#cloudSe
prepare thyself and witnessest mine fattest cloudse *fucks up and starts coughing really badly*
July 12, 2026 at 8:44 PM
📰 TrustSink: Penyedia MFA Eksternal Nakal Bisa Mencuri Password Saat Login Microsoft Entra

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/09/23/trustsink-microsoft-entra-rogue-mfa-provider-curi-password/

#accountTakeover #authentication #authenticationPolicyAdministrator #cloudSe
September 23, 2026 at 5:57 AM
Job #1: CloudBoost: This Job let you work remotely on your own schedule: Register here: dailycashflow.my.canva.site

Job #2: Passive Investing with CloudSE. 100% Passive Income Register: tr.ee/wJbajB

Job #3: Daily Trading with CloudEx: 🔥 Earn over $20,000 in just 30 days: Register: tr.ee/8oxrX8
Blue, Light Grey, and Orange Colorful UI Education Bio-Link Website
dailycashflow.my.canva.site
July 13, 2025 at 6:07 PM
Multi-agent AI on Google Cloud: identity, network control & data boundaries matter 🔥💡 #ai #cloudsecurity #devops

https://medium.com/google-cloud/how-to-secure-multi-agent-ai-workflows-on-google-cloud-in-2026-396eb901db64
May 10, 2026 at 5:09 AM
It's almost leg day!
#art #woodcut #hplff #horror #monster
September 19, 2024 at 6:37 PM
BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA
A phishing-as-a-service operation targeting Microsoft 365 users has harvested thousands of session cookies that could be used to hijack authenticated sessions after victims complete multifactor authentication, CloudSEK said. The cybersecurity firm said in a report that it uncovered the operation, known as BigBear 2.0, in June after gaining access to its administrative panel. The panel contained 5,137 credential records linked to 461 targeted organizations across more than 40 countries. CloudSEK also reported 4,148 captured session cookies and 1,032 plaintext passwords. The firm said 474 records showed completed logins in which attackers captured the authenticated session created after MFA. BigBear 2.0 is built on Evilginx2, a framework that places an attacker-controlled reverse proxy between the victim and Microsoft’s legitimate authentication service. The victim signs in through the proxied page and completes MFA as usual. Once Microsoft issues an authenticated session cookie, the phishing infrastructure can intercept it and allow the attacker to reuse the session without completing the authentication process again. The operation also uses residential proxies selected according to the victim’s country, which can make malicious authentication traffic appear geographically consistent with the user. CloudSEK said this technique can weaken location-based checks used in Conditional Access policies. Researchers also found custom code designed to disable FIDO2/WebAuthn authentication on the phishing pages, potentially steering users toward weaker, phishable authentication methods. CloudSEK described BigBear 2.0 as a multi-user service with at least five identified affiliate operators. The company said it observed 42 virtual private server (VPS) nodes over the campaign, with 26 deleted from the panel since late July. IT services and managed service providers accounted for 151 of the organizations identified by CloudSEK, making them the most heavily represented sector in its data. Such organizations can present especially valuable targets because employees may hold privileged access to customer environments and administrative systems. ## Session theft moves into the mainstream The significance of BigBear 2.0 is not just its ability to capture authenticated sessions after MFA, but the way it packages techniques once associated with more skilled attackers into a service that can be used at scale, said Keith Prabhu, founder and CEO of Confidis. The underlying technique is not new, said Akshat Tyagi, associate practice leader at HFS Research. “What BigBear 2.0 changes is accessibility and scale,” Tyagi said. “It packages AiTM phishing, residential proxies and automated cookie replay into a service that lowers the expertise needed to run these attacks.” That shift means enterprises need to think beyond protecting the authentication event itself, he said, because a captured session may give an attacker access to Microsoft 365 without another password or MFA challenge. Prabhu added that successful MFA should no longer be treated as proof that an account or session remains secure. Session cookies and access and refresh tokens should be treated as high-value authentication material rather than technical artifacts behind the password, said Sakshi Grover, senior research manager for cybersecurity products and services at IDC Asia Pacific. The risk, she said, is that many enterprise controls are still geared toward detecting credential theft rather than the hijacking of an already authenticated session. ## Phishing-resistant authentication becomes critical OTP, SMS, and push-based MFA should not be relied on as standalone defenses against this type of attack, Tyagi said, because the attacker can allow the legitimate user to complete authentication before stealing the resulting session. Tyagi said enterprises should enforce phishing-resistant authentication such as FIDO2/WebAuthn passkeys rather than merely making it available alongside weaker alternatives. Prabhu pointed to Windows Hello for Business and certificate-based authentication as additional options, with stronger methods enforced through Conditional Access authentication strengths. Grover said organizations should also use Continuous Access Evaluation and token protection where Microsoft 365 supports them, but cautioned against treating token protection as a complete solution because coverage varies across platforms, clients and workloads. The problem is also operational, Grover said. Identity and access tools are not always sufficiently integrated with security operations or SIEM platforms, leaving potentially useful identity signals disconnected from the analysts responsible for detecting attacks. ## Password resets are not enough “Treat the event as an active session compromise, not merely a stolen-password incident,” Prabhu said. He recommended disabling or containing the affected account, revoking Entra sign-in sessions and refresh tokens, and forcing reauthentication. Incident responders should then examine Microsoft 365 logs for evidence of mailbox access, malicious inbox rules, unusual OAuth consent, newly registered MFA devices, privilege changes, and access to other cloud applications. Tyagi cautioned that IP location may provide limited reassurance in such investigations because residential proxies can make attacker activity appear geographically consistent with the legitimate user. Responders should instead focus on reconstructing what occurred during the compromised session, he said. Investigators should also determine whether the stolen session was used to reach other employees, customers, or external contacts, Prabhu added. Grover said organizations should also include session hijacking in tabletop exercises, testing how identity, security operations, messaging, and cloud teams would coordinate during an authenticated-session compromise. Such exercises can expose gaps that may not emerge in simulations centered on conventional credential theft or ransomware, she said.
