Cloud Security Weekly News – Week 11
  1. GitHub repositories are used to Extract PII using information stealer called RisePro (Link)
  2. Security flaws identified by SALT Security in ChatGPT (Link)
    1. First, being ChatGPT allowing vulnerable / malicious plugin to be installed
    2. Second, 0 – click account takeover on plugin’s there by taking control of the account.
    3. Third, Similar to #2 , But manipulating OAuth Redirect.
  3. RCE on windows node within Kubernetes cluster (Link)
  4. Prompt Leakage, Jailbreak and Indirect Injection in Google Gemini , LLM Threats (Link)
  5. Midnight Blizzard had its hand on Microsoft source code and unauthorized access (Link)
  6. Did United Health’s Change Healthcare unit pay $22 Million to  Blackcat and AlphV (Link)
  7. francetravail (governmental agency which registers unemployed people) reported data breach of 43 Million people (Link) . Claims there were no “Passwords and bank details are not affected by this malicious cyber act. There is therefore no risk to compensation.
  8. Microsoft Copilot for Security is generally available on April 1, 2024, with new capabilities (Link) and news was release on 13th March .
  9. Europe approved AI ACT (Link)

Azure security updates

  1. Application Gateway WAF v2 Configuration gets retired (Link)
  2. General availability: Application Gateway for Containers
  3. Azure Application Gateway now supports TLS and TCP protocols (Not can be used for non-HTTP application) (Link)

Leave a comment

I’m Ara

Welcome to Cloud Security Blog, my corner of the internet dedicated to Cloud and AI Security .

Let’s connect