<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Cloud</title><description>Attacks against cloud identity and productivity platforms — Microsoft 365, Google Workspace, Azure, AWS — including OAuth consent phishing, device-code abuse, token theft, and the &quot;identity-first&quot; intrusion patterns that treat the tenant, not the endpoint, as the ground floor. Combined article + CVE feed for the Cloud beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>Fortune 500 Firms Named in Azure Data Theft Claim</title><link>https://0daynews.com/articles/2026-08-17-fortune-500-azure-data-theft-campaign/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-17-fortune-500-azure-data-theft-campaign/</guid><description>Threat actor claims mass exfiltration from McDonald&apos;s, TCS, Vodafone, and other Fortune 500 firms via Azure. Named companies have not confirmed. Story developing.</description><pubDate>Mon, 17 Aug 2026 07:30:00 GMT</pubDate><category>Cloud</category><category>article</category></item><item><title>Beacon CRM Breach Hits 1,000+ Charities via AWS Key</title><link>https://0daynews.com/articles/2026-08-14-beacon-crm-breach-charities-aws-key/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-beacon-crm-breach-charities-aws-key/</guid><description>Over 1,000 UK charities had supporter data exposed after attackers used an AWS access key found in Beacon&apos;s public JavaScript build artifacts.</description><pubDate>Fri, 14 Aug 2026 10:00:00 GMT</pubDate><category>Cloud</category><category>article</category></item><item><title>Azure CosmosEscape Flaw Exposed Any Tenant&apos;s Database</title><link>https://0daynews.com/articles/2026-07-30-azure-cosmos-db-cosmosescape-cross-tenant/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-30-azure-cosmos-db-cosmosescape-cross-tenant/</guid><description>Wiz&apos;s CosmosEscape attack chain escaped Azure Cosmos DB&apos;s Gremlin sandbox, gained platform code execution, and extracted a key granting cross-tenant read/write access. Now patched.</description><pubDate>Thu, 30 Jul 2026 20:00:00 GMT</pubDate><category>Cloud</category><category>article</category></item><item><title>NodeBB Patches Eight AI-Found High-Severity Flaws</title><link>https://0daynews.com/articles/2026-07-24-nodebb-eight-ai-found-flaws-admin-access/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-nodebb-eight-ai-found-flaws-admin-access/</guid><description>Eight high-severity NodeBB flaws expose admin access and private chats in all pre-4.14.0 versions. Aikido Security&apos;s AI pentest found them in six hours. Patch to 4.14.2.</description><pubDate>Fri, 24 Jul 2026 11:30:00 GMT</pubDate><category>Cloud</category><category>article</category></item><item><title>AI Agents Uncover Redis Zero-Days, Seven Patches Ship</title><link>https://0daynews.com/articles/2026-07-24-kimi-k3-redis-zero-days-rce-patches/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-kimi-k3-redis-zero-days-rce-patches/</guid><description>Kimi K3 AI agents found authenticated RCE flaws in four Redis versions. Redis shipped seven security releases on July 23 — update your deployments.</description><pubDate>Fri, 24 Jul 2026 10:00:00 GMT</pubDate><category>Cloud</category><category>article</category></item><item><title>FedRAMP 20x Ends Point-in-Time Authorization</title><link>https://0daynews.com/articles/2026-07-23-fedramp-20x-rev5-transition-continuous-monitoring-loop/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-fedramp-20x-rev5-transition-continuous-monitoring-loop/</guid><description>FedRAMP 20x moves federal cloud authorization from periodic 3PAO assessments to continuous, machine-readable control evidence — what that shift requires from cloud operators.</description><pubDate>Thu, 23 Jul 2026 15:00:00 GMT</pubDate><category>Cloud</category><category>article</category></item><item><title>NadMesh botnet raids exposed AI tools for 3,811 AWS keys</title><link>https://0daynews.com/articles/2026-07-18-nadmesh-go-botnet-shodan-comfyui-ollama-3811-aws-keys/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-18-nadmesh-go-botnet-shodan-comfyui-ollama-3811-aws-keys/</guid><description>A Go botnet called NadMesh, active since early July, feeds a Shodan queue into ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio. Operator dashboard claims 3,811 AWS keys.</description><pubDate>Sat, 18 Jul 2026 16:15:00 GMT</pubDate><category>Cloud</category><category>article</category></item><item><title>AWS persistence: four patterns to hunt after an incident</title><link>https://0daynews.com/articles/2026-07-15-rapid7-blazek-aws-persistence-iam-lambda-federated-hunt-runbook/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-rapid7-blazek-aws-persistence-iam-lambda-federated-hunt-runbook/</guid><description>Rapid7&apos;s Jan Blažek maps four AWS persistence classes — new IAM users, assume-role edits, Lambda backdoors, federated tokens — with the CloudTrail signals to hunt for each.