Reserve Bank enforces mandatory two-factor authentication for all digital payments from April 1, while NIST's updated identity guidelines and Microsoft's passwordless-by-default accounts mark a coordinated global shift toward phishing-resistant authentication.
Kubescape 4.0 Graduates Runtime Threat Detection to GA and Introduces Security Scanning for AI Agents on Kubernetes
The CNCF incubating project ships runtime threat detection powered by CEL-based rules, a centralized security metadata store, and the first open-source controls for auditing AI agent configurations in Kubernetes clusters.
Signal Begins Enforcing Its Post-Quantum Triple Ratchet as the First Messaging App to Offer Continuous Quantum-Resistant Encryption
Signal's SPQR protocol adds a quantum-safe ratchet alongside the Double Ratchet, with server-side enforcement now rolling out to new accounts.
Iranian Drone Strikes on AWS Data Centers Mark the First Wartime Attack on Hyperscale Cloud Infrastructure
Iranian drones struck three AWS facilities in the UAE and Bahrain, knocking two availability zones offline and challenging the cloud industry's core resilience assumptions.
RSAC 2026 Reveals an Industry Racing to Secure AI Agents It Has Barely Begun to Deploy
The cybersecurity industry's largest conference was dominated by agentic AI security products, even as data shows only 5 percent of enterprises have moved AI agents into production.
AWS European Sovereign Cloud Goes Live, but CLOUD Act Shadow Looms Over €7.8 Billion Promise
Amazon launched its AWS European Sovereign Cloud in Brandenburg, Germany in January 2026 with €7.8 billion in investment and ~90 services, but legal experts warn the U.S. CLOUD Act may undermine its core sovereignty guarantees.
Single Threat Actor Behind 50 Corporate Breaches Using Stolen Cloud Credentials
Threat actor exploited infostealer-harvested passwords to breach enterprise file-sharing platforms at major companies lacking MFA protection.