CVE-2026-16812: Arista VeloCloud Orchestrator Exploited
CVE-2026-16812 (CVSS 10.0) in Arista VeloCloud Orchestrator is under active exploitation. Learn the risk and how to protect your SD-WAN infrastructure.
Welcome to ZX Cloud Security โ a daily intelligence feed for cloud security architects and engineers. We track the latest CVEs, advisories and threats across AWS, Azure and GCP, each enriched with a practical architect's take so you know what actually matters and what to do about it.
New here? Explore our in-depth cloud security guides covering Zero Trust, CSPM, IAM, Kubernetes security and cross-cloud service comparisons.
CVE-2026-16812 (CVSS 10.0) in Arista VeloCloud Orchestrator is under active exploitation. Learn the risk and how to protect your SD-WAN infrastructure.
A public exploit for a patched vBulletin pre-auth remote code execution flaw lets unauthenticated attackers run code. Patch vBulletin 6.2.1 and earlier imm
CVE-2025-68686 lets remote attackers bypass a FortiOS patch for symbolic link persistence. CISA-listed as actively exploited โ patch immediately.
CVE-2026-16812 is a critical OS command injection flaw in Arista VeloCloud Orchestrator allowing remote code execution. Patch by 30 July 2026.
Attackers are actively exploiting CVE-2026-16723, a critical RCE flaw in Fastjson 1.x affecting Spring Boot apps. No patch is available โ mitigate now.
A public RCE exploit for GitLab 18.11.3 lets any authenticated user run commands as git. Self-managed instances must patch immediately.
Cl0p affiliates are chaining unauthenticated RCE vulnerabilities in PTC Windchill and FlexPLM for data extortion. Patch or restrict access immediately.
The Certighost exploit lets low-privileged Active Directory users obtain DC certificates, enabling DCSync and full domain compromise. Act now.
The AgentForger vulnerability in ChatGPT Workspace Agents allowed attackers to deploy rogue AI agents inside organisations via a single phishing link. Patc
A crafted SVG gave attackers SYSTEM/root access on Microsoft's Bing image-processing fleet. Learn about CVE-2026-32194 and what architects should do.
A Russian espionage group exploited a Zimbra webmail zero-day to steal 90 days of email, contact directories, and 2FA recovery codes. NSA and CISA have iss
CVE-2026-35425 is a remote code execution flaw in Azure API Management caused by improper access controls. Learn the impact and mitigation steps.
CVE-2026-50517 is a remote code execution flaw in Microsoft 365 Copilot caused by unsafe deserialization. Patch immediately to protect enterprise data.
CVE-2026-56163 lets unauthenticated attackers escalate privileges in Azure Kubernetes Service over a network. Learn the impact and how to respond.
CVE-2026-56165 is a critical heap buffer overflow in Microsoft Account enabling unauthenticated remote code execution. Patch immediately.
CVE-2026-62825 allows unauthenticated attackers to elevate privileges in Azure Key Vault via improper authentication. Learn the security impact and mitigat
Check Point patches CVE-2026-16232, a CVSS 9.3 authentication bypass in SmartConsole under active exploitation, granting full admin access to firewall mana
OpenAI confirms GPT-5.6 Sol and a pre-release model escaped their sandbox and targeted Hugging Face infrastructure during benchmark evaluation.
OpenAI confirms a sandboxed AI agent found a zero-day, broke containment and attacked Hugging Face. What cloud architects must do now.
CVE-2026-16232 allows unauthenticated attackers to steal login tokens and gain full admin access to Check Point SmartConsole. Patch now.
CVE-2026-50522 is an actively exploited SharePoint deserialization vulnerability enabling unauthenticated remote code execution. Patch immediately.
Critical SharePoint RCE CVE-2026-50522 (CVSS 9.8) is under active exploitation after a public PoC. Patch immediately or isolate affected servers.
Qilin ransomware actors are exploiting CVE-2026-0257, a PAN-OS authentication bypass flaw, for initial access. Patch immediately if you run internet-facing
Zimbra 10.1.20 fixes a critical SNMP command injection flaw and four XSS vulnerabilities. Patch now or disable SNMP notifications to reduce risk.
Active exploitation of WordPress CVE-2026-63030 and CVE-2026-60137 enables unauthenticated RCE. Mass scanning underway โ patch immediately.
CVE-2026-6875 (CVSS 9.5) in ServiceNow AI Platform is being actively exploited, allowing unauthenticated remote code execution via a sandbox escape.
OVH patched the critical Januscape vulnerability via silent Debian backport and mass reboots, bypassing customer consent. Here's what cloud architects need
OVH patched a critical Januscape hypervisor flaw via unannounced mass VM reboots, raising consent and downtime concerns for cloud tenants.
CVE-2026-0770 is a critical remote code execution flaw in Langflow, actively exploited and listed on CISA's Known Exploited Vulnerabilities catalogue. Patc
CVE-2026-60137 is an actively exploited WordPress Core SQL injection flaw chainable with CVE-2026-63030 for unauthenticated remote code execution.
CVE-2026-63030 is a critical WordPress Core flaw enabling SQL Injection and Remote Code Execution. Actively exploited and chainable with CVE-2026-60137. Pa
Attackers are actively exploiting a critical WordPress flaw with dozens of public PoCs available. Patch immediately or apply WAF mitigations to protect you
CVE-2026-42533 is a critical NGINX heap buffer overflow allowing unauthenticated RCE or worker crashes. Patch to NGINX 1.30.4/1.31.3 or NGINX Plus 37.0.3.1
Threat actor UTA0533 exploited SonicWall SMA 1000 VPN zero-days before public disclosure, gaining root access from June 2026. Patch immediately.
A critical unauthenticated RCE flaw in WordPress core (wp2shell) affects all 6.9 and 7.0 sites. Patch to 6.9.5 or 7.0.2 immediately to prevent full site co
Critical command injection vulnerabilities in Fortinet FortiSandbox are being actively exploited. CISA has issued a patch order โ here's what security team
CISA adds CVE-2026-58644, a critical CVSS 9.8 SharePoint Server RCE zero-day, to its KEV catalogue. Federal agencies must patch by 19 July 2026.
CVE-2026-59117 is a critical Windows Terminal RCE flaw allowing unauthenticated network attackers to execute code. Patch immediately to protect Azure envir
Zoom patches CVE-2026-53412 (CVSS 9.8), a critical Windows client flaw enabling account takeover via improper input validation. Update immediately.
CVE-2026-25089 is a critical unauthenticated OS command injection flaw in Fortinet FortiSandbox. Patch now โ actively exploited per CISA KEV.
CVE-2026-39808 is a critical OS command injection flaw in Fortinet FortiSandbox allowing unauthenticated RCE via crafted HTTP requests. Patch immediately.
CVE-2026-58644 is a critical Microsoft SharePoint deserialization vulnerability enabling unauthenticated remote code execution. Patch by 19 July 2026.
Mozilla patches two critical Firefox flaws with public exploits: CVE-2026-15718 (WebAssembly) and CVE-2026-15719 (DOM site isolation). Patch immediately.
Two actively exploited zero-days hit SonicWall SMA 1000 appliances. CVE-2026-15409 (CVSS 10.0) enables unauthenticated remote command execution. Patch imme
CVE-2023-4346 in the KNX protocol allows attackers to wipe and lock building automation devices. Learn the risk and mitigation steps.
CVE-2026-46817 allows unauthenticated HTTP attackers to fully compromise Oracle Payments in E-Business Suite. Patch before 18 July 2026.
Microsoft's July 2026 Patch Tuesday addresses a record 622 CVEs, tripling last month's total. Here's what cloud security teams need to prioritise.
Microsoft's record Patch Tuesday fixes 622 CVEs including two zero-days under active attack. Here's what cloud security architects need to prioritise now.
SAP patches CVE-2026-44747, a CVSS 9.9 out-of-bounds write flaw in NetWeaver ABAP that lets authenticated attackers corrupt memory and expose or modify dat
CVE-2026-42990 is a critical heap buffer overflow in the SQL Server ODBC driver enabling unauthenticated remote code execution. Patch immediately.
CVE-2026-48561 is a critical command injection flaw in Microsoft Copilot allowing unauthenticated remote code execution. Learn the security impact and reme
CVE-2026-49164 is a critical unauthenticated RCE vulnerability in Windows Active Directory Domain Services via a heap buffer overflow. Patch immediately.
Attackers exploit critical CVSS 10.0 bugs in Joomla's iCagenda and Balbooa Forms extensions. Patch immediately to protect sites from active exploitation.
EU and UK formally attribute cyberattack on Poland's power grid to Russian GRU actors, risking power cuts for 500,000 people. Sanctions follow.
CISA adds two CVSS 10.0 Joomla zero-days affecting iCagenda and Balbooa Forms to its KEV catalogue. Patch or mitigate immediately.
CISA confirms active exploitation of CVE-2008-4128, a critical CSRF flaw in Cisco IOS 12.4 allowing remote command execution at privilege level 15.
jscrambler npm 8.14.0 was compromised with a preinstall hook dropping a Rust infostealer on Windows, macOS & Linux. Check your pipelines now.
A critical stored XSS vulnerability in Zimbra Classic Web Client lets crafted emails run malicious code in user sessions. Patch immediately.
Progress Software urges ShareFile customers to shut down Storage Zone Controller Windows servers amid a credible external security threat. Full details ins
The 'Ill Bloom' crypto wallet vulnerability allows attackers to predict recovery phrases via weak randomness, with over $5M stolen in active exploitation.
CVE-2026-48939 in iCagenda allows PHP file upload and remote code execution. Actively exploited โ patch immediately or disable file attachments.
CVE-2026-56291 in Balbooa Forms allows unauthenticated file upload leading to full remote code execution. Actively exploited โ patch by 13 July 2026.
Ubiquiti patches critical UniFi vulnerabilities including CVE-2026-50746 (CVSS 10.0), enabling privilege escalation and arbitrary command execution across
CVE-2026-43499 (GhostLock) lets any local Linux user gain root and escape containers. Affects all major distros since 2011. Patch immediately.
CISA adds 4 actively exploited flaws to KEV, including a CVSS 10.0 Adobe ColdFusion RCE. Patch Joomla and Langflow vulnerabilities urgently.
CVE-2026-14904 in AWS Research and Engineering Studio lets authenticated users read root-accessible files via a symlink attack. Patch immediately.
A critical flaw in Writer AI platform allowed session tokens to leak across tenants via a single malicious link. Learn the impact and mitigation steps.
CVE-2026-10536 is a Use-After-Free flaw in HTTP/2 stream-dependency handling affecting Azure. Learn the impact and how to mitigate it.
CERT/CC warns of a hidden admin backdoor CVE-2026-11405 in Tenda router firmware, allowing full authentication bypass on affected devices.
BeyondTrust patches critical auth bypass flaws in Remote Support and PRA. CVE-2026-40138 scores 9.2 โ unauthenticated attackers could seize control of affe
CVE-2026-48282 is an actively exploited Adobe ColdFusion path traversal flaw enabling arbitrary code execution. Patch immediately per CISA guidance.
CVE-2026-48908 allows unauthenticated attackers to upload and execute PHP files via JoomShaper SP Page Builder. Patch immediately โ actively exploited.
CVE-2026-55255 is an actively exploited authorisation bypass in Langflow allowing authenticated attackers to execute other users' workflows. Patch immediat
CVE-2026-56290 in Joomlack Page Builder allows unauthenticated file upload leading to remote code execution. Actively exploited โ patch immediately.
CVE-2026-53359 'Januscape' lets guest VMs escape to the host via a 16-year-old Linux KVM use-after-free bug on Intel and AMD x86 systems.
Attackers are actively exploiting CVE-2026-20896, a CVSS 9.8 Gitea Docker flaw allowing unauthenticated privilege escalation via header spoofing. Patch now
CVE-2026-46242 'Bad Epoll' lets unprivileged users gain root on Linux and Android. Learn the impact and how to patch your cloud workloads now.
CVE-2026-56645 is a critical heap buffer overflow in Microsoft Edge allowing unauthenticated remote code execution. Patch immediately.
CVE-2026-57975 is a type confusion RCE flaw in Microsoft Edge (Chromium-based) allowing unauthenticated remote code execution. Patch immediately.
CVE-2026-57984 is a use-after-free flaw in Microsoft Edge allowing remote code execution over a network. Patch immediately to protect endpoints.
CVE-2026-57988 is a critical RCE flaw in Microsoft Edge via path traversal. Learn the impact and how to protect your cloud environment.
CVE-2026-57992 is a critical use-after-free RCE flaw in Microsoft Edge (Chromium-based). Patch immediately to prevent remote code execution attacks.
Anubis ransomware affiliates are exploiting Citrix Bleed 2 (CVE-2025-5777) alongside BYOVD and supply chain credentials to breach enterprise networks.
CISA adds SharePoint RCE vulnerability to its KEV list. Attackers need only a valid account to exploit on-prem servers. Patch immediately.
Attackers exploited a critical Oracle E-Business Suite flaw via patch-diffing before public exploit code dropped. Find out what action to take now.
Sysdig reports the first fully AI-run ransomware attack (JADEPUFFER), exploiting a Langflow RCE to breach, move laterally, and encrypt production databases
The FortiBleed FortiGate credential theft campaign is directly tied to INC and Lynx ransomware operations, enabling targeted follow-on intrusions.
CVE-2026-45659 (CVSS 8.8) โ a SharePoint Server RCE flaw via unsafe deserialisation โ is actively exploited and now on the CISA KEV list. Patch immediately
An unpatched Argo CD repo-server vulnerability allows unauthenticated RCE and full Kubernetes cluster takeover. No CVE or fix yet โ mitigate now.
Adobe releases emergency patches for seven maximum-severity CVSS 10.0 vulnerabilities in ColdFusion and Campaign Classic. Patch immediately to prevent RCE.
Critical Cursor AI editor flaws CVE-2026-50548 and CVE-2026-50549 allow prompt injection to escape sandbox and run commands on developer machines.
CVE-2026-8037, a CVSS 9.6 pre-auth RCE flaw in Progress Kemp LoadMaster, is under active exploitation. Patch immediately or restrict management access.
Attackers are actively exploiting CVE-2026-33017 (CVSS 9.3) in Langflow to deploy Monero miners on exposed AI endpoints. Patch or isolate instances now.
Attackers exploit CVE-2026-48558, a CVSS 10.0 auth bypass in SimpleHelp, to deploy TaskWeaver and Djinn Stealer malware. Patch immediately.
CVE-2026-8037 in Progress Kemp LoadMaster allows unauthenticated root command execution via the API. CVSS 9.8 โ patch immediately.
CVE-2026-46817 (CVSS 9.8) in Oracle E-Business Suite Payments is actively exploited, allowing full instance takeover. Patch immediately.
An anonymous researcher has dropped a public zero-day exploit repository with at least two vulnerabilities already under active attack. Here's what securit
Public PoC released for CVE-2026-55200, a critical libssh2 flaw allowing remote code execution on SSH clients. All versions up to 1.11.1 affected. Patch no
CVE-2026-48558 lets unauthenticated attackers forge OIDC tokens in SimpleHelp, gaining full technician access and bypassing MFA. Patch immediately.
CVE-2026-46331 'pedit COW' lets local users gain root on Linux via a kernel traffic-control flaw. Public exploit live โ patch immediately.
CISA adds critical PTC Windchill RCE vulnerability to its KEV catalog amid active web shell attacks targeting PDM and PLM systems.
Nation-state hackers breached Australian critical infrastructure to enable future disruptive attacks. Learn what this means for cloud and OT security archi
CVE-2026-12569 is an actively exploited RCE vulnerability in PTC Windchill and FlexPLM. Unauthenticated attackers can execute arbitrary code remotely.
CVE-2026-20230 is an SSRF vulnerability in Cisco Unified CM allowing unauthenticated attackers to write files and escalate to root. Patch by 28 June 2026.
CVE-2026-20230 is under active exploitation and Cisco's SD-WAN zero-day is more severe than first thought. Here's what security teams need to do now.
CISA confirms active exploitation of CVE-2025-67038, a CVSS 9.8 code injection flaw in Lantronix EDS5000 device servers. Patch immediately.
The Cordyceps vulnerability class exposes 300+ GitHub repositories to supply-chain attacks, allowing full workflow hijack at orgs including Microsoft and G
Threat actors are actively exploiting CVE-2026-20230 in Cisco Unified CM. A PoC file-write flaw enables unauthenticated remote root access. Patch now.
A Russian-speaking IAB has harvested 110M credentials from 430,000+ FortiGate firewalls in the FortiBleed campaign. Learn what architects must do now.
CVE-2025-67038 is a critical OS command injection flaw in Lantronix EDS5000 allowing root-level code execution. Actively exploited per CISA KEV.
CVE-2026-34908 is an actively exploited access control flaw in Ubiquiti UniFi OS allowing unauthorised system changes. Patch now โ CISA deadline 26 June 20
CVE-2026-34909 is an actively exploited path traversal vulnerability in Ubiquiti UniFi OS that could let attackers access system files and compromise accou
CVE-2026-34910 is an actively exploited command injection flaw in Ubiquiti UniFi OS. Patch immediately or restrict network access to limit exposure.
A checkm8-style BootROM exploit for Apple A12 and A13 iPhones is now public. The hardware flaw is unpatchable via software โ only a new device fixes it.
Microsoft's AutoJack exploit lets a single web page hijack an AI browsing agent to execute code on the host โ no credentials required. Here's what architec
CISA warns of FortiBleed, a Russian-linked campaign compromising 86,644 FortiGate devices. Learn what cloud security teams must do now.
CVE-2026-48914 is a heap buffer overflow in QEMU-KVM's virtio-blk SCSI handling, risking VM escape on Azure and self-managed KVM hosts.
Five containerd CRI plugin vulnerabilities (CVE-2026-50195 and others) affect EKS, ECS, Fargate and more. Patch immediately to prevent host compromise.
F5 patches two critical NGINX Open Source RCE vulnerabilities (CVE-2026-42530) exploitable by unauthenticated remote attackers via HTTP/3. Patch immediatel
CVE-2026-45480 is an Azure Active Directory elevation of privilege flaw allowing unauthenticated attackers to escalate privileges over a network. Patch urg
CVE-2026-20253 is a critical Splunk Enterprise vulnerability allowing unauthenticated file creation or truncation via a PostgreSQL sidecar endpoint. Patch
A mass credential-theft attack has hit 75,000 Fortinet firewalls. Learn what cloud security architects should do now to protect their environments.
Cisco updates its max-severity SD-WAN advisory to cover an additional device. Patched users should still audit logs for signs of exploitation.
CISA adds CVE-2026-48907 (CVSS 10.0) to KEV catalogue. The Joomla JCE plugin flaw allows arbitrary PHP code execution โ patch immediately.
Three critical Fortinet FortiSandbox vulnerabilities are being actively exploited. Patches are available โ upgrade immediately to protect your environment.
Attackers are actively exploiting three Fortinet FortiSandbox flaws, including critical CVE-2026-39813 (CVSS 9.1). Patch immediately and restrict JRPC API
CVE-2026-48907 allows unauthenticated attackers to upload and execute PHP code via Widget Factory Joomla Content Editor. Patch by 19 June 2026.
A second Cisco Catalyst SD-WAN Manager zero-day this month allows attackers to gain root access. Patch immediately and restrict management plane exposure.
Three chained vulnerabilities in LiteLLM let low-privilege users gain full admin and RCE, exposing all AI provider API keys. Here's what architects need to
CVE-2026-20253 (CVSS 9.8) allows unauthenticated remote code execution in Splunk Enterprise below 10.2.4 and 10.0.7. Patch immediately.
CVE-2026-12043 is a heap double-free in AWS Common Runtime aws-c-http that could allow a malicious server to achieve remote code execution on SDK clients.
China-linked Velvet Ant compromised PAM and OpenSSH to maintain stealthy Linux access for nearly a decade. Here's what cloud architects must do now.
Three patched LangGraph vulnerabilities, including a critical SQL injection chain, expose self-hosted AI agent deployments to remote code execution. Patch
CVE-2026-35273 is a critical Oracle PeopleSoft PeopleTools missing authentication flaw enabling full system takeover. Patch by 15 June 2026.
Cisco patches CVE-2026-20230 in Unified CM โ an SSRF flaw allowing unauthenticated attackers to write files and escalate to root. Public PoC now available.
A flaw in Anthropic's Claude Code GitHub Action let attackers hijack public repos via a single issue, risking supply chain compromise across downstream pro
CISA adds CVE-2026-45247, a CVSS 9.8 RCE flaw in the Mirasvit Cache Warmer Magento extension, to its KEV catalogue amid active exploitation.
A leftover debug flag in Microsoft 365 Android apps let any installed app steal account tokens silently, exposing email, files and calendar data.
A leftover debug flag in Microsoft 365 Android apps let any installed app steal account tokens silently, exposing email, files and calendar data.
CVE-2026-45247 allows unauthenticated RCE via PHP deserialisation in Mirasvit Full Page Cache Warmer. Actively exploited โ patch immediately.
The Dysphoria IoT botnet now uses blockchain name services and infected-device relays, making traditional C2 disruption tactics ineffective. Here's what ar
Weekly cloud security recap: rogue OpenAI agent, Check Point exploit, slopsquatting supply chain risk, and ClickFix lures targeting enterprise environments
CVE-2026-50333 is a Windows Spaceport.sys elevation of privilege flaw. This update is informational only โ no new patches or severity changes.
CVE-2026-50343 is a Microsoft Install Service Elevation of Privilege flaw. This update revises acknowledgements only โ no new patches required.
CVE-2026-50697 is a Windows CLFS Driver elevation of privilege flaw. This update is informational only โ an acknowledgement change with no new remediation
A Microsoft Defender for Endpoint update broke the security service on Linux, silently leaving systems unprotected on restart and blocking installs on hard
A high-severity n8n sandbox escape lets authenticated workflow editors run OS commands on the host. Patch to v2.31.5 or v2.32.1 now.
Operation BlueDash uses fake Microsoft Teams update pages to install Level RMM and ScreenConnect, giving attackers stealthy persistent remote access.
The Cruciferra crypter uses BYOVD and Process Ghosting to evade Windows defences. Learn what cloud security architects should do to mitigate the risk.
East Asia-linked threat actor deploys TELESHIM, MIXEDKEY, and BINDCLOAK malware against Middle East governments, abusing Telegram for C2 communications.
CVE-2026-16461 is a stack buffer overflow in rpcbind's rpcinfo rpcbdump() affecting Azure Linux workloads. Learn the risks and mitigation steps.
CVE-2026-8450 exposes a critical OS command injection flaw in HTTP::Daemon for Perl before v6.17, enabling remote code execution via send_file().
CVE-2026-16277 is a stack buffer overflow in rpcbind's rpcbaddrlist() function affecting Azure Linux workloads. Learn the risks and mitigations.
CVE-2026-64530 affects the Linux kernel's traffic control subsystem. Azure VM and AKS users should patch promptly to mitigate potential denial of service o
The SourTrade malvertising campaign uses browsers to assemble Windows malware from fragments, evading detection by impersonating TradingView, Solana, and L
CTM360 research reveals insurance phishing has shifted to real-time session hijacking, bypassing MFA and rendering stolen credentials instantly usable.
PRODAFT uncovers DevMan RaaS (Funky Mantis): a centralised portal enabling affiliates to build ransomware payloads, manage victims and handle payouts.
CVE-2026-16807 is an out-of-bounds write flaw in Chromium Codecs affecting Microsoft Edge. Learn the security impact and how to patch.
CVE-2026-16806 is a use-after-free flaw in Chromium's WebMCP affecting Microsoft Edge. Learn the security impact and remediation steps.
CVE-2026-16805 is a use-after-free flaw in Chromium's Blink engine affecting Microsoft Edge. Update Edge immediately to mitigate potential code execution.
CVE-2026-16804 is a use-after-free flaw in Chromium's Input component affecting Microsoft Edge. Learn the risk and recommended patching steps.
The Pope's official prayer app has exposed data on over 700,000 users, highlighting serious cloud security and GDPR compliance failures in consumer apps.
North Korean group BlueNoroff uses a Zoom/Teams phishing kit to profile crypto wallets and deliver malware via social engineering. Here's what security tea
A hacker deployed the Hermes AI agent in autonomous mode to conduct post-exploitation against Thailand's Ministry of Finance, highlighting the emerging thr
Golden Chickens MaaS resurfaces with TinyEgg, ChonkyChicken and a browser credential stealer โ here's what cloud security teams need to know.
CVE-2026-64600 affects the Linux XFS filesystem driver. Azure VM and container workloads may be at risk. Patch Linux kernels promptly to mitigate exposure.
CVE-2026-59677 exposes a process kill attack vector in seunshare's killall() function, posing a risk to Azure Linux workloads using SELinux-based sandboxin
CVE-2026-59676 exposes a local file deletion attack vector in seunshare's rm_rf() function, posing risks to Azure Linux workloads. Learn what to do.
Eight high-severity NodeBB vulnerabilities expose admin access and private chats. Exploit code is public โ upgrade to version 4.14.2 immediately.
Seven Redis security releases patch authenticated RCE zero-days affecting versions 6.2โ8.8. Patch to 6.2.23, 7.2.15, or 7.4.10 immediately.
Russia-linked UAC-0099 is targeting Windows systems with MATCHBOIL.V2 malware disguised as a Notepad++ plugin. Here's what security teams need to know.
Researchers show macOS Gatekeeper can be bypassed by replacing downloaded apps with malicious versions. Apple has declined to fix the issue.
CVE-2026-16796 affects AWS Bedrock AgentCore Python SDK versions below 1.18.1, enabling authenticated users to run arbitrary commands via install_packages(
CVE-2026-16756 in aws-smithy-http-server โค0.66.4 allows unauthenticated Slowloris DoS attacks. Learn the impact and how to remediate.
A year-long Russian phishing campaign infects users the moment they preview an email. Learn what cloud security architects must do to defend their organisa
UCSD researchers find KARR/SWDS aftermarket car security systems share a single hardcoded key, allowing Bluetooth-range attackers to hijack millions of veh
CVE-2026-16584 allows security policy bypass in AWS API MCP Server (0.2.13โ1.3.47) when startup fails. Update to 1.3.47 or enable fail-closed mode now.
Oracle releases a record 1,449 security patches in one quarterly update. Experts warn AI-driven vulnerability discovery is making this the new normal for d
This week's top threats include Android spyware, AI image prompt injection, PLC attacks, and malicious browser extensions. Key risks for cloud and OT secur
CISA expands its alert as Iran-linked groups probe internet-facing industrial control systems across US critical infrastructure. Here's what OT security te
CVE-2026-49159 exposes sensitive data via Microsoft Graph to authenticated attackers over a network. Learn the impact and how to protect your environment.
CVE-2026-54120 allows authorised attackers to execute code remotely on Microsoft Surface devices via improper input validation. Patch now.
CVE-2026-56160 allows authorised attackers to escalate privileges in Azure Red Hat OpenShift (ARO) via improper authorisation controls. Patch now.
CVE-2026-56167 is an SSRF flaw in Azure AI Search allowing authorised attackers to escalate privileges over a network. Learn what action to take.
CVE-2026-56191 affects Microsoft Exchange Online, allowing unauthenticated attackers to tamper with data over a network. Learn the security impact and miti
CVE-2026-57106 is an SSRF flaw in Azure Data Quality enabling unauthenticated privilege escalation over a network. Patch and review exposure now.
CVE-2026-58275 is an Azure DNS elevation of privilege vulnerability allowing unauthenticated network attackers to escalate privileges. Learn the security i
CVE-2026-58630 affects Azure App Service on Azure Stack Hub, allowing unauthenticated network attackers to elevate privileges. Patch and mitigate now.
CVE-2026-62835 is an improper authorisation flaw in Microsoft Online Services allowing unauthenticated remote attackers to disclose sensitive information.
A sandbox escape flaw in Anthropic's Claude Cowork lets an AI agent break out of its Linux VM and access any file on the host macOS system, affecting ~500,
Cisco Talos details msaRAT, a Rust implant used by Chaos ransomware to tunnel C2 traffic through headless Chrome or Edge, evading network detection.
A ChatGPT vulnerability lets a malicious link deploy an autonomous AI agent inside your company with employee-level access. Here's what security architects
China-nexus group JadeProx uses TriBack Loader in attacks on government and healthcare via exposed Alibaba Cloud infrastructure. What architects need to kn
Everest ransomware group hit Swiss train maker Stadler via a supplier platform, demanding $12.3M. Stadler refused โ a key supply chain security lesson.
Attackers are applying synthetic identity fraud techniques to machine identities. Learn what cloud security architects must do to defend service accounts a
Attackers weaponised compromised GitHub repos and malicious Packagist packages to target cPanel and WHM hosting servers at scale via CI/CD pipelines.
CVE-2026-64600 (RefluXFS) lets local users gain root on default RHEL, Fedora Server, and Amazon Linux installs via an XFS kernel flaw. Patch now.
CVE-2026-55973 exposes a stack buffer overflow via DNS error reporting config in Azure. Learn the risk and how to protect your infrastructure.
CVE-2026-53910 is a heap-based buffer overflow in GNU diffutils affecting Azure environments. Learn the risk and how to remediate.
CVE-2026-63136 enables uncontrolled resource consumption in Elasticsearch on Azure, leading to Denial of Service. Patch and restrict access now.
CVE-2026-63140 is a reachable assertion bug in Elasticsearch that can cause denial of service in Azure environments. Learn what architects should do now.
CVE-2026-56145 is an uncontrolled resource consumption flaw in Elasticsearch that can cause Denial of Service in Azure environments. Patch now.
A man accessed private medical files using social engineering alone โ no badge, no hacking. A stark reminder that human trust is often the weakest security
CVE-2026-8933 lets unprivileged users gain root on Ubuntu Desktop 24.04โ26.04 via a snap-confine flaw. Patch immediately on cloud VMs and VDI.
CVE-2026-48294 in the Adobe Acrobat Chrome extension allowed malicious sites to silently steal WhatsApp Web data from 314 million users.
Dophin X Windows stealer targets 300+ apps including cloud credentials, using AI profiling to identify high-value victims. Here's what security architects
CVE-2026-29059 is an actively exploited path traversal flaw in Windmill allowing unauthenticated attackers to read arbitrary server files. Patch now.
Proofpoint finds over a third of ransomware victims face repeat extortion after paying up โ and some never got their files back. Here's what architects sho
79% of attacks are now malware-free. Learn why cloud SOCs must adopt multi-layered, behavioural detection to counter AI-equipped threat actors.
A first-person identity theft case shows how sharing a single MFA code led to full email and account takeover. Key lessons for cloud security teams.
CVE-2026-56434 affects NGINX's ngx_http_ssi_module. Azure users running NGINX workloads should review exposure and apply patches promptly.
CVE-2026-42533 affects NGINX Map directive regex matching on Azure. Learn the impact, risks, and steps cloud architects should take to remediate.
CVE-2026-59885 exposes a denial-of-service risk in pyasn1 via quadratic complexity in OID parsing. Azure workloads using pyasn1 should patch promptly.
CVE-2026-57215 exposes RabbitMQ to unauthorised reply-channel injection via persistent direct-reply-to bindings, risking message interception on Azure.
CVE-2026-57211 is an SSRF vulnerability in RabbitMQ's management UI on Windows, posing credential theft and internal network exposure risks in Azure enviro
CVE-2026-57216 allows remote guest sessions in RabbitMQ by bypassing loopback enforcement in AMQP 1.0, AMQP 0-9-1, and Stream protocols. Patch now.
CVE-2026-57213 exposes a stored XSS flaw in RabbitMQ's federation management plugin via unsanitised consumer_tag rendering. Learn the risks and mitigations
CVE-2026-57217 allows cross-tenant routing-key bypass in RabbitMQ topic authorisation, risking message interception in multi-tenant Azure deployments.
CVE-2026-57220 allows unauthenticated attackers to exhaust RabbitMQ server memory by bypassing stream frame-size limits. Patch or restrict access now.
CVE-2026-64188 is a Linux kernel use-after-free vulnerability in the Qualcomm RmNet driver affecting Azure workloads. Patch now.
CVE-2026-64189 is a Linux kernel netfilter ipset race condition affecting Azure Linux workloads. Learn the security impact and remediation steps.
CVE-2026-64192 patches a Linux kernel BPF LSM initialisation flaw affecting Azure workloads. Learn the risk and remediation steps.
CVE-2026-26199 is a buffer underflow flaw in HDF5 H5Iget_name/H5G_get_name affecting Azure. Learn what cloud architects need to do.
CVE-2026-26197 exposes an array size validation flaw in H5Odtype.c, risking memory corruption in Azure workloads that process HDF5 files. Patch promptly.
Law enforcement dismantles Kratos phishing kit that stole Microsoft 365 session tokens and bypassed MFA. What cloud architects need to know.
A typosquatted NuGet fork of Newtonsoft.Json hides game-rigging code targeting the Digitain platform. Learn how to protect your supply chain.
A prompt injection flaw in Microsoft's Azure DevOps MCP server lets attackers use hidden PR comments to hijack AI review agents and leak repository data.
Two s2n-tls vulnerabilities: a TLS 1.3 AEAD bypass enabling silent record drops and a QUIC memory leak via HelloRetryRequest. AWS patch required.
CVE-2026-15957 in smithy-rs allows unauthenticated remote DoS via stack exhaustion in JSON, CBOR, and XML deserialisers. Update aws-sdk-rust to release-202
A prompt injection flaw in AWS Kiro let poisoned web pages rewrite config files and execute code on developer machines. AWS has patched the issue.
CVE-2026-50462 is a Windows WinSock elevation of privilege flaw. Learn what cloud architects need to know and what action to take.
CVE-2026-58640 is a Windows NTFS Remote Code Execution flaw. Latest update is an acknowledgement change only โ no new patches issued.
Suno AI music platform suffers a data breach affecting 55 million users, confirmed by Have I Been Pwned. What cloud security teams need to know.
Researchers show invisible screen text can hijack open-source Android AI agents and run commands on host PCs via indirect prompt injection attacks.
N-day vulnerabilities are being weaponised within hours of patch release. Learn why speed alone won't protect your cloud environment and what else you need
Bit2Watt lets cloud tenants use standard GPU access to rapidly spike power draw in data centres, threatening grid stability โ no exploit needed.
CVE-2026-63796 affects the ocfs2 Linux cluster file system, allowing oversized bitmap descriptors that could destabilise or compromise Azure Linux VMs.
CVE-2026-3842 exposes a host out-of-bounds write in QEMU-KVM's Hyper-V SynDbg. Learn the risk and how to protect your Azure and KVM environments.
CVE-2026-63801 is a Linux kernel use-after-free bug in TIPC decryption affecting Azure Linux workloads. Learn the risk and mitigation steps.
CVE-2026-64017 affects the Linux kernel blk-mq subsystem in Azure environments. Learn the security impact and what architects should do now.
CVE-2026-63879 affects the Linux kernel AMDGPU driver on Azure GPU VMs. Learn the impact and patching steps for cloud security teams.
CVE-2026-64077 affects the Linux kernel netfilter ebtables subsystem on Azure VMs. Learn what cloud architects should do to mitigate risk.
JADEPUFFER deploys ENCFORGE ransomware via Langflow RCE to encrypt AI model weights, vector indexes, and training datasets. Learn the risks and mitigations
Adversarially crafted cloud workloads could destabilise power grids serving data centres โ a critical cross-domain risk for cloud and CNI security architec
The FakeGit campaign uses 7,600 malicious GitHub repositories posing as AI tools and MCP servers to deliver SmartLoader malware to developers.
The HOLLOWGRAPH campaign abuses Microsoft 365 calendar invites to hide malware commands, using Microsoft's own cloud as a covert C2 channel.
HollowGraph malware uses Microsoft 365 calendar events dated 2050 to hide C2 traffic and exfiltrate files via the Graph API. Here's what architects need to
CVE-2024-35248 is an elevation of privilege flaw in Microsoft Dynamics 365 Business Central. Build numbers updated โ check your patch status now.
Microsoft updates CVE-2026-47304 advisory for a .NET security feature bypass. Review patching scope for Azure and on-prem .NET workloads.
CVE-2026-50525 is a .NET Denial of Service vulnerability. Learn the impact on Azure workloads and what cloud architects should do to mitigate risk.
Microsoft updates product info for CVE-2026-50646, a .NET Framework RCE flaw. Learn what Azure architects need to know and action.
Microsoft updates CVE-2026-50648 advisory for a .NET Framework Denial of Service flaw. Review revised product scope and ensure patches are applied across a
CVE-2026-50649 is a .NET remote code execution vulnerability. Review Microsoft's updated advisory and patch affected runtimes across Azure workloads.
CVE-2026-50650 is a .NET Framework elevation of privilege vulnerability. Learn what it means for Azure workloads and how to remediate it.
Weekly security recap covering WordPress RCE, SonicWall and SharePoint zero-days, AI service attacks, and in-the-wild exploitation before patches were avai
Dutch intelligence warns Russian services are compromising IP cameras across NATO states to monitor military convoys and Ukrainian troop movements. What to
Anthropic's Mythos is accelerating CVE discovery. Learn why your exposure window โ not volume โ is the real risk and how to respond.
CVE-2026-14266 is a heap buffer overflow in 7-Zip that lets attackers run code via crafted XZ archives. Patch to 7-Zip 26.02 immediately.
CVE-2026-63815 affects the Linux f2fs kernel driver on Azure. Learn the impact on Azure VMs and containers, and what architects should do now.
Hugging Face confirms a breach by an autonomous AI agent exposing internal datasets and credentials โ a major supply chain risk for AI pipelines.
Three malicious RubyGems packages in the SleeperGem campaign target developer machines via the Ruby package registry. Find out which gems to remove and how
Connecting AI agents to external services creates serious security risks including prompt injection and data exfiltration. What cloud architects need to kn
Russian GRU-linked group UAC-0145 uses fake CAPTCHA prompts to trick Ukrainian users into installing data-stealing malware. Here's what security teams need
CVE-2026-50012 is a memory corruption flaw in Squid's cache digest reply handling. Azure deployments using Squid proxies should patch immediately.
CVE-2026-47729 exposes a memory disclosure flaw in Squid's FTP gateway. Azure users running Squid should patch immediately to prevent sensitive data leakag
CVE-2026-62299 exposes a nil-pointer panic in CoreDNS's rewrite plugin, enabling remote denial-of-service attacks on Kubernetes and Azure workloads.
CVE-2026-62309 allows a remote attacker to crash CoreDNS with a single 28-byte packet, risking DNS outages in Kubernetes and Azure environments.
CVE-2026-15905 is a use-after-free flaw in Chromium's Aura framework affecting Microsoft Edge. Learn the security impact and patching steps.
CVE-2026-15904 is a use-after-free flaw in Chromium's Ozone layer affecting Microsoft Edge. Learn the security impact and remediation steps.
CVE-2026-15903 is an out-of-bounds read/write flaw in the V8 JavaScript engine affecting Microsoft Edge. Update immediately to mitigate code execution risk
CVE-2026-15902 is a use-after-free flaw in Chromium's Cast component affecting Microsoft Edge. Update Edge immediately to mitigate potential code execution
CVE-2026-15901 is a use-after-free flaw in Chromium's Network component affecting Microsoft Edge. Learn the security impact and patching steps.
CVE-2026-15900 is a use-after-free flaw in Chromium's GPU component affecting Microsoft Edge. Update Edge immediately to mitigate potential code execution
CVE-2026-15899 is a use-after-free flaw in Chromium's CameraCapture component affecting Microsoft Edge. Learn the security impact and remediation steps.
The OpenSSL HollowByte flaw lets attackers exhaust server memory with 11-byte TLS requests. No CVE was issued. Learn what to patch and how to detect exposu
CVE-2026-15415 affects aws-healthomics-mcp-server <=0.0.35, enabling arbitrary file writes via path traversal in workflow linting tools. Patch now.
CVE-2026-12283 affects the AWS Athena Synapse Connector (2022โ2026), allowing crafted table names to expose unintended data via federated queries.
Seven malicious npm packages targeting Vite developers deliver a RAT using blockchain-based C2 infrastructure, bypassing traditional takedown defences.
The NadMesh botnet is scanning for exposed AI tools like Ollama and ComfyUI to steal AWS keys and Kubernetes tokens. Here's what architects need to know.
Chinese APT subgroup CylindricalCanine breached DigiCert in April 2026, stealing code-signing certificates. Learn the supply chain security implications.
CVE-2026-56159 is a Remote Code Execution flaw in Windows DHCP Server Service. Learn what cloud security architects need to know and do.
North Korean hackers use steganography in SVG images to deliver OtterCookie-aligned malware via fake coding interviews, stealing credentials and crypto wal
The EU has ordered Google to grant third-party AI assistants full Android system access โ mic, camera, screen and app control โ by August 2027. Here's what
A multi-touch gesture bypasses Android lock screen auth, letting Gemini send SMS without a PIN. Google is working on a fix. Here's what you need to know.
ACR Stealer uses ClickFix lures to steal browser credentials, session tokens, and Microsoft 365 files from OneDrive and SharePoint. Here's what to do.
GoSerpent malware is targeting Southeast Asian government and diplomatic entities in a long-term espionage campaign discovered by Kaspersky in 2026.
CVE-2026-59884 exposes a denial-of-service flaw in pyasn1's ASN.1 decoder. Azure workloads using Python should patch immediately to prevent service disrupt
CVE-2026-60081 exposes a path index limitation flaw in DBI::ProfileData for Perl before v1.651. Learn the security impact and how to remediate.
CVE-2026-60082 affects Perl DBI versions before 1.651, failing to enforce statement handle consistency. Learn the impact and how to remediate on Azure.
CVE-2026-57433 affects Perl Storable before 3.41, causing a signed integer overflow during deserialisation. Upgrade now to protect Azure workloads.
CVE-2026-15709 exposes a denial-of-service risk in libsoup's WebSocket permessage-deflate handling. Learn the impact and mitigation steps for Azure workloa
CVE-2026-15712 exposes a heap buffer over-read in libsoup3's HTTP/2 GOAWAY frame parsing, risking memory disclosure on Azure workloads.
CVE-2026-15714 is an out-of-bounds read in libsoup's multipart input stream. Learn the impact on Azure workloads and how to remediate.
CVE-2026-15713 allows remote attackers to cause a denial of service via a memory leak in libsoup's HTTP/2 frame window handling. Azure workloads at risk.
CVE-2026-15711 is a libsoup WebSocket denial-of-service flaw affecting Azure Linux workloads. Learn the risks and remediation steps.
CVE-2026-53366 targets a Linux kernel IPv4 memory allocation flaw affecting Azure workloads. Learn the impact and recommended mitigations.
CVE-2026-48863 is a stack-based buffer overflow in libsolv's EdDSA PGP verification, enabling denial of service on Azure and Linux workloads.
A researcher poisoned an open-weight AI model for under $100, exposing serious supply chain risks for orgs deploying unverified model weights.
CVE-2026-15895 is an OS command injection flaw in AWS jsii-diff. Versions before 1.131.0 allow shell command execution via crafted CLI arguments.
Two Scattered Spider members sentenced to 5.5 years for the 2024 TfL cyberattack, which downed 148 systems and cost ยฃ29 million. Key lessons for security t
CVE-2026-15737 exposes raw AI prompts and responses via CloudWatch Logs in AWS Bedrock AgentCore Python SDK versions 1.4.8 and 1.5.0.
Weekly threat roundup: game cheat spyware, 24-hour ransomware deployment, and Chrome Sync abused for stalking. Key risks for cloud security teams.
CVE-2026-50304 affects Windows AD FS, enabling denial of service attacks that could disrupt authentication in hybrid Azure environments. Patch now.
CVE-2026-50324 affects Windows AD FS with a denial of service risk. Learn what cloud security architects need to know and do.
CVE-2026-50355 affects Windows AD FS with a Denial of Service risk. Updated product info released. Find out what Azure architects need to know.
CVE-2026-50368 affects Windows AD FS, enabling denial of service attacks that could disrupt authentication in hybrid Azure environments. Patch now.
CVE-2026-50411 is a Denial of Service flaw in Windows AD FS that could disrupt federated authentication. Review Microsoft's updated advisory and patch prom
CVE-2026-50647 is a Denial of Service flaw in Active Directory Federation Services. Learn the impact and patching guidance for cloud security teams.
CVE-2026-50652 is a Denial of Service flaw in Azure Active Directory that could disrupt authentication. Learn what architects should do now.
CVE-2026-50653 is a Denial of Service flaw in Azure Active Directory that could disrupt authentication services. Learn what cloud architects should do.
CVE-2026-56171 is a Windows RDP information disclosure vulnerability allowing unauthenticated network attackers to expose private data. Patch now.
CVE-2026-58598 is a race condition in Windows Backup Service allowing local privilege escalation. Learn the security impact and remediation steps.
CVE-2026-58643 is an XSS spoofing vulnerability in Windows Admin Center allowing unauthenticated network attackers to compromise admin sessions. Patch now.
A JWT validation flaw in n8n Enterprise ignores the issuer claim, letting attackers authenticate as other users across trusted identity providers.
TELEPUZ is a modular malware using ClickFix lures to steal data and run remote commands. Learn what cloud security teams should do now.
Two UK members of Scattered Spider jailed for the 2023 Transport for London ransomware attack โ the biggest cybercrime conviction in UK history.
ClickLock is a new macOS infostealer that kills system apps every 210ms to coerce login credential entry. Here's what security teams need to know.
Brazilian government sites hijacked in the PhantomEnigma campaign to distribute malware. Learn what cloud security architects should do to mitigate the ris
A new Agent Data Injection attack poisons trusted data sources to make AI agents execute attacker commands โ impacting agentic AI in cloud and dev workflow
One in six PCs still runs Windows 10 as end-of-support looms. Here's what cloud security architects must do to protect their environments.
China-linked Daxin rootkit resurfaces at a Taiwanese manufacturer alongside new Stupig pre-login SYSTEM backdoor. What security architects need to know.
An unpatched flaw in Shark robot vacuums lets attackers with physical access take root control of other vacuums region-wide via AWS, exposing Wi-Fi passwor
CVE-2026-59831 allows remote code execution via GitHub CLI's gh codespace jupyter command when connecting to a malicious Codespace. Patch promptly.
A law firm's use of one shared admin password exposed all client data to anyone with the credential โ a critical identity management failure with serious d
A tech support scam caused a Qantas data breach exposing 5.7 million customers' PII. Here's what cloud security architects need to know.
CVE-2026-15746 exposes Elasticsearch API keys via SSRF in AWS Strands Agents Tools. Upgrade to v0.7.0+ and rotate credentials immediately.
OkoBot malware injects fake seed phrase prompts into real Ledger and Trezor wallet apps on Windows, stealing crypto recovery keys from victims.
CVE-2026-50375 is a Windows DirectX Graphics Kernel elevation of privilege flaw. This update is an informational acknowledgment change only โ no new patche
CVE-2026-56182 is a Windows NTFS elevation of privilege flaw affecting Azure VMs and Windows workloads. Latest update is an acknowledgment change only.
Microsoft corrects the CVSS vector, exploitability rating, and exploitation status for CVE-2026-58644, a SharePoint Remote Code Execution vulnerability.
A researcher dropped a new Windows User Profile Service zero-day PoC after Patch Tuesday. Learn the risk and how cloud security teams should respond.
Approved marketing tags can load hidden fourth-party scripts exposing customer data. Learn how to close the Approval Gap before attackers exploit it.
A Cursor AI editor flaw on Windows silently executes a malicious git.exe from a repo root, exposing SSH keys and cloud tokens with no user prompt.
Four @asyncapi npm packages were compromised to deliver multi-stage botnet malware. Find out which versions are affected and how to protect your pipelines.
CVE-2026-58253 exposes a NATS Server authentication bypass in the Route API, risking unauthorised cluster access in Azure cloud-native environments.
CVE-2026-58209 allows MQTT retained and QoS replay to bypass subscription deny filters in NATS Server, risking unauthorised message access.
CVE-2026-58252 allows attackers to bypass NATS Server subscription authorisation using wildcard overlaps, risking unauthorised message access in cloud-nati
CVE-2026-58250 allows unauthenticated attackers to crash NATS Server via a malformed leafnode handshake. Patch immediately to prevent denial of service.
CVE-2026-58208 lets attackers crash NATS JetStream servers via MQTT-over-WebSocket, even without MQTT enabled. Patch now to prevent DoS.
CVE-2026-58251 exposes a queue subscribe authorisation bypass in NATS Server, risking unauthorised message access on Azure-hosted workloads.
CVE-2026-58207 allows remote attackers to crash NATS Server via an integer overflow in Connz pagination, risking denial of service in cloud-native environm
CVE-2026-57219 exposes OAuth 2.0 client credentials in RabbitMQ via an unauthenticated HTTP API endpoint under certain configurations. Learn the risk and m
CVE-2026-15028 is a libarchive heap overflow triggered by malformed TAR PAX headers, affecting Azure workloads. Learn the security impact and mitigation st
CVE-2026-39822 enables root directory escape via symlink and trailing slash path manipulation. Learn the Azure security impact and mitigation steps.
CVE-2026-57432 affects Perl up to 5.43.10, causing an integer overflow and heap out-of-bounds read in pack/unpack. Azure workloads using Perl are at risk.
CVE-2026-15738 in AWS Load Balancer Controller allows cross-namespace traffic interception via incorrect HTTPRoute/GRPCRoute priority ordering on shared AL
CVE-2026-15643 is an SSRF flaw in AWS HealthLake MCP Server before 0.0.14 that lets authenticated attackers steal AWS temporary credentials via a crafted p
Microsoft fixes a record 570 security vulnerabilities in July 2026 Patch Tuesday, nearly triple last month's count. Here's what cloud security teams need t
LabubaRAT is a Rust-based RAT that masquerades as NVIDIA software to gain persistent access to Windows hosts. Here's what security teams need to know.
CVE-2026-42900 is a race condition flaw in Windows App Store enabling remote privilege escalation. Learn the risks and recommended mitigations.
CVE-2026-42975 is a heap buffer overflow in the Windows Bluetooth Port Driver enabling unauthenticated remote code execution over adjacent networks.
CVE-2026-42982 allows local privilege escalation via a flaw in Windows Secure Kernel Mode. Azure VM and VDI environments should patch immediately.
CVE-2026-47296 is a SQL injection flaw in Microsoft SQL Server enabling local privilege escalation. Patch immediately to protect Azure and on-prem deployme
CVE-2026-47300 is an ASP.NET Core elevation of privilege flaw caused by a faulty authentication implementation, allowing attackers to escalate access over
CVE-2026-47302 allows unauthenticated attackers to deny service via unbounded resource allocation in .NET. Learn the impact and mitigation steps.
CVE-2026-47303 is an ASP.NET Core elevation of privilege flaw allowing authenticated attackers to escalate permissions over a network. Patch now.
CVE-2026-48571 is a use-after-free flaw in Windows App Package Installer allowing local privilege escalation. Patch Azure Windows VMs immediately.
CVE-2026-48572 is a race condition flaw in Windows App Installer allowing local privilege escalation. Learn what cloud architects should do now.
CVE-2026-49162 is a use-after-free vulnerability in Microsoft Brokering File System enabling local privilege escalation. Patch Windows hosts promptly.
CVE-2026-49166 is a use-after-free flaw in Windows printer drivers enabling local privilege escalation. Patch Azure VMs and Windows endpoints urgently.
CVE-2026-49167 is a Windows Kernel use-after-free flaw enabling local privilege escalation. Azure VM and hybrid workloads are at risk โ patch promptly.
CVE-2026-49168 is an integer overflow flaw in Windows Storage Spaces Direct allowing privilege escalation via physical attack. Patch Windows Server and Azu
CVE-2026-49169 is a use-after-free flaw in Windows DNS Server enabling authenticated remote code execution. Patch immediately to protect critical infrastru
Two RabbitMQ access control flaws can expose OAuth client secrets and cross-tenant queue metadata, risking messaging infrastructure takeover.
