Cloud Security

Swiss officials urged to avoid US hyperscale clouds

A Swiss National Flag waves as a pedestrian crosses the dreirosenbruecke or three roses Bridge in Basel,Switzerland. Swiss privacy law applies to all global users of a Swiss-based service, not just those in the region.(Photo by Michele Tantussi/Getty Images)

In a major data security alert, Switzerland's Privacy Conference has formally recommended that Swiss public bodies avoid using major US-based hyperscale cloud and SaaS platforms, citing significant sovereignty and legal risks, reports The Register. The resolution specifically states that services like Microsoft 365 are inappropriate for handling sensitive or confidential data, arguing they do not offer true end-to-end encryption and are subject to foreign laws like the US CLOUD Act.

The resolution asserts, "The use of SaaS applications therefore entails a significant loss of control," as providers can unilaterally change terms. In separate security news, an engineer's scan of 5.6 million public GitLab repositories uncovered 17,000 live secrets, including thousands of credentials for Google Cloud, AWS, and OpenAI, at a cost of $770. Meanwhile, fitness app Strava is updating its terms to absolve itself of risks related to users oversharing location data, which has previously exposed military personnel and officials.

Additionally, an investigation into leaked documents suggests Iran's "Charming Kitten" hacking group is involved in sophisticated operations, including assassination targeting. Reports also indicate the Israeli military may ban Android phones for senior officers.

An In-Depth Guide to Cloud Security

Get essential knowledge and practical strategies to fortify your cloud security.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds