<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cloud Security on Security Blueprints</title>
    <link>https://securityblueprints.io/tags/cloud-security/</link>
    <description>Recent content in Cloud Security on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:44 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/tags/cloud-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>JADEPUFFER Agentic Ransomware Campaign via Langflow CVE-2025-3248 (2026)</title>
      <link>https://securityblueprints.io/data-breaches/jadepuffer-agentic-ransomware-campaign-via-langflow-cve-2025-3248-2026/</link>
      <pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/jadepuffer-agentic-ransomware-campaign-via-langflow-cve-2025-3248-2026/</guid>
      <description>Executive Summary Sysdig’s Threat Research Team published or documented JADEPUFFER on 2026-07-01, assessing it as an end-to-end ransomware operation driven by a large-language-model agent. That date is a publication/documentation date, not an independently established victim-specific compromise date; one source places the activity in late June. The operation began against an internet-exposed Langflow deployment vulnerable to CVE-2025-3248, then reached a separate production environment running MySQL and Alibaba Nacos. No victim organization is publicly identified, and no affected-person count is reported.</description>
    </item>
    <item>
      <title>Microsoft Email Accounts Security Breach</title>
      <link>https://securityblueprints.io/data-breaches/microsoft-email-accounts-security-breach/</link>
      <pubDate>Mon, 01 May 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/microsoft-email-accounts-security-breach/</guid>
      <description>Executive Summary In May 2023, a data breach occurred at Microsoft when China-based hackers, identified as Storm-0558, used forged authentication tokens to gain unauthorized access to customer email accounts. This incident highlighted vulnerabilities in Microsoft&amp;rsquo;s authentication systems and raised concerns over national security implications.&#xA;Key Dates and Timeline Breach Date: May 2023 Discovery Date: June 2023, by the U.S. Department of State source . Public Disclosure Date: April 2024, following a thorough review by the Cyber Safety Review Board source .</description>
    </item>
    <item>
      <title>Pegasus Airlines Data Exposure</title>
      <link>https://securityblueprints.io/data-breaches/pegasus-airlines-data-exposure/</link>
      <pubDate>Tue, 01 Mar 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/pegasus-airlines-data-exposure/</guid>
      <description>Executive Summary Incident Overview In March 2022, Pegasus Airlines faced a data exposure due to a misconfiguration in an AWS S3 bucket by a system administrator. This incident led to the exposure of approximately 23 million files, containing Personally Identifiable Information (PII) and critical operational data (source ).&#xA;Severity of Impact The breach involved 6.5 terabytes of sensitive data, including sensitive operational information, crew identification details, plaintext passwords, secret keys, insurance documents, and safety guidelines.</description>
    </item>
    <item>
      <title>Capital One Data Breach 2019</title>
      <link>https://securityblueprints.io/data-breaches/capital-one-data-breach-2019/</link>
      <pubDate>Wed, 17 Jul 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/capital-one-data-breach-2019/</guid>
      <description>Executive Summary In July 2019, Capital One experienced a significant data breach that compromised over 100 million customer records. This breach occurred due to a server-side request forgery (SSRF) exploiting a misconfigured Web Application Firewall (WAF) in their systems. The attack was orchestrated by Paige A. Thompson, a former software engineer at Amazon Web Services (AWS), leveraging insider knowledge and scanning for vulnerabilities using the misconfigured AWS resources.&#xA;Key Dates Attack Period: March 22-23, 2019 Discovery Date: July 19, 2019 Public Disclosure: July 29, 2019 Severity of Impact This breach ranks among the largest in history, affecting approximately 100 million individuals in the United States and around 6 million in Canada, approximately 106 million individuals combined.</description>
    </item>
    <item>
      <title>2016 Uber Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/2016-uber-data-breach/</link>
      <pubDate>Mon, 14 Nov 2016 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/2016-uber-data-breach/</guid>
      <description>Executive Summary On November 14, 2016, a data breach exposed records of approximately 57 million Uber users and 600,000 driver license numbers. The breach occurred when hackers exploited Uber&amp;rsquo;s systems by using stolen credentials to access its GitHub repository, subsequently gaining entry into an AWS S3 bucket containing sensitive user data such as names, email addresses, and phone numbers. For further details, refer to this source .&#xA;Key Events November 14, 2016: Attackers demanded a ransom for stolen data deletion.</description>
    </item>
    <item>
      <title>2014 Uber Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/2014-uber-data-breach/</link>
      <pubDate>Mon, 12 May 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/2014-uber-data-breach/</guid>
      <description>Executive Summary In 2014, Uber experienced a significant data breach, where approximately 50,000 consumers&amp;rsquo; sensitive information, particularly names and driver&amp;rsquo;s license numbers, was accessed without authorization. This incident arose from the mishandling of an unencrypted Amazon Web Services (AWS) access key that was inadvertently published on GitHub, thereby allowing attackers unauthorized system access. (source , source )&#xA;Key Dates:&#xA;May 12, 2014: Attackers gained access to Uber&amp;rsquo;s AWS account by exploiting a publicly exposed AWS access key on GitHub.</description>
    </item>
  </channel>
</rss>