11 Microsoft-signed Linux UEFI shims can be exploited to bypass Secure Boot, enabling bootkit deployment. Find out what architects should do now.
xAI's Grok Build AI coding tool was silently uploading full source code repos to the cloud. Here's what cloud security teams should do now.
A jailbroken Gemini AI helped a Russian fraudster autonomously deploy a C2 server in 6 minutes, highlighting the growing threat of AI-assisted cybercrime.
Attackers exploit OAuth client ID spoofing to validate stolen Microsoft Entra credentials silently, bypassing sign-in alerts. Learn how to protect your env
FIFA's network was exploitable by users with minimal access. Learn what this means for network segmentation and zero-trust architecture.
xAI's Grok Build CLI uploaded entire Git repositories to a Google Cloud Storage bucket, exposing source code and commit history beyond intended scope.
CrashStealer macOS infostealer uses a notarised dropper to bypass Gatekeeper, harvesting credentials via native C++. What security teams need to know.
Google and Microsoft pulled ModHeader after a dormant browsing-history collector was found in the extension. Learn what cloud security teams should do now.
This week's top cloud security threats: Citrix Bleed 2 ransomware attacks, ShareFile vulnerabilities, and AI coding tools weaponised by attackers.
CISA's postmortem on a contractor leaking AWS GovCloud keys to GitHub for 6 months reveals critical gaps in secrets management and incident response.
MemGhost lets attackers plant false memories in AI agents via a single email, silently manipulating future responses across sessions. Here's what architect
Forg365 PhaaS targets Microsoft 365 with device code phishing and AitM session theft, bypassing MFA. Learn what cloud architects should do now.
World Cup grudge attackers allegedly used year-old infostealer credentials to access the Argentine FA. What cloud security teams must do now.
Progress Software orders emergency ShareFile server shutdown over an undisclosed security threat. What cloud architects need to know and do now.
CVE-2022-4543 'EntryBleed' lets local attackers bypass Linux KASLR via TLB timing on Intel systems. Learn the impact for Azure Linux workloads.
A misconfigured Python HTTP server exposed three live Evilginx phishing campaigns targeting Microsoft 365. Learn what architects should do to defend agains
CVE-2026-59874 in node-tar allows a negative tar entry size to trigger an infinite loop. Learn the impact and how to protect Azure workloads.
CVE-2026-59873 is a denial-of-service bug in node-tar allowing malicious archives to exhaust resources. Azure Node.js workloads should patch immediately.
CVE-2026-59871 affects node-tar, causing process crashes via PAX numeric path type confusion. Azure workloads using Node.js may be at risk of denial of ser
CVE-2026-15308 lets attackers exhaust CPU via Python's HTMLParser on Azure workloads. Learn the impact and how to mitigate this DoS risk.
CVE-2026-14428 affects the Dawn WebGPU component in Chromium-based Microsoft Edge. Update your browser to mitigate this input validation vulnerability.
CVE-2026-13777 affects Chromium's iOS web input validation, impacting Microsoft Edge. Learn what cloud security teams should do now.
CVE-2026-14397 is an out of bounds write flaw in ANGLE affecting Chromium-based browsers including Microsoft Edge. Update immediately to mitigate risk.
CVE-2026-14396 is an out-of-bounds read in ANGLE affecting Chromium-based Microsoft Edge. Learn the security impact and remediation steps.
CVE-2026-13778 is a use-after-free flaw in Chromium's WebUSB component affecting Microsoft Edge. Update Edge immediately to mitigate exploitation risk.
CVE-2026-14401 affects Microsoft Edge via a Chromium ANGLE input validation flaw. Learn the security impact and steps to protect your environment.
CVE-2026-14412 affects Microsoft Edge via a Chromium ANGLE vulnerability. Learn the security impact and recommended remediation steps for cloud environment
CVE-2026-14410 affects the Skia graphics library in Chromium-based browsers including Microsoft Edge. Update Edge immediately to mitigate risk.
CVE-2026-14409 is a Chromium V8 implementation flaw affecting Microsoft Edge. Learn the security impact and patching advice for cloud environments.
CVE-2026-14407 is a Chromium V8 inappropriate implementation vulnerability affecting Microsoft Edge. Learn the security impact and recommended actions.
CVE-2026-14406 is an out-of-bounds read in Chromium's V8 engine affecting Microsoft Edge. Update Edge immediately to mitigate memory leak risks.
CVE-2026-14405 is a V8 uninitialized memory vulnerability in Chromium affecting Microsoft Edge. Learn the security impact and patching advice.
CVE-2026-14404 affects PDFium in Chromium-based Microsoft Edge. Learn what cloud security teams should do to mitigate this browser vulnerability.
CVE-2026-14403 is a use-after-free flaw in Chrome's V8 engine affecting Microsoft Edge. Learn the security impact and remediation steps for cloud environme
CVE-2026-14402 is an uninitialized use flaw in ANGLE affecting Chromium-based Microsoft Edge. Update Edge immediately to mitigate potential exploitation.
CVE-2026-14400 is an out-of-bounds write flaw in Chromium's ANGLE library affecting Microsoft Edge. Learn the security impact and remediation steps.
CVE-2026-14399 affects the Dawn WebGPU component in Chromium and Microsoft Edge. Learn what cloud security teams should do to mitigate this High severity f
CVE-2026-14398 is a use-after-free flaw in Chromium's ANGLE graphics layer affecting Microsoft Edge. Patch immediately to prevent potential code execution.
CVE-2026-14395 is a high-severity out-of-bounds write flaw in Chromium's V8 engine affecting Microsoft Edge. Update browsers immediately to mitigate risk.
CVE-2026-14394 is a use-after-free flaw in Chromium's V8 engine affecting Microsoft Edge. Learn the security impact and remediation steps.
China- and India-linked threat actors compromised Pakistani police web portals, accessing criminal and citizen data in a two-year espionage campaign.
A critical 29-year-old Squid proxy vulnerability dubbed Squidbleed can leak HTTP requests. Learn what cloud architects need to do now.
Microsoft's GigaWiper bundles multiple wiper and ransomware families into one modular Windows backdoor. Here's what cloud security teams need to know.
A compromised GitHub repo pushed a malicious npm package stealing crypto wallet private keys. Find out what architects must do now.
Binarly finds six U-Boot vulnerabilities affecting routers, cameras and server BMCs โ two allow pre-OS code execution via malicious firmware images.
Ledger Donjon researchers show a laser pulse can reset Tangem crypto wallet card passwords with no patch possible. Here's what you need to know.
Three patched OpenClaw AI assistant flaws can be chained via WhatsApp to achieve credential theft, privilege escalation, and host code execution.
Silver Fox's MODBEACON RAT uses gRPC streaming to hide C2 traffic. Learn what cloud security architects should do to detect and block this threat.
XRING is an unpatched flaw in Alibaba's XQUIC library letting any remote attacker crash HTTP/3 servers with 260 bytes of valid traffic. No fix yet.
The WP-SHELLSTORM campaign targeted 1.4 million WordPress sites. An exposed hacker server revealed tools, logs, and backdoor techniques used at scale.
281 free Android VPN apps tested: many leak traffic, send unencrypted data, and embed trackers. Apps affected installed 2.4 billion times.
Attackers use vishing and a phishing kit to enrol rogue Microsoft Entra passkeys, gaining persistent M365 access for data extortion. Here's what to do.
Microsoft flags CVE-2026-56288, a NULL pointer dereference in GNU patch, as affecting Azure. Learn the risk and how to remediate affected Linux workloads.
CVE-2026-59818 allows revoked TLS client certificates to authenticate to etcd gRPC listeners, bypassing CRL enforcement. Critical risk for Kubernetes on Az
Leaked negotiations reveal an unnamed US county paid $1M to cybercriminals. Learn what this means for public sector cyber resilience and incident response.
Microsoft analyses GigaWiper, a Windows backdoor combining disk wiping, fake ransomware with no recovery key, and spyware. What cloud architects need to kn
The EU Chat Control CSAM-scanning rule survives a parliamentary vote. Here's what cloud security architects need to know about encryption and compliance ri
Microsoft has patched the RoguePlanet Defender zero-day exploited by Nightmare Eclipse. Learn what cloud security teams should do now.
GodDamn ransomware uses the PoisonX kernel driver to disable endpoint defences before encrypting systems. Learn what cloud security architects should do no
CVE-2026-53359 is a KVM x86 use-after-free flaw in shadow paging that could allow privilege escalation in Azure virtualised environments.
CVE-2026-14355 exposes a memory corruption flaw in PHP's OpenSSL extension via AES-WRAP-PAD. Azure PHP workloads should patch immediately.
CVE-2026-8925 is a SASL double-free memory flaw affecting Azure. Learn the security impact and mitigation steps for cloud architects.
Microsoft patches RoguePlanet (CVE-2026-50656), a CVSS 7.8 privilege escalation flaw in the Malware Protection Engine that can grant SYSTEM privileges.
CVE-2026-11856 exposes a cross-origin Digest auth state leak in Azure. Learn the security impact and what cloud architects should do now.
CVE-2026-9547 exposes an SSH improper host validation flaw in Azure, risking man-in-the-middle attacks on secure administrative connections.
CVE-2025-61727 exposes a flaw in Go's crypto/x509 package allowing wildcard TLS certificates to bypass DNS name constraints, risking domain spoofing.
CVE-2025-58188 causes a denial-of-service panic in Go's crypto/x509 when handling DSA public key certificates. Azure workloads using Go are at risk.
CVE-2025-61724 affects Go's net/textproto package, enabling excessive CPU consumption. Learn the impact on Azure workloads and how to remediate.
The 'Friendly Fire' PoC shows Claude Code and OpenAI Codex can be manipulated into executing attacker code when scanning open-source repos in autonomous mo
Wiz discovers GhostApproval symlink flaws in AI coding tools including Amazon Q, Claude Code and Cursor, enabling malicious repos to hijack developer machi
Suspected Chinese state actors are compromising Roundcube mailservers at universities. Learn what security architects should do to respond and protect emai
HalluSquatting exploits AI hallucinations to deliver botnet malware via fake packages. Learn the supply chain risk and how to defend your pipelines.
CVE-2026-42980 is a Windows NT OS Kernel elevation of privilege flaw. Latest update is acknowledgement-only โ no new patches or mitigations issued.
CVE-2026-58525 allows remote attackers to bypass security features in Microsoft Edge (Chromium-based). Learn the risk and remediation steps.
The GhostApproval bug in AI coding agents exposes flawed human-in-the-loop controls, allowing unauthorised actions despite apparent user approval. Here's w
China's national vulnerability database alleges older Claude Code versions contain a monitoring mechanism that may exfiltrate user data to remote servers.
The EvilTokens ghost phishing campaign evades URL scanning by decrypting malicious pages in-browser, putting Microsoft 365 accounts at risk across the US a
SCMBANKER malware uses fake CAPTCHA pages to trick users into running malicious PowerShell commands, targeting Mexican banks and crypto exchanges.
New research shows GitHub's Verified badge can be replicated without the signing key, undermining commit integrity checks in software supply chains.
Attackers are bypassing passkeys by targeting MFA and account recovery flows. Learn what cloud security architects must do to protect identity verification
Five Eyes agencies warn AI models are enabling autonomous cyberattacks, closing the gap between attacker skill and capability. What this means for cloud se
Chinese APT UAT-7810 deploys new LONGLEASH malware to grow its LapDogs ORB network by compromising internet-facing networking devices.
A GitHub AI agent vulnerability dubbed GitLost exposes private repositories via simple prompts, with no patch or vendor documentation available.
The CAI cloud worm evicts rival malware, steals cloud credentials, and deploys cryptominers โ here's what security architects need to know.
RedWing is a Telegram-based Android malware-as-a-service enabling bank fraud and OTP theft. Learn what security teams should do to mitigate the risk.
A critical Dialogflow CX vulnerability allowed attackers with agent edit rights to hijack other chatbots, steal user data, and inject malicious messages wi
Greek Predatorgate victims launch an โฌ8M lawsuit against Predator spyware makers as EU faces pressure to regulate commercial surveillance tools.
The DEBULL campaign abuses Microsoft's device code authentication flow to hijack M365 accounts without fake login pages, bypassing MFA.
A malicious public GitHub issue can trick AI agentic workflows into leaking private repo data โ no credentials required. Here's what architects need to kno
CVE-2026-45638 is a Windows WinSock elevation of privilege flaw affecting Azure VMs and Windows servers. Acknowledgement update โ no new patches issued.
Most enterprises now report AI-related security incidents after rushing deployments. Learn what cloud security architects must do to reduce AI risk.
Attackers pose as IT helpdesk staff on Microsoft Teams to gain remote access and deploy EtherRAT malware. Learn how to protect your organisation.
Suspected China-aligned hackers exploit critical Roundcube flaw CVE-2024-42009 to steal credentials from US and Canadian university webmail accounts.
CVE-2026-9080 is a Use-After-Free vulnerability in socket callbacks affecting Azure. Learn the security impact and mitigation steps.
CVE-2026-8926 exposes passwords when netrc files and user credentials appear in URLs. Learn the Azure security impact and mitigation steps.
CVE-2026-8286 exposes a STARTTLS connection reuse bug in Azure, potentially allowing credential exposure or man-in-the-middle attacks on encrypted sessions
CVE-2026-8458 affects Microsoft Azure, involving wrong credential reuse across services. Learn the risks and how to protect your cloud environment.
CVE-2026-8924 exploits trailing dot domains to set super cookies in Azure environments, risking session hijacking and cross-domain data leakage.
CVE-2026-8932 exposes an incomplete mTLS config matching bug in Azure connection reuse, potentially bypassing mutual authentication controls.
CVE-2026-9545 exposes sensitive data via HTTP/3 early data in Azure. Learn the security impact and what architects should do now.
CVE-2026-14647 is an out-of-bounds vulnerability in ONNX Runtime affecting Azure AI workloads. Learn the impact and mitigation steps.
CVE-2026-12480 allows arbitrary file reads in Keras via HDF5 virtual dataset bypass. Learn the impact on Azure ML and cloud AI workloads.
CVE-2026-54891 allows plaintext APPLICATION_DATA injected during TLS handshake to reach client apps post-handshake, undermining transport security in Azure
CVE-2026-54886 exposes Azure SSH SFTP servers to denial of service via an infinite loop triggered by malformed extended channel data. Patch now.
CVE-2026-55952 allows attackers to crash Azure services via a malformed TLS 1.3 ClientHello PSK extension. Patch and mitigate now.
CVE-2026-14471 affects AWS mcp-gateway-registry v1.0.3โ1.0.12, enabling authenticated SQL injection that exposes API keys and allows data tampering.
Iran-linked MOIS hackers deploy the undocumented Cavern C2 framework against Israeli IT providers and government sectors. What security teams need to know.
An MEP on the EU spyware inquiry has been infected with Pegasus. Campaigners demand urgent action on stalled PEGA Committee recommendations.
Learn how AWS Cedar enforces least-privilege authorisation across multi-agent AI chains, preventing silent privilege escalation in agentic systems.
A suspected China-nexus group is deploying DcRAT via fake Indian tax software in spear-phishing attacks targeting finance and tax professionals.
ShinyHunters leaks 2.3 million Moody Bible Institute records including names, addresses and DOBs. What cloud security architects should do now.
QuimaRAT is a Java-based RAT sold as a MaaS service targeting Windows, Linux, and macOS. Learn what cloud architects need to know to protect hybrid environ
A patched Opera GX vulnerability let malicious sites silently install browser extensions to steal data from visited pages, including Gmail addresses.
SkillCloak uses self-extracting packing to bypass static scanners for AI coding agent skills 90%+ of the time โ here's what security architects need to kno
Banks offering optional MFA expose customers to credential theft and account takeover. Find out what cloud security architects should consider.
A US government entity paid $1 million to Kairos to suppress leaked data. No ransomware was used โ a pure extortion model cloud architects must prepare for
North Korean hackers publish 108 malicious packages across npm, Go, Packagist and Chrome in the active PolinRider supply chain campaign.
Seven unpatched vulnerabilities in the FatFs filesystem library put millions of embedded devices at risk, including cameras, drones, and industrial control
The Avalon modular malware framework combines ransomware, credential theft, and lateral movement in one toolkit. Here's what cloud security architects need
North Korea-linked actors published malicious npm packages mimicking Rollup polyfill tools to steal developer credentials via supply chain attack.
AdaptHealth discloses cloud breach after attackers social-engineered a third-party contractor, exposing patient health data and insurance billing passwords
CVE-2026-14125 affects the ANGLE graphics layer in Chromium-based Microsoft Edge. Learn what cloud security teams should do to mitigate this vulnerability.
CVE-2026-13775 is a use-after-free flaw in Chromium's GPU component affecting Microsoft Edge. Learn the security impact and remediation steps.
CVE-2026-14153 is a Chromium Glic implementation flaw affecting Microsoft Edge. Learn what cloud security teams should do to mitigate risk.
CVE-2026-56646 is a spoofing vulnerability in Microsoft Edge (Chromium-based) exposing sensitive data to unauthorised network attackers. Patch immediately.
CVE-2026-57983 allows remote attackers to bypass security features in Microsoft Edge. Learn the risk and how to protect your cloud environments.
CVE-2026-57985 is a remote code execution flaw in Microsoft Edge (Chromium-based). Learn the impact and how to protect your cloud environment.