</description><pubDate>Wed, 15 Jul 2026 19:15:00 GMT</pubDate><category>Cloud</category><category>article</category></item><item><title>Miggo: RabbitMQ leaked OAuth secret via obsolete endpoint</title><link>https://0daynews.com/articles/2026-07-14-rabbitmq-miggo-oauth-secret-cross-tenant-cve-2026-57219/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-14-rabbitmq-miggo-oauth-secret-cross-tenant-cve-2026-57219/</guid><description>Miggo disclosed two RabbitMQ flaws today: an obsolete /api/auth endpoint exposed the broker&apos;s OAuth client secret, and a bug bypassed vhost boundaries.</description><pubDate>Tue, 14 Jul 2026 16:20:00 GMT</pubDate><category>Cloud</category><category>article</category></item><item><title>CISA postmortem: nine alerts ignored, six months exposed</title><link>https://0daynews.com/articles/2026-07-13-cisa-github-leak-postmortem-nine-alerts-six-months/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-13-cisa-github-leak-postmortem-nine-alerts-six-months/</guid><description>CISA&apos;s postmortem on its own six-month GitHub credential leak faults slow key rotation and nine ignored GitGuardian alerts — signal without intake.</description><pubDate>Mon, 13 Jul 2026 16:15:00 GMT</pubDate><category>Cloud</category><category>article</category></item><item><title>WriteOut: One Preview Link Took Over Writer AI Accounts</title><link>https://0daynews.com/articles/2026-07-08-writeout-writer-ai-cross-tenant-session-sand-security/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-08-writeout-writer-ai-cross-tenant-session-sand-security/</guid><description>SAND Security&apos;s WriteOut let a Writer AI agent preview link steal a signed-in user&apos;s session cookie across tenants. Writer has patched — the pattern hasn&apos;t.</description><pubDate>Wed, 08 Jul 2026 22:45:00 GMT</pubDate><category>Cloud</category><category>article</category></item><item><title>GitLost: Public Issue Leaks Private GitHub Repo Data</title><link>https://0daynews.com/articles/2026-07-08-gitlost-github-agentic-workflows-noma-security-private-repos/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-08-gitlost-github-agentic-workflows-noma-security-private-repos/</guid><description>Noma Security&apos;s GitLost shows how a public GitHub issue can trick Agentic Workflows into leaking private repos. Not patchable — scope your agent tokens today.</description><pubDate>Wed, 08 Jul 2026 11:15:00 GMT</pubDate><category>Cloud</category><category>article</category></item><item><title>Dialogflow&apos;s Rogue Agent Flaw Is a Very Old Bug Class</title><link>https://0daynews.com/articles/2026-07-08-dialogflow-cx-rogue-agent-shared-exec-varonis/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-08-dialogflow-cx-rogue-agent-shared-exec-varonis/</guid><description>Varonis&apos; Rogue Agent finding in Google Dialogflow CX is a shared-runtime exec() escape — a bug class old enough to have graduated shared hosting.</description><pubDate>Wed, 08 Jul 2026 08:15:00 GMT</pubDate><category>Cloud</category><category>article</category></item><item><title>Umbrij: ToddyCat Hijacks Gmail OAuth via Browser</title><link>https://0daynews.com/articles/2026-07-04-toddycat-umbrij-oauth-gmail-kaspersky/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-04-toddycat-umbrij-oauth-gmail-kaspersky/</guid><description>Kaspersky Securelist detailed Umbrij, a ToddyCat post-compromise tool that self-grants Google Workspace OAuth tokens by driving a logged-in Chromium session. Nothing to patch. Plenty to audit.</description><pubDate>Sat, 04 Jul 2026 07:20:00 GMT</pubDate><category>Cloud</category><category>article</category></item><item><title>ARToken PhaaS Targets M365 Device-Code Phishing</title><link>https://0daynews.com/articles/2026-07-04-artoken-eviltokens-m365-device-code-phishing-talos/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-04-artoken-eviltokens-m365-device-code-phishing-talos/</guid><description>Cisco Talos exposed ARToken, a React-panel phishing-as-a-service tied to EvilTokens. Device code flow is the mechanic. Conditional Access is the fix, and most tenants still haven&apos;t turned it on.</description><pubDate>Sat, 04 Jul 2026 06:20:00 GMT</pubDate><category>Cloud</category><category>article</category></item><item><title>ConsentFix + ClickFix: M365 Grants Outlive Resets</title><link>https://0daynews.com/articles/2026-07-04-consentfix-clickfix-m365-oauth-consent-phishing/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-04-consentfix-clickfix-m365-oauth-consent-phishing/</guid><description>BleepingComputer covered two M365 hijack patterns and Opera&apos;s Paste Protect defense this week. The clipboard lane can be closed. The OAuth grant substrate underneath is unchanged.</description><pubDate>Sat, 04 Jul 2026 04:15:00 GMT</pubDate><category>Cloud</category><category>article</category></item><item><title>Unpatched Argo CD Flaw Lets Unauth Cluster Takeover</title><link>https://0daynews.com/articles/2026-07-03-argo-cd-repo-server-unauth-rce-unpatched/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-03-argo-cd-repo-server-unauth-rce-unpatched/</guid><description>Synacktiv disclosed an unpatched code-execution flaw in Argo CD&apos;s repo-server component. No fix, no CVE. Reachability of the internal port is the whole game.</description><pubDate>Fri, 03 Jul 2026 18:15:00 GMT</pubDate><category>Cloud</category><category>article</category></item></channel></rss>