
ServiceNow patches three critical AI Platform flaws
Three maximum-severity flaws make verified patch evidence—not assumptions about automatic cloud updates—the immediate priority for every ServiceNow platform owner.
Cloud incidents often combine identity, configuration and data exposure. Follow verified developments across cloud and SaaS platforms, with practical context for access controls, visibility, data protection and shared responsibility.

Three maximum-severity flaws make verified patch evidence—not assumptions about automatic cloud updates—the immediate priority for every ServiceNow platform owner.

Because NGINX often sits directly in front of critical web and API services, this vulnerability deserves both patching and exposure review.

AWS firewall hit counts may help identify quiet stateful rules, but the capability is unverified and does not cover stateless rules or justify automatic deletion.

Attackers are increasingly moving identity phishing into collaboration services that employees already trust. Palo Alto Networks Unit 42 documented campaigns using platforms such as Microsoft Teams, Slack and…

Microsoft corrected an Azure Cosmos DB security issue that researchers said could have exposed customer database credentials across tenant boundaries. Cosmos DB is a managed cloud database used…

The Bank of England, PRA and FCA have begun supervising four major cloud and technology providers whose disruption could threaten UK financial stability.

Accenture confirmed an isolated security incident after a threat actor offered 35GB of allegedly stolen data for sale. The attacker claimed the dataset included source code, RSA and…

On May 18, 2026, KrebsOnSecurity reported that cisa administrator exposed government cloud keys on public github. The account describes a concrete security, privacy or fraud consequence rather than…

Rockstar confirmed limited company-data access through a third-party breach while rejecting the broader impact implied by attackers’ extortion claims.

Snowflake customers faced exposure after integration-provider token theft. BleepingComputer documented the development in April 2026. SecBriefs checked the central claim against a primary record or genuinely independent reporting…

Eye Security’s 2026 report, as reported by CSO Online, highlights identity abuse, passwords, and familiar attack methods as continuing security concerns.

A new Eye Security report says identity-based attacks dominate, with password-related incidents and misuse of legitimate accounts central to the trend.

A reported Fortinet zero-day bypasses FortiCloud single sign-on authentication, with exploitation noted before patches were available for several products.

A cybersecurity firm says a Restic-related clue led it to cloud storage that helped 12 US companies recover data encrypted by INC ransomware.