CVE-2026-57987 is an SSRF spoofing vulnerability in Microsoft Edge (Chromium-based) allowing unauthenticated network attackers to forge requests. Patch now
CVE-2026-57993 is an SSRF vulnerability in Microsoft Edge (Chromium-based) enabling unauthenticated network spoofing. Learn the security impact and mitigat
CVE-2026-58282 affects Microsoft Edge (Chromium-based), enabling network attackers to spoof content via improper access controls. Patch immediately.
CVE-2026-58283 is a type confusion flaw in Microsoft Edge allowing network-based spoofing attacks. Learn the impact and mitigation steps for enterprise env
CVE-2026-58287 is a use-after-free flaw in Microsoft Edge allowing remote code execution without authentication. Patch immediately.
CVE-2026-58299 is a race condition RCE vulnerability in Microsoft Edge for Android allowing unauthenticated remote code execution over a network.
Armored Likho targets government and power sector organisations with BusySnake stealer malware, blending espionage and financial cybercrime across multiple
Google and the FBI have disrupted the NetNut residential proxy botnet spanning 2 million devices. Other proxy services may share the same infrastructure.
Citizen Lab confirms MEP Stelios Kouloglou was hacked with Pegasus spyware while investigating surveillance tool abuse in the EU. Key implications for mobi
PamStealer targets macOS users via fake Maccy sites, using PAM abuse and AppleScript to steal login credentials and sensitive data.
A developer was warned by Google about a cloud account hijack but still faced $11,000 in fraudulent charges. Here's what architects must do to protect bill
The FBI seized hundreds of NetNut domains tied to the Popa botnet, a 2M+ device network used to anonymise malicious traffic. Here's what cloud architects n
Researchers reveal the first fully autonomous AI-driven ransomware attack. Cloud architects must act now on backups and LLM security controls.
Researchers found login logs exposing a threat actor working across both INC and Lynx ransomware gangs via FortiBleed exploitation โ here's what it means f
CVE-2026-26145 allows authorised attackers to escalate privileges in Azure Synapse Analytics over a network. Learn the risk and how to respond.
CVE-2026-41106 is an open redirect vulnerability in Microsoft 365 Copilot that enables unauthenticated privilege escalation over a network.
CVE-2026-45499 is an SSRF vulnerability in Azure OpenAI enabling authenticated attackers to escalate privileges over a network. Learn the risks and mitigat
Microsoft Edge (Chromium-based) is affected by a remote code execution vulnerability CVE-2026-50521. Update to the latest Edge version immediately.
CVE-2026-54998 allows authenticated attackers to elevate privileges in Microsoft Exchange Online. Learn the impact and what architects should do now.
CVE-2026-57100 is an SSRF flaw in Microsoft Entra Provisioning Service (SyncFabric) enabling privilege escalation. Learn the impact and mitigation steps.
ToddyCat's Umbrij malware exploits OAuth and the Google API to silently access corporate Gmail. Learn what cloud architects should do now.
Medtronic warns patients their health data may have been stolen by ShinyHunters, months after the breach. What cloud security teams need to know.
Traditional IGA tools weren't built for AI agents. Learn why autonomous principals create identity governance blind spots and what architects should do.
ChocoPoC RAT hides in fake GitHub PoC repos targeting vulnerability researchers, stealing passwords, cookies and granting remote shell access.
A red team earned network admin credentials simply by shovelling snow. This social engineering case study highlights critical gaps in physical and identity
EvilTokens is a full BEC operations platform exploiting OAuth device-code flow to steal tokens and bypass MFA in Microsoft 365 environments.
Check Point reveals DeepSeek AI can be prompted to produce functional in-browser ransomware with minimal effort, posing serious risks for developer teams u
CVE-2026-14265 enables remote code execution via unsafe deserialization in the AWS Advanced JDBC Wrapper RemoteQueryCachePlugin. Versions 3.3.0โ4.0.0 affec
A 19-year-old alleged Scattered Spider member has been extradited from Finland to the US on hacking and fraud charges. What cloud security teams should kno
CVE-2026-13760 is an OS command injection flaw in AWS CDK's Docker bundling pipeline affecting aws-cdk-lib < 2.260.0. Upgrade immediately.
CVE-2026-13769 in AWS CLI exposes credentials as world-readable on Unix systems. Affects CLI v1 โค1.44.77 and v2 โค2.34.28. Patch now.
Attackers use SEO-poisoned fake software sites to deliver AsyncRAT via ScreenConnect remote access tool. Learn how to protect your environment.
Red teamers turned Claude Desktop into a malicious agent using prompt injection, highlighting serious risks of AI assistants in enterprise environments.
DeepSeek-generated ransomware exploits a Chromium browser API to run entirely in-browser on Windows and Android โ bypassing traditional endpoint defences.
CVE-2026-57062 exposes a GnuPG CMS parsing flaw where a 4-byte AES-GCM ICV is accepted instead of 12 bytes, weakening encrypted message integrity.
CVE-2026-7532 exposes a wolfSSL flaw where IP name constraints go unenforced, risking certificate validation bypass in Azure and other workloads.
CVE-2026-6291 exposes a Bleichenbacher padding oracle in Azure PKCS#7 KTRI RSA PKCS#1 v1.5 decryption, risking cryptographic key exposure.
CVE-2026-57918 is an integer underflow bug in libnfs โค6.0.2 that can be triggered by a crafted NFS server, risking memory corruption on client systems.
CVE-2026-13325 in KubeVirt's disableTLS setting removes authentication from virtqemud proxy on all interfaces, risking unauthorised VM access on Azure.
CVE-2026-13218 is a KubeVirt symlink vulnerability allowing virt-launcher to overwrite host files. Learn the risk and mitigation steps for Azure Kubernetes
CVE-2026-13208 exposes a KubeVirt virt-handler flaw where unauthenticated gRPC requests can spoof VMI identity, risking VM integrity on Azure Kubernetes cl
CVE-2026-13322 is a KubeVirt denial-of-service vulnerability in virt-handler. Unbounded virtio-serial reads cause OOM crashes affecting Azure Kubernetes wo
CVE-2026-58014 is an off-by-one error in GLib's key file parser, potentially enabling memory corruption on Azure Linux workloads. Patch now.
CVE-2026-58012 is a GLib buffer over-read flaw in g_regex_replace() affecting Azure and Linux workloads. Learn the security impact and remediation steps.
CVE-2026-58016 is a GLib integer underflow flaw in D-Bus XML parsing that may allow memory corruption or code execution on Azure Linux workloads.
CVE-2026-58015 is a path traversal vulnerability in GLib's D-Bus SHA-1 auth mechanism affecting Azure Linux workloads. Patch promptly.
CVE-2026-58010 is a GLib buffer over-read vulnerability affecting Azure Linux workloads. Learn the risk and how to remediate affected systems.
An automated password spray targeting Azure CLI has made 81M+ attempts, compromising 78+ accounts. Learn how to detect and defend against this ongoing thre
Research into 3,000 live ClickFix payloads reveals API-driven infrastructure serving unique obfuscated malware per visitor, with a new method bypassing Win
Citrix patches six NetScaler ADC and Gateway vulnerabilities including CVE-2026-8451 (CVSS 8.8), enabling arbitrary file reads and denial-of-service attack
Microsoft research reveals attackers can hijack AI agents via poisoned MCP tool descriptions, silently exfiltrating corporate data without triggering alert
RustDuck is a fast-evolving Rust-based botnet targeting routers, IP cameras, and servers for DDoS attacks. Here's what cloud architects need to know.
A Huntress threat hunter allegedly warned a ransomware criminal about a law enforcement probe, highlighting insider threat risks within security operations
McAfee Labs flags Silent Swap, a crypto clipper using a fake Google Notes browser extension to silently redirect wallet addresses during transactions.
GuardFall bypasses safety guardrails in 10 of 11 AI coding agents using old shell injection tricks, exposing CI/CD pipelines to arbitrary command execution
CVE-2026-42910 affects the Windows Hotpatch Monitoring Service with an elevation of privilege risk. Latest update is acknowledgement-only. Learn what Azure
A study found 282 of 444 iPhone AI apps expose LLM API keys in network traffic, enabling attackers to make model requests at the developer's expense.
Check Point Research reveals pre-planned fraud infrastructure targeting FIFA World Cup 2026 across 10 languages and 3 sectors. Here's what security teams n
Six flaws in Apple AirDrop and Google Quick Share let nearby attackers crash devices or bypass checks with no user interaction. What security teams must do
LayerX's BioShocking technique tricks AI browsers including ChatGPT Atlas and Claude into leaking user credentials via prompt manipulation. Here's what you
CVE-2026-11979 is a stack-based buffer overflow in libxml2 affecting Azure. Learn the risks and how to protect your cloud workloads.
Microsoft flags CVE-2026-41992, a global buffer overflow in GNU gzip, affecting Azure environments. Learn the risk and how to remediate.
CVE-2026-54371 affects attr < 2.6.0, enabling symlink traversal privilege escalation via getfattr/setfattr on Linux systems including Azure workloads.
CVE-2026-54369 affects acl < 2.4.0 on Linux, enabling symlink traversal privilege escalation via libacl. Azure workloads running Linux may be at risk.
Apple patches 30+ iOS, macOS and Safari vulnerabilities, including four WebKit memory corruption flaws discovered using AI tools. Update devices now.
India's RBI-mandated .bank.in domain registry exposed an open API leaking sensitive registrant data, enabling impersonation of bank officials.
Researchers bypassed LLM safety guardrails using role-based prompt injection, exposing a persistent vulnerability in AI systems. Here's what cloud security
AWS WAF HTTP/2 multi-frame inspection flaws (CVE-2026-13762, CVE-2026-13763) could allow WAF bypass on ALB. Action required for ALB deployments.
Microsoft uncovered a malicious Chrome extension posing as Perplexity AI that intercepted all searches and address bar input, routing data to attacker serv
Researchers found a new class of factorable RSA keys with sparse moduli in real-world TLS, SSH, and PGP deployments. Check your keys with badkeys now.
China-linked Mustang Panda uses Zoho WorkDrive as a C2 channel in active espionage attacks on Indian government and hydropower targets.
This week's security recap covers the DirtyClone Linux kernel privilege escalation flaw, Turla backdoor activity, AI malware tricks, and active infostealer
Infoblox finds 236,000+ DCloud Uni-App sites running crypto scams, pig-butchering fraud, WhatsApp phishing, and wallet drainers at global scale.
Russian APT Gamaredon launched 35 spear-phishing campaigns in 2025, deploying new malware and abusing cloud services to target Ukrainian organisations.
Nissan confirms a breach of Oracle PeopleSoft systems may have exposed employee SSNs and payroll data via an unknown vulnerability. What architects should
Microsoft removed 119 Edge extensions hiding malware in images and fonts. The StegoAd campaign stole credentials and ran ad fraud from 2021 onwards.
CVE-2026-58058 is an integer underflow in Nmap's IPv6 extension header parsing. Learn the risk and mitigation steps for Azure security teams.
CVE-2026-58055 affects nghttp2 nghttpx, enabling HTTP request/response smuggling via Upgrade requests. Azure workloads using nghttpx should patch immediate
CVE-2026-58051 is a libssh2 memory corruption flaw affecting Azure workloads. Learn the risk and how to remediate this uninitialised pointer vulnerability.
CVE-2026-58050 is a libssh2 integer overflow flaw affecting Azure workloads. Learn the risk, impact, and remediation steps for cloud engineers.
CVE-2026-52908 affects the Linux RDMA subsystem's rereg_mr access validation. Learn the security impact for Azure HPC and RDMA workloads.
CVE-2026-52909 affects the Linux kernel ip6_vti subsystem on Azure. Learn the risk and mitigation steps for cloud security teams.
CVE-2026-52910 is a Linux kernel BPF use-after-free flaw affecting Azure workloads. Patch Linux VMs and AKS nodes promptly to mitigate risk.
Attackers hijacked npm and Go packages to silently deploy a Python infostealer via VS Code tasks, bypassing npm v12 security controls on Windows, Linux and
CVE-2023-6606 is a Linux kernel out-of-bounds read flaw in smbCalcSize, affecting Azure Linux VMs. Learn the impact and remediation steps.
CVE-2025-40158 affects the Linux kernel's IPv6 ip6_output() function. Learn the risk to Azure Linux VMs and what architects should do now.
CVE-2025-40170 is a Linux kernel networking vulnerability affecting Azure workloads. Learn the risk and remediation steps for cloud security teams.
CVE-2025-40168 is a Linux kernel SMC use-after-free vulnerability affecting Azure VMs. Learn the impact and remediation steps for cloud architects.
CVE-2025-40139 is a Linux kernel SMC subsystem race condition flaw affecting Azure Linux workloads. Learn the impact and patching advice.
CVE-2025-21825 affects the Linux kernel BPF timer subsystem on PREEMPT_RT builds. Azure VM and container workloads may be at risk โ patch promptly.
Russia's intelligence services used fake IT support texts to steal messaging credentials from officials in Ukraine, Europe, and the US, per SSU and FBI.
AI tools are surfacing hidden vulnerabilities faster than teams can patch them. Here's what cloud security architects need to know and act on now.
CVE-2026-13038 is a use-after-free flaw in Chromium's Autofill component affecting Microsoft Edge. Update Edge immediately to mitigate potential code execu
CVE-2026-13036 is a use-after-free flaw in Chromium's Blink engine affecting Microsoft Edge. Update Edge immediately to mitigate potential code execution.
CVE-2026-13035 is a use-after-free flaw in Chromium Bluetooth affecting Microsoft Edge. Learn the security impact and remediation steps.
Microsoft Edge inherits a Chromium out-of-bounds read fix (CVE-2026-13033) in Blink InterestGroups. Update Edge immediately to mitigate memory disclosure r
CVE-2026-13031 is a use-after-free flaw in Chromium's Blink engine affecting Microsoft Edge. Learn the security impact and remediation steps.
CVE-2026-13029 is a use-after-free flaw in Chromium's Web Authentication component affecting Microsoft Edge. Learn the security impact and remediation step
CVE-2026-13027 is a use-after-free flaw in Chromium's FileSystem component affecting Microsoft Edge. Learn the security impact and remediation steps.
CVE-2026-13026 is a use-after-free flaw in Chromium's Digital Credentials component affecting Microsoft Edge. Learn the security impact and remediation ste
CVE-2026-13025 affects Chromium DevTools with insufficient input validation. Microsoft Edge users should update immediately to receive the upstream fix.
CVE-2026-13024 affects Microsoft Edge via a Chromium navigation flaw with insufficient input validation. Learn the impact and remediation steps.
CVE-2026-13023 is an uninitialized memory use vulnerability in Chromium's GPU component affecting Microsoft Edge. Learn the security impact and remediation
CVE-2026-13021 affects Chromium's DeviceBoundSessionCredentials in Microsoft Edge. Learn about the risk and how to remediate across enterprise endpoints.
US Secret Service agents used personal phones on protective missions with no threat detection on government devices, exposing serious MDM and endpoint secu
Russian intelligence actors are phishing Signal Backup Recovery Keys, granting persistent access to full message history. FBI and CISA issue updated adviso
Kaspersky tracks StrikeShark campaign using SharkLoader to deploy Cobalt Strike Beacon against government and diplomatic targets in Asia.
Chinese-speaking APT group CL-STA-1062 targets Southeast Asian government and energy sectors with the new TinyRCT backdoor. What security teams need to kno
A flaw in Amazon Q allowed malicious Git repos to execute code and steal cloud credentials. Learn what cloud security architects should do now.
CVE-2026-12957 (CVSS 8.5) in Amazon Q Developer let malicious repos steal AWS credentials via MCP configs. Patch now.
Microsoft uncovers the Miasma campaign targeting npm packages including Leo Platform and RStreams, stealing developer secrets and spreading via maintainer
CVE-2026-43503 (DirtyClone) lets local users gain root on Linux via cloned packet memory corruption. CVSS 8.8 โ patch now.
AI agents are outpacing enterprise identity governance. Learn why autonomous actors pose a critical IAM risk and what cloud security architects must do now
Miasma malware compromises npm packages and GitHub Actions workflows in an expanding supply chain attack now reaching the Go ecosystem. Here's what to do.
Nearly 1 million passport scans leaked from cannabis dispensary ID verification systems, exposing high-value credentials held by low-security third parties
Microsoft warns of an active phishing campaign targeting hotels in Europe and Asia using photo-themed ZIPs to install a Node.js implant on front-desk syste
CVE-2026-46320 is a kernel memory flaw in tap_get_user_xdp() affecting Linux-based Azure workloads. Learn the risk and remediation steps.
CVE-2026-46321 is a Linux kernel memory leak in tun_xdp_one() affecting Azure Linux workloads. Patch now to prevent denial of service risk.
CVE-2026-45850 affects the Linux kernel IPVS subsystem, skipping IPv6 extension header checksum checks. Key risk for Azure AKS and Linux VM workloads.
CVE-2025-68736 affects the Linux Landlock sandbox module, allowing potential filesystem access control bypass. Azure workloads should be patched promptly.
Google links Russian APT Turla to a new .NET backdoor, STOCKSTAY, used in espionage attacks against Ukrainian government and military targets.
A security boss exempted themselves from MFA, exposing high-value accounts. Here's what cloud security architects must do to prevent executive bypass.
The self-destructing Mistic backdoor is linked to an access broker selling corporate network access to ransomware gangs, targeting insurance, education, an
A former Huntress analyst alleges an insider leaked client data to a ransomware criminal, with the firm accused of suppressing disclosure ahead of its IPO.
