Firewall integrations

Fortinet

Elevate the power of your Fortinet Fortigate Firewall using by adding our Intelligence.

Palo Alto

Palo Alto Firewalls can be hardened with our threat intelligence as well.

Sophos XGS

Enhance the Sophos XGS Firewall with our threat intelligence.

OPNsense

Enhance your OPNsense Firewall with our threat intelligence using the native plugin.

SIEM integrations

Splunk

Splunk is a great platform, but without the right Threat Intelligence it's just a log server. Try our threat intelligence today. 

Microsoft Sentinel

One of the most used SIEM solutions should be enriched with the right Intelligence. At Q-Feeds you're at the right place!

Other

Luckily there are many other SIEM vendors whom support 3rd party threat intelligence.

Threat Intelligence Portal

Darkweb Monitoring

Darkweb monitoring is one of our services, not only for threat intelligence but also for you most important assets.

Threat Lookup

With Threat Lookup you get full insights in our IOC database, including full MITRE ATT&K mapping.

External Attack Surface Management

A toolset to check your external facing assets exposed on the internet

Vulnerability Scanner

A comprehensive vulnerability scanner which can scan your infrastructure and web applications

Brand Protection

Protect your brand for look-a-likes and potential phishing attempts

Services

TAXII Feeds & Server Software

TAXII/STIX2.1 standard. Both in form of feeds and server software available

Implementation

Need help with implementations? No worries, we have a strong network of partners who are able to help you.

Solutions

Enrich my SIEM

Elevate the power of your SIEM solution using by adding our Intelligence.

Enrich my Firewall

Firewalls can be hardened with our threat intelligence as well.

Prevent phishing

Enhance your protection against phishing

Achieve compliancy

Achieve compliancy by correlating the best threat intelligence to your logs

Futuristic eye design with circuits and geometric shapes.

Company

About

Read here all about Q-Feeds

News and Updates

Cybersecurity news and updates about us

Publications

All of our media coverage in one place

Become a reseller

Strengthen your portfolio with our comprehensive reseller program

Partner locator

Find our certified partners here

Contact

For all your questions or inquiries

Neural network representation of a human brain

Support

My Account

Access your account and manage your licenses

Downloads & Manuals

On this page you find white papers and manuals

Knowledge base

Our knowledge base full of implementation instructions

Start for free

Start your cyber security intelligence journey here

Abstract geometric wireframe human head

Navigating the global namespace threat: How universal bucket hijacking can compromise cloud data integrity

Jun 23, 2026 | Threat Intelligence Research

Cloud Bucket Hijacking Technique Discovered

Palo Alto Networks has identified a cloud storage vulnerability known as bucket hijacking that affects multiple major cloud service providers. This technique allows attackers to reroute sensitive data from an organization’s active data streams to their own storage environments by exploiting the unique naming conventions of cloud storage buckets.

The research highlights that an attacker can gain access by deleting an existing storage bucket and then immediately recreating it under their own account, thus redirecting data streams without alerting the targeted organization. This risk is inherent in the architectural choices made by cloud service providers, where bucket names are globally unique, exposing a critical security flaw.

The attack process involves compromising a cloud environment to obtain permissions necessary for deleting a storage bucket. Following deletion, the attacker swiftly recreates the bucket under their control, enabling the routing of potentially sensitive logs and critical data to their environment. The research details specific examples, including simulating this attack using Google Cloud Services and AWS, revealing how this method can be applied across platforms.

Defensive Context

Organizations utilizing cloud services must be vigilant about this type of attack, particularly those that depend on data logging and streaming services. Companies that manage sensitive information and utilize services from Google, AWS, or Azure should assess whether their configurations expose them to this vulnerability. Organizations less reliant on cloud storage or that operate on a different architecture may not need to prioritize this issue as closely.

Why This Matters

The bucket hijacking technique can lead to severe data breaches if exploited. Organizations handling sensitive information, especially in regulated sectors such as healthcare and finance, are at risk if their cloud configurations allow this attack. Data that may be redirected includes critical logs, user information, or proprietary business data, potentially leading to compliance breaches or loss of intellectual property.

Defender Considerations

Defending against this technique requires tightly controlled permissions, especially concerning bucket deletion. Organizations should audit their identity access policies to minimize the risk associated with over-privileged roles that grant unnecessary permissions for critical processes. The vulnerability stemmed from the ability to modify data stream configurations without closely monitored permissions, indicating that review mechanisms are essential to prevent unauthorized actions.

Indicators of Compromise (IOCs)

Currently, no specific IOCs have been disclosed in the article. However, organizations should be attuned to any unauthorized changes to storage configurations, particularly deletions or modifications of storage buckets.

Click here for the full article

Try our Intelligence today!

Streamline your security operations with a free Q-Feeds trial and see the difference.

Other articles