www.csoonline.com
September 8, 2026 at 4:13 PM
BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA
A phishing-as-a-service operation targeting Microsoft 365 users has harvested thousands of session cookies that could be used to hijack authenticated sessions after victims complete multifactor authentication, CloudSEK said. The cybersecurity firm said in a report that it uncovered the operation, known as BigBear 2.0, in June after gaining access to its administrative panel. The panel contained 5,137 credential records linked to 461 targeted organizations across more than 40 countries. CloudSEK also reported 4,148 captured session cookies and 1,032 plaintext passwords. The firm said 474 records showed completed logins in which attackers captured the authenticated session created after MFA. BigBear 2.0 is built on Evilginx2, a framework that places an attacker-controlled reverse proxy between the victim and Microsoft’s legitimate authentication service. The victim signs in through the proxied page and completes MFA as usual. Once Microsoft issues an authenticated session cookie, the phishing infrastructure can intercept it and allow the attacker to reuse the session without completing the authentication process again. The operation also uses residential proxies selected according to the victim’s country, which can make malicious authentication traffic appear geographically consistent with the user. CloudSEK said this technique can weaken location-based checks used in Conditional Access policies. Researchers also found custom code designed to disable FIDO2/WebAuthn authentication on the phishing pages, potentially steering users toward weaker, phishable authentication methods. CloudSEK described BigBear 2.0 as a multi-user service with at least five identified affiliate operators. The company said it observed 42 virtual private server (VPS) nodes over the campaign, with 26 deleted from the panel since late July. IT services and managed service providers accounted for 151 of the organizations identified by CloudSEK, making them the most heavily represented sector in its data. Such organizations can present especially valuable targets because employees may hold privileged access to customer environments and administrative systems. ## Session theft moves into the mainstream The significance of BigBear 2.0 is not just its ability to capture authenticated sessions after MFA, but the way it packages techniques once associated with more skilled attackers into a service that can be used at scale, said Keith Prabhu, founder and CEO of Confidis. The underlying technique is not new, said Akshat Tyagi, associate practice leader at HFS Research. “What BigBear 2.0 changes is accessibility and scale,” Tyagi said. “It packages AiTM phishing, residential proxies and automated cookie replay into a service that lowers the expertise needed to run these attacks.” That shift means enterprises need to think beyond protecting the authentication event itself, he said, because a captured session may give an attacker access to Microsoft 365 without another password or MFA challenge. Prabhu added that successful MFA should no longer be treated as proof that an account or session remains secure. Session cookies and access and refresh tokens should be treated as high-value authentication material rather than technical artifacts behind the password, said Sakshi Grover, senior research manager for cybersecurity products and services at IDC Asia Pacific. The risk, she said, is that many enterprise controls are still geared toward detecting credential theft rather than the hijacking of an already authenticated session. ## Phishing-resistant authentication becomes critical OTP, SMS, and push-based MFA should not be relied on as standalone defenses against this type of attack, Tyagi said, because the attacker can allow the legitimate user to complete authentication before stealing the resulting session. Tyagi said enterprises should enforce phishing-resistant authentication such as FIDO2/WebAuthn passkeys rather than merely making it available alongside weaker alternatives. Prabhu pointed to Windows Hello for Business and certificate-based authentication as additional options, with stronger methods enforced through Conditional Access authentication strengths. Grover said organizations should also use Continuous Access Evaluation and token protection where Microsoft 365 supports them, but cautioned against treating token protection as a complete solution because coverage varies across platforms, clients and workloads. The problem is also operational, Grover said. Identity and access tools are not always sufficiently integrated with security operations or SIEM platforms, leaving potentially useful identity signals disconnected from the analysts responsible for detecting attacks. ## Password resets are not enough “Treat the event as an active session compromise, not merely a stolen-password incident,” Prabhu said. He recommended disabling or containing the affected account, revoking Entra sign-in sessions and refresh tokens, and forcing reauthentication. Incident responders should then examine Microsoft 365 logs for evidence of mailbox access, malicious inbox rules, unusual OAuth consent, newly registered MFA devices, privilege changes, and access to other cloud applications. Tyagi cautioned that IP location may provide limited reassurance in such investigations because residential proxies can make attacker activity appear geographically consistent with the legitimate user. Responders should instead focus on reconstructing what occurred during the compromised session, he said. Investigators should also determine whether the stolen session was used to reach other employees, customers, or external contacts, Prabhu added. Grover said organizations should also include session hijacking in tabletop exercises, testing how identity, security operations, messaging, and cloud teams would coordinate during an authenticated-session compromise. Such exercises can expose gaps that may not emerge in simulations centered on conventional credential theft or ransomware, she said. _The article originally appeared on CSO._
www.computerworld.com
September 9, 2026 at 6:42 AM
Google Cloud Gemini Enterprise faces a CRITICAL flaw (CVE-2026-1727) exposing sensitive data through predictable bucket names. Update to post-Dec 12, 2025 version & audit your buckets now! https://radar.offseq.com/threat/cve-2026-1727-cwe-200-exposure-of-sensitive-inform-c82534e3 #OffSeq #CloudSe...
CVE-2026-1727: CWE-200 Exposure of Sensitive Information to an Unauthorized Acto
CVE-2026-1727 is a vulnerability classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) affecting Google Cloud Gemini Enterprise (formerly Agentspace). The root cause lies in the use of predictable Google Clou
radar.offseq.com
February 7, 2026 at 12:30 PM
Assistenza centralini telefonici Aastra a Pordenone:soluzione definitiva con centralino cloudSe stai cercando assistenza centralini telefonici Aastra a Pordenone, probabilmente il tuo sistema telefonico aziendale sta
https://www.telefonia.business/2026/03/18/assistenza-centralino-aastra-a-pordenone/
March 28, 2026 at 12:18 AM
Cloudsek Off-campus Drive 2025 hiring Software Development Engineer | Bachelor’s Degree Cloudse...