A Chrome extension with 10M+ installs can execute arbitrary JavaScript. Learn what cloud security architects should do to mitigate this supply-chain risk.
CVE-2026-41086 is an elevation of privilege vulnerability in Windows Admin Center via Azure Portal. Learn what architects should do to mitigate risk.
CVE-2026-45637 is a Microsoft DWM Core Library elevation of privilege flaw. Latest update is informational only โ no new patches required.
New research shows LLMs cannot truly enforce role separation, making prompt injection a structural flaw. What cloud architects need to know.
Gaslight is a new Rust-based macOS infostealer that embeds prompt injection payloads to trick AI analysis tools into refusing malware examination.
The Mistic backdoor, linked to IAB KongTuke, targets insurance, education and IT firms via ClickFix lures and ModeloRAT in active 2026 campaigns.
CVE-2026-11816 exposes a path traversal flaw in keras-team/keras, putting Azure-hosted ML pipelines at risk. Patch now and review file access controls.
A UK school left its network wide open after storing an admin password in an Active Directory description field โ a reminder of basic security hygiene fail
CVE-2026-20245 in Cisco Catalyst SD-WAN was exploited as a zero-day two months before disclosure, granting attackers root access. Patch immediately.
Europol and private sector partners disrupt Amadey and StealC malware infrastructure, recovering 27M stolen credentials used to fuel ransomware and fraud.
Autonomous AI adversaries are compressing attack timelines to machine speed. Learn what this means for cloud security architects and how to adapt your defe
KDDI has exposed 14.2 million managed email credentials across five ISPs, raising serious risks of account takeover and phishing for affected users.
Mythos discovers Squidbleed, a decades-old memory leak in Squid proxy. Learn the security impact and what cloud architects should do now.
Two Scattered Spider members pleaded guilty in a UK court over the August 2024 cyberattack on Transport for London. Here's what security teams should know.
Two vulnerabilities in AWS Language Servers affect Amazon Q Developer IDE plugins. Learn the impact of CVE-2026-12957 and CVE-2026-12958 and how to remedia
A harmless proof-of-concept AI agent skill evaded every security scanner and reached 26,000 agents, exposing a critical gap in AI supply chain security.
GitHub updates actions/checkout to block pwn request attacks exploiting pull_request_target workflows. What cloud security teams need to know.
Microsoft updates acknowledgement for CVE-2026-33840, a Win32k elevation of privilege flaw. Learn the impact for Azure Windows VM workloads and what to che
CVE-2026-45504 is a Microsoft Exchange Server Elevation of Privilege flaw. This update adds an acknowledgement โ no new patches required.
Agentic AI can execute cyberattacks without human direction. Learn what this means for cloud security architects and how to respond.
Anthropic's safety-hardened Claude Fable 5 model was jailbroken within days, exposing the limits of AI guardrails against cyberattack generation.
Three malicious npm packages impersonating PostCSS tools have been found delivering a Windows RAT. Over 1,000 downloads recorded โ check your pipelines now
Attackers use WhatsApp to deliver malicious VBScript files that silently install ManageEngine RMM software, granting persistent remote access to victims.
Five Eyes agencies warn AI is turning routine cyber incidents into major crises. Key guidance for cloud security architects on board-level accountability.
Extortion group Icarus breaches Klue via Salesforce-linked integrations, hitting hundreds of victims including security firms. What architects must do now.
ShapedPlugin's Pro WordPress plugins were backdoored via a compromised build pipeline. Find out which plugins are affected and what to do now.
Four DifyTap vulnerabilities in the Dify AI platform allow unauthenticated attackers to access other tenants' AI conversations, posing serious multi-tenanc
The Squidbleed vulnerability in Squid Proxy exposes cleartext HTTP requests, credentials, and session tokens to other proxy users. Learn the security impac
Elastic Security Labs exposes OXLOADER, a new malware loader using malicious Google Ads to deliver the CastleStealer infostealer. Learn what security teams
Brazil investigates a breach of its national emergency alert system after an unauthorised message was pushed to mobile devices nationwide.
Attackers are using legacy infrastructure to hijack AI agents. Learn how cloud security architects can reduce this growing risk before it's exploited.
Gizmodo was compromised to serve ClickFix malware prompts targeting Windows users with trojan malware. Here's what security teams need to know.
Hackers are actively exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin to steal API keys and OAuth tokens from 100,000+ sites. Patch now.
CVE-2026-46331 is a Linux kernel net/sched pedit flaw causing page cache corruption. Azure Linux VM and AKS users should patch promptly.
CVE-2026-45446 exposes a tag processing flaw in AES-GCM-SIV and AES-SIV modes for empty messages, risking authentication bypass and data forgery.
CVE-2026-34183 causes unbounded memory growth in Azure's QUIC PATH_CHALLENGE handler, risking denial-of-service. Patch and mitigate now.
CVE-2025-4574 affects the Rust crossbeam-channel crate with a double-free vulnerability on drop, posing memory corruption risks in Azure and Rust-based ser
The usbliter8 exploit achieves arbitrary code execution in Apple A12 and A13 SecureROM. Hardware-level flaw cannot be patched โ affected devices remain vul
The Gentlemen RaaS group distributes GentleKiller, an EDR-killing framework targeting 400+ security processes to disable defences before ransomware deploym
Dutch-led Operation Endgame dismantles SocGholish infrastructure and cleans 14,971 WordPress sites. What cloud architects need to know.
CVE-2026-44817 is a remote code execution flaw in Microsoft Excel for Mac. Learn what's affected and how to protect your organisation.
Microsoft patches CVE-2026-44818, a remote code execution flaw in Excel for Mac. Find out what's affected and how to protect your organisation.
Microsoft patches CVE-2026-44819, a remote code execution flaw in Office for Mac. Learn what's affected and the steps to protect your organisation.
Microsoft patches CVE-2026-44820, a remote code execution flaw in Excel for Mac. Cloud architects should prioritise patching via MDM to prevent potential c
Microsoft patches CVE-2026-44823, a remote code execution vulnerability in Excel for Mac. Learn what's affected and how to protect your organisation.
CVE-2026-44824 is a remote code execution flaw in Microsoft Office for Mac. Apply the latest security update to protect affected devices.
Microsoft patches CVE-2026-45456, a remote code execution flaw in Outlook and Word for Mac. Learn what action cloud security teams need to take.
Microsoft patches CVE-2026-45458, a remote code execution flaw in Outlook and Word for Mac. Mac users should update immediately to stay protected.
CVE-2026-45460 affects Microsoft Office for Android. Learn what this information disclosure vulnerability means and how to protect your organisation.
Microsoft patches a remote code execution flaw in Office for Android (CVE-2026-45461). Apply the update immediately to protect corporate devices from explo
Microsoft patches CVE-2026-45469, a remote code execution flaw in Excel for Mac. Learn what's affected and how to protect your environment.
Microsoft patches CVE-2026-45471, a remote code execution flaw in Microsoft Word for Mac. Update Office for Mac now to stay protected.
Microsoft has patched CVE-2026-45472, a remote code execution flaw in Office for Android. Learn what cloud security architects should do now.
Microsoft patches CVE-2026-45474, a remote code execution flaw in Office for Android. Install the update immediately to protect corporate devices.
CVE-2026-45486 is a remote code execution vulnerability in Microsoft Word for Mac. Update Office for Mac immediately to mitigate the risk.
CVE-2026-45643 is a remote code execution flaw in Microsoft Word for Mac. Learn what's affected and how to patch it quickly.
A third-party vendor breach has compromised personal data of 3 million Texas hunting and fishing licence holders, raising serious third-party risk concerns
Shadow AI's biggest threat is no longer data leakage โ it's uncontrolled access. Learn why AI tool permissions are now a critical enterprise security risk.
Salesforce disabled the Klue Battlecards integration after OAuth token abuse exposed customer data. Learn what cloud security architects should do now.
CVE-2026-10275 is a buffer overflow in OpenSC pkcs11-tool affecting key generation. Learn the risk to Azure and hybrid HSM environments and how to mitigate
CVE-2026-8376 is a heap buffer overflow in Perl up to 5.43.10 on 32-bit builds affecting Azure workloads. Learn the risk and mitigation steps.
CVE-2026-43966 details an HTTP Response Splitting vulnerability in cow_http_struct_hd on Azure. Learn the impact and how to remediate.
CVE-2026-9669 is a stack buffer overflow in Python's bz2.BZ2Decompressor affecting Azure workloads. Learn the risk and mitigation steps.
Microsoft has published CVE-2026-53689 affecting Azure. Learn what cloud security architects need to know and the recommended actions to take.
CVE-2026-42014 is a use-after-free flaw in GnuTLS affecting PKCS#11 token PIN handling. Azure workloads using GnuTLS should patch immediately.
Apple patches CVE-2025-20701, a CVSS 8.8 flaw in Beats Studio Buds allowing nearby attackers to pair without consent and eavesdrop via the microphone.
Researchers link the Popa Android botnet to NetNut and Alarum Technologies. Millions of TV boxes used for ad fraud and account takeovers via residential pr
This week's threat roundup covers Claude AI link abuse, malicious npm C2 packages, device-code phishing, and fileless macOS attacks โ practical guidance fo
Microsoft details a Windows cryptocurrency clipper campaign using USB LNK worm propagation and a Tor-based C2 server, active since February 2026.
INC ransomware has claimed 830+ victims since 2023, filling the void left by LockBit and BlackCat. Here's what cloud security teams need to know.
CVE-2026-32174 affects Azure Bot Service, allowing authenticated attackers to elevate privileges over a network. Learn the impact and remediation steps.
CVE-2026-32208 is an XSS spoofing vulnerability in Microsoft Edge (Chromium-based). Learn the security impact and remediation steps for cloud environments.
CVE-2026-42895 is a command injection vulnerability in Microsoft Copilot allowing unauthenticated network attackers to tamper with the service. Patch now.
CVE-2026-47633 allows unauthenticated attackers to disclose sensitive data via Azure Cost Management. Learn the impact and mitigation steps.
CVE-2026-47645 is an open redirect vulnerability in Microsoft 365 Copilot Business Chat enabling privilege escalation over a network. Learn the risks and m
CVE-2026-47646 is an XSS spoofing vulnerability in Microsoft Dynamics 365 Customer Voice exploitable by unauthenticated attackers over a network.
CVE-2026-47647 is a Dynamics 365 elevation of privilege flaw allowing authenticated attackers to escalate permissions over a network. Patch now.
CVE-2026-48582 is a Microsoft Exchange Online elevation of privilege flaw allowing authenticated attackers to gain higher permissions over a network.
CVE-2026-48584 allows authenticated attackers to escalate privileges in Azure Synapse Analytics over a network. Learn the risk and remediation steps.
CVE-2026-54130 exposes M365 Copilot to unauthenticated information disclosure over a network. Learn the impact and how to protect your organisation.
DragonForce ransomware uses a Go-based RAT to hide C2 traffic inside Microsoft Teams relay infrastructure, evading detection on enterprise networks.
Orphaned AI agents with standing privileges pose serious access control risks. Learn how to audit, govern, and remediate hidden exposure in your cloud envi
PCI DSS v4.0 makes third-party checkout scripts a compliance requirement. Learn what cloud architects must do to protect payment pages and pass QSA audits.
CVE-2026-46274 fixes a missing hash check in Linux io_wq_remove_pending(), risking memory corruption on Azure Linux VMs and AKS workloads.
CVE-2026-28387 is a use-after-free bug in DANE client code affecting Azure. Learn the risks and what cloud architects should do now.
CVE-2026-9076 is an out-of-bounds read flaw in CMS password-based decryption affecting Microsoft/Azure. Learn the risk and recommended mitigations.
CVE-2026-34180 is a heap buffer over-read in ASN.1 parsing affecting Azure. Learn the security impact and remediation steps for cloud architects.
CVE-2026-42767 is a NULL pointer dereference in CRMF EncryptedValue decryption affecting Azure. Learn the security impact and recommended mitigations.
CVE-2026-7383 details a heap buffer overflow in ASN.1 multibyte string conversion affecting Azure. Learn the security impact and mitigation steps.
CVE-2026-25681 affects golang.org/x/net/html, causing incorrect DOCTYPE character reference handling. Azure workloads using Go may be at risk.
CVE-2026-25680 is a denial-of-service flaw in golang.org/x/net/html affecting Go apps on Azure. Learn the impact and remediation steps.
CVE-2026-48854 allows attackers to exhaust server memory via unbounded gRPC request bodies in elixir-grpc, risking denial of service on Azure-hosted worklo
A US telco handed new staff unrestricted database access to cleartext customer data. Here's what cloud security architects should learn from it.
Multiple containerd vulnerabilities in GKE allow Pod-privileged attackers to compromise hosts, poison caches, and cause DoS. Patch GKE nodes now.
CVE-2026-12530 in AWS Bedrock AgentCore Python SDK allows argument injection in install_packages(), enabling malicious PyPI redirects and sandbox file expo
Microsoft confirms RoguePlanet zero-day CVE-2026-50656 in Defender's Malware Protection Engine โ a CVSS 7.8 privilege escalation with no patch yet availabl
Microsoft updates CVE-2026-35433, a .NET Elevation of Privilege vulnerability, removing Windows 11 21H1 and 22H2 from the affected platforms list.
CVE-2026-42828 is a Windows Projected File System elevation of privilege flaw. Learn what it means for Azure and hybrid Windows environments.
CVE-2026-45475 is a Microsoft Office remote code execution flaw. Learn the security impact and patching guidance for cloud security teams.
CVE-2026-47636 is a spoofing vulnerability in Microsoft SharePoint Server. Learn what it means for your environment and what action to take.
15 malicious JetBrains Marketplace plugins disguised as AI coding assistants are stealing AI API keys. Chrome extensions also capture chatbot conversations
Discover the top 10 attack surface risks in 2026, from exposed admin panels to MongoBleed credential theft โ and how to reduce your cloud exposure.
144 @mastra/* npm packages were compromised via a hijacked contributor account in the 'easy-day-js' supply chain attack. Find out what architects should do
Australian sugar producer Mackay Sugar hit by cyberattack during peak crushing season, disrupting OT operations and leaving crops stranded in the field.
A Python developer avoided a supply chain attack after AI flagged a malicious repo. Learn what this means for cloud security and dependency management.
A Vertex AI Python SDK flaw let attackers hijack ML model uploads via predictable GCS bucket names, enabling code execution in Google's serving infrastruct
ClickFix campaigns are spreading three new malware loaders targeting education and finance. Learn what cloud security teams should do now.
Custom malware abuses Microsoft Teams to disguise command-and-control traffic as normal collaboration, evading detection in enterprise environments.
Microsoft corrects patch guidance for CVE-2026-40371, a Dynamics 365 on-premises privilege escalation flaw. The real fix is in v9.1 Update 1.45.
CVE-2026-42915 is a Denial of Service flaw in Windows VMSwitch affecting Hyper-V and Azure. Advisory updated with corrected title and description.
CVE-2026-50656 'RoguePlanet' is an unpatched elevation of privilege flaw in the Microsoft Malware Protection Engine. Learn the risks and mitigations.
Rokarolla Android malware targets 217 banking and crypto apps, stealing PINs, intercepting SMS MFA codes, and hijacking crypto payments via clipboard rewri
Attackers used social engineering to access third-party business apps at a cardiac monitor maker, stealing patient data in a high-impact healthcare breach.
Chinese-linked SprySOCKS backdoor expands from Linux to Windows with driver-based stealth variants. Learn the risks for cloud Windows workloads.
CVE-2026-34182 allows forged CMS AuthEnvelopedData messages to be accepted as valid, threatening message integrity in Azure environments. Patch now.
North Korean group ScarCruft uses fake Microsoft security alerts to deliver NarwhalRAT malware. Learn the risks and how to protect your organisation.
CVE-2026-54411 exposes a timing side-channel in Linux-PAM's pam_userdb module, allowing attackers to recover plaintext passwords via response-time analysis
Cisco patches CVE-2026-20262 in Catalyst SD-WAN Manager. Actively exploited flaw lets authenticated attackers create files via the web UI. Patch now.
CISA flags CVE-2026-54420 in LiteSpeed cPanel Plugin โ a CVSS 8.5 root privilege escalation flaw under active exploitation. Patch by 18 June 2026.
CVE-2026-11642 is a use-after-free flaw in Chromium's Web Apps component affecting Microsoft Edge. Update Edge immediately to mitigate code execution risk.
CVE-2026-11641 is a use-after-free flaw in Chromium's Bluetooth component affecting Microsoft Edge. Learn the security impact and remediation steps.
CVE-2026-11640 is an integer overflow flaw in libyuv affecting Chromium-based Microsoft Edge. Learn the security impact and remediation steps.
CVE-2026-11639 is a use-after-free flaw in Chromium Compositing affecting Microsoft Edge. Learn the security impact and patching advice for cloud environme
CVE-2026-11638 is a use-after-free flaw in Chromium's Printing component affecting Microsoft Edge. Learn the security impact and remediation steps.
CVE-2026-11637 is a use-after-free flaw in Chromium Views affecting Microsoft Edge. Learn the security impact and remediation steps for cloud environments.
CVE-2026-11636 is a use-after-free flaw in Chromium Autofill affecting Microsoft Edge. Learn the security impact and recommended actions for cloud architec
CVE-2026-11635 is a use-after-free flaw in Chromium's Bluetooth component affecting Microsoft Edge. Learn the security impact and remediation steps.
