Tag / 6 entries / feed available

Cloud Security

6 of the 76 analyses in Data Breaches carry this tag. All 6 are scored against the four invariants; the matrix below is that evidence.

How this tag scores against the four invariants

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

076

JADEPUFFER Agentic Ransomware Campaign via Langflow CVE-2025-3248 (2026)

Contained by: PEC, EGR

JADEPUFFER exploited an internet-exposed Langflow deployment vulnerable to CVE-2025-3248, then accessed MinIO, PostgreSQL, MySQL, and Alibaba Nacos environments. The operation encrypted exactly 1,342 Nacos configuration items, deleted original tables, and attempted additional database destruction; a later ENCFORGE payload targeted AI and machine-learning files. No victim organization or affected-person count was publicly reported, and the degree of human involvement in the agentic campaign remains unresolved.

054

Microsoft Email Accounts Security Breach

In May 2023, Microsoft suffered a data breach conducted by China-based hackers, Storm-0558, who used forged authentication tokens to access customer email accounts. This breach impacted governmental entities, resulting in the unauthorized access and potential exfiltration of approximately 60,000 unclassified emails, emphasizing the breach’s serious national security implications.

040

Pegasus Airlines Data Exposure

In March 2022, Pegasus Airlines faced a major data breach caused by a cloud misconfiguration of an AWS S3 bucket, resulting in the exposure of approximately 23 million files. The breached data contained Personally Identifiable Information (PII) and sensitive operational details, posing significant risks including identity theft and operational disruptions. No direct external threat actors were confirmed to have exploited this vulnerability.

030

Capital One Data Breach 2019

Prevented by: EGR

In July 2019, Capital One experienced a major breach compromising over 100 million customer records due to a misconfigured Web Application Firewall exploited by a former Amazon Web Services employee. The attack led to unauthorized access to personal information including names, addresses, Social Security Numbers, and banking details, heightening the risk of identity theft and financial fraud. The incident emphasized vulnerabilities in cloud security configurations and poor application of the least privilege principle.

020

2016 Uber Data Breach

Prevented by: HSF

On November 14, 2016, Uber suffered a data breach exposing the personal information of 57 million users and 600,000 driver license numbers. Hackers accessed Uber’s data by exploiting credential mismanagement and accessing unsecured AWS S3 buckets, following infiltration of Uber’s GitHub repositories. The perpetrators, identified as Brandon Charles Glover and Vasile Mereacre, demanded a ransom disguised as a bug bounty program to avoid public disclosure.

014

2014 Uber Data Breach

In 2014, Uber experienced a data breach impacting approximately 50,000 individuals, exposing personal information such as names and driver’s license numbers. Unauthorized access was facilitated through a publicly exposed AWS access key on GitHub, underscoring critical flaws in credential management and cloud security. No specific threat actors were identified, but the incident highlighted significant vulnerabilities in Uber’s data protection practices.

RSS feed for this tag →

Now playing Bandcamp