https://fresherjoblist.learnsoftechs.com/cloudsek-off-campus-drive-2025-hiring-software-development-engineer/

#New #Jobs #Bachelor's #Jobs #BE/BTech #Jobs #Blog #Fresher #job #list #Fresher […]
Original post on fresherjoblist.learnsoftechs.com
fresherjoblist.learnsoftechs.com
May 5, 2025 at 2:52 PM
Pendant in the form of a Dragon, 1027–775 BCE, Late Western Zhou dynasty. Calcified yellowish green jade with gray-brown and brown cloudse, 6.35 x 2.54 x 0.48 cm. Bequest of Alfred F. Pillsbury, 50.46.231 © Minneapolis Institute of Art
March 7, 2026 at 8:07 PM
Cloudse
February 9, 2025 at 4:16 AM
CloudSense Training - CloudSense Online Training - Certified Expert

www.techmunus.com/page/cloudse...
June 2, 2026 at 7:11 AM
Exciting insights from Check Point's latest report! 🌥️ AI is transforming cloud security, and it's time for organizations to embrace Zero Trust strategies to tackle new threats. Stay secure! #CloudSecurity #ZeroTrust

https://whois-secure.com/blog/check-point-report-ai-cloud-security
June 11, 2026 at 9:41 PM
☁️ Amazon launches Security Hub Extended
• Unified security solution with partner integrations
• Pre-negotiated pricing, single bill, and Level 1 support
#AWS #CloudSe

https://aws.amazon.com/blogs/aws/aws-security-hub-extended-offers-full-stack-enterprise-security-with-curated-partner-solutions/
February 28, 2026 at 10:00 PM