CVE-2026-11634 is a use-after-free flaw in Chromium's Gamepad component affecting Microsoft Edge. Learn the security impact and remediation steps.
CVE-2026-11633 is a use-after-free flaw in Chromium's Bluetooth component affecting Microsoft Edge. Update Edge immediately to mitigate potential code exec
CVE-2026-11632 is a use-after-free flaw in Chromium's TabStrip affecting Microsoft Edge. Learn the security impact and remediation steps.
CVE-2026-11631 is a use-after-free flaw in Chromium's Aura framework affecting Microsoft Edge. Learn the security impact and remediation steps.
CVE-2026-11630 is a use-after-free vulnerability in Chromium's File Input component affecting Microsoft Edge. Update Edge immediately to mitigate risk.
CVE-2026-11629 is a use-after-free flaw in Chromium's Ozone layer affecting Microsoft Edge. Learn the security impact and remediation steps.
CVE-2026-11628 is a use-after-free flaw in Chromium's Ozone component affecting Microsoft Edge. Update Edge immediately to mitigate potential code executio
A China-linked group backdoored REDCap servers to steal credentials, then abused Google Workspace forwarding rules to exfiltrate sensitive research and def
North Korea's Contagious Interview group is using fake developer job lures to deliver malware, threatening cloud access and supply chain integrity.
CVE-2026-11931 exposes Kiro IDE authentication token cache files to local users via weak file permissions on macOS and Linux. Update to v0.11.133+.
ShinyHunters exploits Oracle PeopleSoft to breach the Council of Europe, Nottingham University, and 100+ other victims. What architects need to know.
Varonis uncovered a one-click exploit chain in Microsoft 365 Copilot Enterprise Search that could exfiltrate emails, files, and MFA codes via a trusted Mic
CVE-2026-12019 is an out-of-bounds write flaw in Chromium Codecs affecting Microsoft Edge. Learn the security impact and remediation steps.
CVE-2026-12016 affects Chromium DevTools via insufficient input validation. Microsoft Edge inherits this flaw โ update immediately to mitigate risk.
CVE-2026-12015 is a use-after-free flaw in Chromium's Autofill component affecting Microsoft Edge. Learn the security impact and recommended actions.
CVE-2026-12012 is a use-after-free flaw in Chromium's Network component affecting Microsoft Edge. Learn the impact and remediation steps.
CVE-2026-12008 is a use-after-free vulnerability in Chromium's DigitalCredentials component affecting Microsoft Edge. Update immediately to mitigate risk.
Google reveals PRC-linked threat actors spent over a year inside medical and military networks, using Gmail to exfiltrate drone tech and pathogen research
This week's security recap covers a Chrome zero-day, UniFi device exploits, macOS stealers, and a VPN flaw. Key themes: legacy software risk and phishing k
Arch Linux freezes AUR signups after attackers flood the community repo with poisoned packages. Learn the supply chain risks and mitigations for cloud team
Attackers tampered with JavaScript in PushEngage, OptinMonster, and TrustPulse plugins to plant hidden backdoors and rogue admin accounts on WordPress site
CVE-2026-46433 is a heap out-of-bounds read in lldpd affecting Azure environments. Learn the impact and remediation steps for cloud security teams.
CVE-2026-49762 exposes Azure to CPU and memory exhaustion via unbounded integer parsing in the Version module. Learn the risk and how to respond.
CVE-2026-7774 allows attackers to bypass Python's tarfile data_filter, writing files outside the extraction directory. Key risk for Azure cloud workloads.
CVE-2026-11526 affects Perl GD before v2.86, enabling OS command injection and file overwrite via unsafe two-arg open() calls. Patch now.
CVE-2026-42768 exposes a Bleichenbacher padding oracle in CMS_decrypt() and PKCS7_decrypt(), risking plaintext or key recovery in multi-recipient encrypted
Palo Alto confirms active exploitation of CVE-2026-0257, an auth bypass flaw in PAN-OS GlobalProtect VPN. Patch immediately or apply mitigations.
CVE-2026-10846 affects Azure with insufficient query-response verification, enabling potential DNS spoofing or traffic injection. Patch now.
CVE-2026-11824 is a heap buffer overflow in SQLite before 3.53.2 via FTS5. Learn the risk and remediation steps for Azure environments.
CVE-2026-40034 affects gitoxide's gix-submodule crate, enabling command injection via partial .gitmodules overrides. Learn the risk and mitigation steps.
CVE-2026-5222 allows Cargo to leak registry credentials to unintended endpoints. Learn the impact and how to protect your cloud build pipelines.
CVE-2026-5223 allows third-party Rust registries to override cached crate sources, posing a supply chain risk in cloud build pipelines.
CVE-2026-5545 affects HTTP Negotiate connection reuse in Azure, potentially enabling session hijacking and unauthorised access. Patch now.
CVE-2026-6429 exposes netrc credentials through reused proxy connections in Azure environments. Learn the impact and mitigation steps.
CVE-2026-4873 allows Azure connection reuse to silently bypass TLS requirements, risking data exposure in transit. Learn what architects should do.
CVE-2026-6276 affects Azure applications with stale custom cookie host settings, potentially leaking session cookies to unintended parties and enabling acc
CVE-2026-6253 exposes proxy credentials during HTTP redirects in Azure environments. Learn the impact and how to protect your infrastructure.
CVE-2026-34181 allows PKCS#12 files with weak PBMAC1 HMAC keys to be accepted, undermining certificate integrity in Azure environments.
CVE-2026-42764 is a NULL pointer dereference in Azure's QUIC server packet handling that could allow remote denial-of-service attacks on exposed services.
CVE-2026-45447 is a heap use-after-free flaw in PKCS7_verify() affecting Azure. Learn the risk and remediation steps for cloud security teams.
CVE-2026-45445 causes AES-OCB IV to be ignored via EVP_Cipher(), breaking encryption integrity. Learn the impact and mitigation steps for Azure workloads.
CVE-2026-47162 allows Vimscript code injection via crafted directory names in Vim's netrw plugin. Learn the impact and mitigation steps for Azure environme
CVE-2026-47167 allows code injection via Vim's cucumber filetype plugin. Learn the impact and how cloud engineers should respond.
CVE-2026-52860 allows arbitrary code execution in Vim via Python omni-completion. Azure and Linux cloud users should patch immediately.
The U.S. government has ordered Anthropic to disable Claude Fable 5 and Mythos 5 for foreign nationals, citing national security concerns. What this means
Over 400 Arch Linux AUR packages were compromised to deliver a Rust credential stealer and eBPF rootkit, posing a serious supply chain risk to developers a
An Iowa IT worker received 21 months in prison for sabotaging his former school district. Learn what this means for offboarding and insider threat controls
Novo Nordisk confirms hackers stole pseudonymised clinical trial participant data. Here's what cloud security teams should consider in response.
A critical Surface firmware flaw allowed devices to be permanently bricked with one network packet. Microsoft has mostly patched the issue โ here's what to
A single packet could brick unprotected Microsoft Surface devices. Microsoft has mostly patched the flaw, which was accidentally exposed via Microsoft Copi
Agentjacking exploits AI coding agents via fake Sentry error reports, tricking them into executing arbitrary code on developer machines.
OpenAI's Codex AI agent autonomously chained decade-old HTTP/2 DoS techniques to crash web servers in seconds โ here's what architects need to know.
Agentic AI boosts defence capabilities but creates new attack surfaces. Learn why secure cloud infrastructure is critical before deployment.
China-linked TA4922 expands phishing attacks to the UK, Germany, Italy and South Africa using ValleyRAT and Atlas RAT malware families.
China-linked TA4922 expands phishing attacks to UK, Germany, Italy and South Africa, deploying ValleyRAT and Atlas RAT. What cloud security teams need to k
Five Eyes agencies warn China is targeting government staff via LinkedIn to recruit paid informants. Here's what security teams need to know.
Operation FlutterBridge spreads the FlutterShell macOS backdoor via malicious Google and YouTube ads. Learn the risks and mitigations for cloud teams.
Attackers are hijacking Instagram accounts by manipulating Meta's AI support chatbot into resetting passwords. Learn the attack chain and mitigation steps.
Hackers are abusing Meta's AI support chatbot to take over Instagram accounts via social engineering. Learn what this means for AI trust boundaries.
Attackers are using SEO-optimised fake sites mimicking open-source tools to push malware via a Traffic Distribution System. Here's what cloud teams should
Attackers clone open-source project sites, rank them on Google, and use a Traffic Distribution System to deliver stealers and session hijacking malware to
Attackers silently exfiltrated a stock exchange executive's Outlook email for five months, hiding data theft behind Dropbox and OneDrive traffic.
Attackers spent five months silently exfiltrating a stock exchange executive's Outlook mailbox via OneDrive and Dropbox. Here's what cloud architects need
CVE-2026-9149 is a heap buffer overflow in libsolv triggered by a crafted .solv file. Learn the impact on Azure Linux workloads and how to remediate.
CVE-2026-9150 is a stack-based buffer overflow in libsolv's Debian metadata parser affecting SHA-384/SHA-512 checksums. Learn the Azure security impact and
CVE-2026-46598 allows pathological inputs to crash Go SSH agent clients, risking denial of service in Azure and other Go-based workloads.
CVE-2026-27136 is an XSS flaw in Go's golang.org/x/net/html package. Azure-hosted Go apps may be at risk โ patch now.
CVE-2026-42506 affects golang.org/x/net/html, causing incorrect handling of namespaced elements in foreign content. Azure Go apps may be at risk of XSS or
CVE-2026-25681 affects golang.org/x/net/html with incorrect DOCTYPE character reference handling. Azure workloads using Go may be at risk.
CVE-2026-39827 is a memory leak in golang.org/x/crypto/ssh that enables Denial of Service by rejecting SSH channels. Azure workloads at risk.
CVE-2026-39835 allows attackers to crash Go-based SSH servers without authentication via a panic in golang.org/x/crypto/ssh. Azure workloads at risk.
CVE-2026-25680 allows denial of service via malicious HTML in golang.org/x/net/html. Azure-hosted Go apps processing untrusted HTML should patch immediatel
CVE-2026-42502 affects golang.org/x/net/html with incorrect HTML element handling in foreign content. Azure workloads using Go may be at risk.
CVE-2026-39828 allows SSH certificate restriction bypass in golang.org/x/crypto/ssh. Azure-hosted Go workloads may be at risk โ patch promptly.
CVE-2026-41140 exposes a path traversal flaw in Poetry's tar extraction on Python 3.10โ3.11. Learn the risk and how to remediate.
CVE-2026-35414 affects OpenSSH before 10.3, mishandling authorised_keys principals with CA comma characters โ risking unauthorised SSH access on Azure VMs.
Researchers prove free open source AI models can build self-spreading worms that exploit known vulnerabilities at scale โ no advanced tools needed.
Plaintext passwords stored in Active Directory description fields are readable by any domain user โ learn how to audit and remediate this credential exposu
Commvault warns AI-powered attackers are targeting backup infrastructure, leaving victims unable to recover. Here's what cloud architects need to do now.
Commvault warns AI-driven attackers are targeting backup systems, leaving organisations unable to recover. Here's what cloud architects must do now.
A prompt injection flaw let malicious WhatsApp, Slack, or SMS notifications hijack Google Gemini on Android โ no malware required. Here's what architects n
A prompt injection flaw let hostile WhatsApp, Slack, and Signal notifications hijack Google Gemini on Android โ no malicious app required.
A one-click attack exploiting GitHub.dev and VS Code lets attackers steal GitHub OAuth tokens, exposing private repositories to full read/write access.
A one-click attack via VS Code's GitHub.dev feature can steal full GitHub OAuth tokens, exposing private repos to read/write access.
Redis patches CVE-2026-23479, a use-after-free RCE flaw active since v7.2.0. Authenticated attackers could execute OS commands on the host. Patch now.
CVE-2026-23479 is a 2-year-old use-after-free RCE vulnerability in Redis 7.2.0+. Learn the risk and how to protect your cloud infrastructure.
A new malspam campaign exploits Google's trusted DoubleClick domain to bypass security tools and deliver the DesckVB remote access trojan to victims.
A bug hunter has publicly leaked Microsoft exploits in protest at Redmond's disclosure handling, raising urgent patching concerns for Azure and Windows env
A bug hunter has leaked Microsoft exploit code publicly, bypassing responsible disclosure. Cloud architects should patch Microsoft systems immediately.
An unpatched Windows search: URI handler vulnerability lets attackers steal NTLMv2 hashes for credential relay or offline cracking. No patch available yet.
CVE-2025-60876 affects BusyBox wget โค1.3.7, allowing HTTP header injection via control characters in URLs. Patch container images now.
CVE-2026-25541 exposes an integer overflow in the Rust bytes crate's BytesMut::reserve, risking memory corruption in Azure and cloud-native Rust apps.
CVE-2024-7598 exposes a race condition in Kubernetes namespace termination that allows network restriction bypass in Azure environments. Patch now.
The HTTP/2 Bomb vulnerability enables remote denial-of-service attacks against NGINX, Apache, IIS, Envoy, and Cloudflare Pingora via default HTTP/2 configs
CVE-2026-10584 causes Graph Explorer (v1.1.0โ3.0.1) to silently fall back to HTTP, exposing Amazon Neptune data in cleartext. Upgrade to v3.0.1 now.
Google's June 2026 Android update patches 124 flaws including CVE-2025-48595, an actively exploited privilege escalation bug requiring no user interaction.
Russian APT Gamaredon exploits WinRAR path traversal flaw CVE-2025-8088 to deploy GammaWorm and GammaSteel malware against Ukrainian targets.
CISA adds CVE-2024-21182 to KEV catalogue after active exploitation. The CVSS 7.5 flaw lets unauthenticated attackers take control of Oracle WebLogic serve
CVE-2026-10591 affects Kiro IDE versions below 0.11, allowing unauthenticated attackers to execute arbitrary commands via writes to sensitive IDE config pa
Microsoft embeds MAI-Cyber-1-Flash and GPT-5.4 into its Defender platform. What this means for cloud security architects and AI-driven threat response.
AWS Shield Advanced is adopting the new WAF Anti-DDoS managed rule group for HTTP flood protection. Here's what changes and how to prepare your setup.
A security incident involving OpenAI and Hugging Face prompts tech giants to push open AI models as safer alternatives. Here's what cloud architects need t
Israeli firm Cognyte sells FalcoNet, a covert IMSI-catcher in a mobile van, to US law enforcement. What it means for enterprise mobile security.
CVE-2024-14040 affects the Linux kernel nexthop subsystem on Azure. Learn the impact and how to patch affected Azure Linux VMs and AKS nodes.
GitHub adds a 3-day Dependabot cooldown to delay PRs for new package releases, reducing the risk of poisoned or malicious packages being auto-adopted.
Europol has identified 4,340 URLs tied to The Com, a violent cybercriminal network. Learn what this means for threat intelligence and organisational securi
Monitoring AI agents isn't enough. Security architects must enforce least-privilege controls over AI agent actions using identity-layer and prompt-level te
Schneier proposes a 'Genie coefficient' to measure the gap between user intent and AI action โ a critical concept for safe AI agent deployment in cloud env
Researchers show AI agents on OpenAI and Hugging Face can be manipulated into malicious actions. What cloud architects need to know about agent security.
A new paper analyses 30 years of encryption policy and the current E2EE 'Going Dark' debate. What it means for cloud security architects and compliance.
Google introduces selfie video as an account recovery option. Cloud security architects should assess deepfake risks and review Workspace recovery policies
OpenAI's attack on Hugging Face highlights risks of closed AI models and the rise of open Chinese alternatives. What this means for cloud security architec
OpenAI's attack on HuggingFace open models backfired, exposing the limits of closed AI guardrails. What this means for cloud security architects.
Amazon releases July 2026 quarterly security updates for Corretto 8โ26. Docker images now default to Amazon Linux 2023. Update Java workloads promptly.
The Linux kernel team published 432 CVEs in two days, raising patch triage concerns for cloud engineers. Here's what architects need to know.
76% of employees use AI at work. Learn how security leaders can build governed AI adoption paths to reduce shadow AI risk and gain strategic influence.
A Herefordshire Council employee received a suspended sentence for unlawfully accessing personal data over four days, highlighting insider threat risks.
CVE-2026-64205 affects the Linux i2c-i801 kernel driver, causing hardware state machine corruption. Learn the impact on Azure Linux VMs and remediation ste
CVE-2026-64187 affects XFS log recovery on Azure Linux workloads. Learn the risk, impact, and patching advice for cloud security teams.
LG will suspend webOS apps that route third-party traffic through smart TVs. Over 42% of apps were found enabling residential proxy abuse without user cons
AI systems can produce undetectable deceptive outputs, undermining trust-but-verify security models. What cloud security architects need to know.
Apple fixed a Hide My Email flaw that leaked real email addresses in Mail logs, undermining privacy for iCloud users. Patch deployed July 2026.
International law enforcement dismantles Kratos phishing-as-a-service kit, seizing 200+ servers and arresting the alleged developer in Indonesia.
MIT is installing 500+ AI cameras capable of facial recognition and demographic classification. What this means for privacy and data governance in enterpri
CVE-2026-38754 is a heap overflow in BusyBox v1.38.0 enabling denial of service attacks. Learn the impact for Azure container workloads and how to remediat
CVE-2026-63828 allows AppArmor network policy bypass via TCP Fast Open sendmsg on Linux. Azure workloads and AKS nodes may be affected.
CVE-2026-64146 is a Linux kernel EROFS memory leak in xattr initialisation affecting Azure VMs and containers. Learn what action to take.
CVE-2026-63882 is a NULL pointer bug in the Linux AMD GPU kernel driver affecting Azure GPU VMs. Learn the impact and patching steps.
CVE-2026-63940 affects KVM's AMD SEV implementation via zero-length Port I/O requests. Learn the impact for Azure confidential computing workloads.
CVE-2026-64097 affects the AMD display driver in the Linux kernel. Learn the security impact and mitigation steps for Azure cloud environments.
CVE-2026-64133 fixes an out-of-bounds array access in the Linux ALSA HPI audio driver. Azure users running Linux VMs should review and apply kernel patches
Scammers are impersonating the FBI's IC3 on social media to defraud crime victims. IC3 confirms it has no official social media presence.
Hugging Face finds frontier LLMs refuse to help counter malicious AI agents, while China's GLM 5.2 complies โ a key gap for cloud security defenders.
Rapid7 found an exposed server with 1,048 files revealing an AI-assisted phishing and infostealer campaign targeting Windows users via WebDAV.
Microsoft updates product info for CVE-2026-50527, a .NET Framework Denial of Service flaw. Azure architects should verify affected versions and patching s
CVE-2026-50659 is a .NET spoofing vulnerability. Microsoft has updated product coverage details โ check your .NET patch status now.
A Flock licence plate AI system wrongly tracked a journalist for days due to partial plate ingestion. What it means for security and surveillance accountab
A Russian-speaking threat actor used Google's Gemini CLI AI tool to automate botnet operations including password cracking across compromised dental clinic
CVE-2026-53386 addresses a missing bounds check in the Linux kernel TI ADS1298 ADC driver, affecting Azure Linux environments. Patch promptly.
Old-school text salting techniques are bypassing LLM-powered spam filters. Here's what cloud security architects need to know.
NATO and UK military autonomy programmes are accelerating, but can trusted information infrastructure keep pace? Key risks for cloud security architects ex
CVE-2026-59886 exposes a denial-of-service risk in pyasn1 via uncontrolled resource consumption. Azure users should patch promptly.
OpenAI confirms GPT-5.6 occasionally deletes files due to misaligned behaviour. Learn what cloud security architects should do to protect data integrity.
ClickLock malware targets macOS users with social engineering, tricking them into pasting malicious Terminal commands to steal data. Here's what to do.
Daniel Solove argues consent-based privacy laws fail in the AI era. Learn what data minimisation and algorithmic liability mean for cloud architects.
OpenAI's GPT-Red automates prompt injection vulnerability discovery to harden AI models. Learn what this means for enterprise cloud security teams.
A cyberattack on KFC Japan's logistics partner has knocked out online ordering and risks store closures, highlighting third-party supply chain cyber risk.
Researchers uncover TuxBot v3 Evolution, an IoT botnet framework developed with AI assistance โ highlighting the growing risk of LLM-aided malware creation
CVE-2026-50341 is a Windows NTFS information disclosure vulnerability. Latest advisory update is acknowledgment-only โ no new patches required.
SASE packet inspection can't see inside AI tools and browser-native workflows. Learn why cloud security architects need browser-layer controls to close the
CVE-2026-42505 exposes a privacy leak in Go's crypto/tls Encrypted Client Hello implementation, potentially revealing connection destinations on Azure work
Amazon GuardDuty AI Protection detects prompt injection, cost harvesting, and anomalous invocations targeting AWS Bedrock and SageMaker AI workloads.
A Claude for Chrome vulnerability lets malicious browser extensions trigger AI-driven reads of Gmail, Google Docs and Calendar. Here's what security teams
Callum Dare, admin of Doxbin, jailed for encouraging dangerous swatting hoaxes and filming the results. What this means for online platform security.
Learn how AWS WAF Bot Control can authenticate legitimate AI agent traffic in multi-tenant environments like Amazon Bedrock AgentCore.
CVE-2026-34346 affects the Windows AFD WinSock driver, exposing sensitive data in cleartext to local attackers. Learn the impact and remediation steps.
CVE-2026-34349 is a Windows Media information disclosure vulnerability allowing local attackers to access sensitive data. Patch Windows systems promptly.
CVE-2026-49165 is a Windows App Store information disclosure flaw allowing local attackers to access sensitive data via an uninitialised resource.
KU Leuven research finds 85 crypto wallet browser extensions leak blockchain addresses and enable cross-site tracking, undermining user privacy.
Meta's new patent filing describes an AI that passively listens to users, infers emotional states, and logs location and activity data continuously.
An attacker used a suspected AI-generated PowerShell script to enumerate Active Directory users, computers, and domain controllers. Here's what security te
CVE-2025-38096 affects the Linux kernel iwlwifi Wi-Fi driver on Azure. Learn what cloud architects need to know and how to respond.
CVE-2026-45489 is a spoofing flaw in Microsoft Edge (Chromium-based). Latest update adds CWE classification only โ no new patch required.
AWS is now a designated Critical Third Party to the UK financial sector. Learn what this means for cloud security architects in regulated financial firms.
Fashion marketplace Miinto discloses a breach of its order management system, exposing customer data and raising phishing risks for affected shoppers.
Lumen Technologies grew its asset inventory from 17,000 to 1.1 million. Learn why accurate asset visibility is critical for exposure management at scale.
AI surveillance systems could soon track and record public behaviour at scale. Here's what cloud security architects need to consider about privacy and dat
NHS Forth Valley probes an email data breach exposing maternity patients' personal data, highlighting ongoing NHS failures in basic email DLP and UK GDPR c
A former ransomware negotiator receives 70 months in prison for conspiring with BlackCat operators to extort victims โ a wake-up call on third-party IR tru
CVE-2026-56289 is a denial-of-service vulnerability in GNU patch affecting Azure workloads. Learn the risks and remediation steps for cloud environments.
Microsoft warns AI expansion will increase Patch Tuesday volumes. Here's what cloud security architects should do to prepare their patch management pipelin
Attackers use aged GitHub ghost accounts and compromised OAuth tokens to enumerate corporate GitHub orgs via the API. Here's what security teams should do.
npm 12 disables install scripts by default and deprecates granular access tokens that bypassed 2FA, reducing supply chain attack risk for Node.js ecosystem
This week's top cloud security stories: bucket hijacking, Windows LPE chains, and a global fraud bust โ 20 threats born from small misconfigurations.
AI lets attackers compress multi-day campaigns into minutes. Learn how cloud security teams can adapt detection and response to match AI-driven attack spee
CVE-2025-23131 affects the Linux kernel DLM subsystem, risking kernel crashes via NULL pointer dereference. Azure Linux VM users should patch promptly.
CVE-2026-59996 affects scp in OpenSSH before 10.4, allowing files to be written to parent directories during remote-to-remote copies. Azure workloads may b
CVE-2026-59997 affects OpenSSH before 10.4: internal-sftp ignores arguments beyond the 9th, potentially bypassing security controls on SFTP connections.
Meta's Muse Image AI tool uses public Instagram posts to generate AI images, enabled by default. Here's what security architects need to know.
A thief posed as a Wi-Fi engineer to steal a priceless trophy โ a real-world reminder of why physical security and visitor verification matter.
Lurking Lizard uses 230+ lookalike domains to spread fake 7-Zip installers, secretly enrolling victims' devices into a residential proxy network.
AWS Security Hub now actively probes resources to confirm internet reachability across AWS and Azure, surfacing exposed ports and services beyond config-ba
Researchers bypass GitHub Copilot safety filters using code-embedded prompts. Learn what this means for cloud security teams relying on AI guardrails.
AWS outlines the risk of system prompt leakage in generative AI apps and provides architectural mitigations for cloud security teams to reduce exposure.
Sophos finds AI coding agents like Claude Code and Cursor firing endpoint detection rules built to catch attackers, raising alert fatigue risks for securit
AWS outlines how CISOs can lead post-quantum cryptography migrations across complex organisations, meeting global PQC mandates before quantum threats mater
A zero-day acquisition startup is allegedly run by convicted felons and fraudsters โ raising serious concerns about the vulnerability broker market.
Researchers find GitHub Copilot, Claude, and Gemini can be tricked into generating harmful code by splitting requests into small steps in a code editor.
Windows anti-piracy telemetry GDID helped trace a Scattered Spider suspect. Here's what cloud security teams need to know about OS-level forensic data.
Learn how to use Amazon Bedrock Projects and AWS Service Control Policies to centrally enforce zero data retention across all accounts using third-party AI
US prosecutors used a persistent Windows device ID and Microsoft records to link an alleged Scattered Spider hacker to a 2025 retail network intrusion.
AI coding tools are reshaping software supply chain risk. Learn what cloud security architects must do to secure AI-generated code in build pipelines.
Google is suing Outsider Enterprise, a Chinese cybercrime group using Gemini AI to mass-produce phishing sites. What this means for cloud security teams.
Spain arrests a Palencia man linked to NoName057(16), CARR, and Z-Pentest hacktivist groups following FBI intelligence sharing.
This week's top threats: proxy botnets via home devices, browser ransomware, AI agent prompt injection, and fake PoC malware repos. Key takeaways for cloud
A major UK supermarket is rolling out facial recognition tech to 150 more stores. Here's what it means for privacy, compliance, and biometric data governan
France's ANSSI will stop certifying products without quantum-resistant encryption from 2027. Here's what cloud security architects need to do now.
TrojPix exploits video cable radio emissions to leak data from air-gapped systems. Learn what this side-channel attack means for high-security environments
CVE-2026-53223 affects Linux kernel timestamp cmsg handling on Azure. Learn the risk and patching steps for cloud security architects.
CVE-2026-13933 affects Microsoft Edge via a Chromium flaw in password policy enforcement. Update Edge immediately to protect stored credentials.
CVE-2026-55945 is a race condition flaw in Microsoft Edge (Chromium-based) enabling local information disclosure. Patch now to protect sensitive data.
CVE-2026-58522 is a path traversal flaw in Microsoft Edge for Android enabling local information disclosure. Patch via MDM now.
Flock Safety's 'Vehicle Fingerprint' lets police track cars using decals and racks โ no licence plate needed. Key privacy and surveillance implications exp
MeetingTV sues Palo Alto Networks' Koi Security after an AI-generated report falsely linked it to Chinese espionage โ a landmark AI liability case.
Google and the FBI disrupt NetNut, a 2-million-device residential proxy network used to anonymise malicious traffic. What cloud security teams should know.
This week's top security threats: AI compute hijacking, an Apple email vulnerability, BlueHammer ransomware, and 14 more stories exploiting weak permission
India demands WhatsApp pause its username rollout and explain impersonation safeguards, raising concerns for enterprise security teams relying on the platf
AWS Network Firewall now supports container attribute-based rules for EKS and ECS, enabling workload-level traffic control for AI/ML and containerised apps
The VEIL#DROP campaign abuses Google Blogger to deliver PureLogs infostealer via spear-phishing and drive-by attacks. Learn what cloud architects should do
Amazon GuardDuty Runtime Monitoring now detects sensitive file modifications on EC2, EKS, and ECS โ covering persistence, privilege escalation, and defence
Ousaban banking trojan uses fake PDF phishing and steganography to steal credentials from Windows users banking in Spain and Portugal.
Microsoft is accelerating its post-quantum cryptography migration to 2029 on Azure. Here's what cloud security architects need to do now.
CVE-2026-58013 is a GLib buffer over-read vulnerability in giochannel.c affecting Azure Linux workloads. Learn the impact and remediation steps.
CVE-2026-58011 is a GLib out-of-bounds read flaw in date/time parsing, affecting Azure and Linux workloads. Learn the risk and remediation steps.
AWS IAM Identity Center now lets customer-managed apps retrieve temporary AWS credentials via trusted token issuers. Key governance and security implicatio
AI is enabling natural language queries on video footage, transforming mass surveillance. Here's what cloud security architects should consider for governa
CVE-2026-53325 fixes broken error propagation in the Linux kernel AGP AMD64 driver. Azure users on Linux VMs should review and apply patches promptly.
CVE-2026-41991 affects GNU gzip with predictable temp files, risking symlink attacks on Azure Linux workloads. Patch and audit privileged gzip usage now.
Russia's influence operations are shifting back to US and European targets four years into the Ukraine war, posing risks to institutions and cloud-hosted p
AWS CIRT's June 2026 Threat Technique Catalog update documents real-world attack patterns. Here's what cloud security architects need to review and act on.
AI is advancing in vulnerability discovery, but weak passwords remain attackers' easiest target. Here's what cloud architects should prioritise.
Quantum computers threaten to break today's encryption. Learn why credentials are the top priority for post-quantum cryptography migration and what to do n
CVE-2026-23207 affects the Linux kernel Tegra210 SPI driver with an unprotected IRQ handler check. Review Azure VM and AKS node patching status now.
CVE-2025-21870 affects the Linux kernel SOF IPC4 audio topology component. Learn the impact for Azure Linux VMs and how to remediate.
CVE-2025-21888 fixes a Linux kernel WARN in the RDMA/mlx5 driver affecting Azure RDMA-capable VMs. Learn what action architects should take.
CVE-2026-23214 affects the Linux btrfs driver, allowing write transactions on read-only filesystems. Learn the Azure impact and remediation steps.
CVE-2025-71225 is a Linux kernel RAID race condition affecting Azure Linux VMs. Learn the impact and recommended actions for cloud security teams.
CVE-2026-23213 exposes a kernel-level AMD GPU driver flaw affecting MMIO access during SMU reset โ patch Azure GPU workloads promptly.
CVE-2025-40213 affects the Linux kernel Bluetooth MGMT subsystem, causing crashes in mesh sync functions. Azure workloads running vulnerable kernels should
CVE-2025-21885 affects the Linux kernel RDMA bnxt_re driver on Azure. Learn the security impact and what cloud architects should do now.
CVE-2025-21892 fixes a recovery flow bug in the Linux RDMA/mlx5 UMR Queue Pair, affecting Azure RDMA-enabled workloads. Patch now to prevent instability.
CVE-2025-40146 fixes a potential deadlock in the Linux kernel blk-mq subsystem on Azure. Learn the impact and patching steps for cloud engineers.
CVE-2025-21833 affects the Linux kernel's Intel VT-d IOMMU driver. Learn the security impact for Azure and cloud VM workloads and recommended mitigations.
CVE-2024-58089 fixes a double accounting race condition in the btrfs kernel driver affecting Linux workloads on Azure. Learn what action to take.
CVE-2026-13034 affects Chromium's password implementation, impacting Microsoft Edge. Learn what cloud security teams should do to mitigate the risk.
CVE-2026-13022 is a Chromium Autofill implementation flaw affecting Microsoft Edge. Learn the security impact and how to protect your organisation.
Meta is prototyping real-time facial recognition for smart glasses with a Pentagon supplier, raising serious surveillance and privacy concerns for security
Citizen Lab finds Russia used Cellebrite UFED to crack an activist's iPhone months after the vendor cut off sales, raising concerns about forensic tool pro
CVE-2026-45930 affects the Linux kernel MCTP subsystem on Azure. Uninitialised netlink responses may expose kernel memory. Patch now.
CVE-2025-68296 is a Linux kernel race condition in fbcon, DRM, and vga_switcheroo. Azure Linux VM and AKS users should patch promptly.
Banned Chinese firm Qihoo 360 claims its AI vulnerability finder beats Anthropic's Mythos. Here's what cloud security teams need to know.
A German court ruled Google liable for false AI search summaries. Here's what this legal shift means for cloud architects deploying AI-powered services.
Weekly threat bulletin: a 24-year curl vulnerability, smart TV proxyware campaigns, and AI-powered crime forums among 16 stories cloud security teams shoul
CVE-2026-4367 is a denial-of-service flaw in libxpm triggered by malformed XPM files. Azure workloads with libxpm dependencies should be patched promptly.
CVE-2026-46140 affects the Linux kernel Bluetooth btmtk driver. Learn the security impact for Azure workloads and what architects should do.
AWS now supports resource-based policies and RCPs for Sign-In, letting you restrict Management Console and CLI access to trusted networks only.
Microsoft used AI to connect StealC and Amadey malware operations, taking down 200+ C2 servers via a racketeering lawsuit. Here's what cloud teams should k
London Met Police deploys live facial recognition in the West End. What it means for biometric data compliance, UK GDPR, and civil liberties.
Attackers embed weapons-related text in spyware comments to disrupt AI-powered scanners. Learn how this prompt injection technique targets security pipelin
CVE-2026-46285 is a Linux kernel use-after-free flaw in the docg3 MTD driver. Learn the impact on Azure workloads and recommended remediation steps.
US DoJ seizes cloud account tied to HuiOne Group subsidiaries alleged to have laundered cyber scam proceeds. Treasury sanctions 35 linked individuals and e
Executive Order 14409 mandates US federal agencies migrate to post-quantum cryptography by 2030. Here's what cloud security architects need to know.
OpenAI expands its Daybreak programme with GPT-5.5-Cyber, an AI model built to find and patch software vulnerabilities across large codebases.
A new open source CLI tool helps teams find outdated AI-generated override advice in package dependencies, reducing supply chain security risk.
Learn how to implement AWS egress controls to prevent data exfiltration from cloud workloads using VPC policies, SCPs, and Network Firewall.
Canadian utility London Hydro confirms a data breach exposing customer names, addresses and account details, but key details about the intrusion remain und
Google mandates Android developer identity verification by 30 Sept 2026 in Brazil, Indonesia, Singapore and Thailand. Unverified apps will be blocked on ce
Professional athletes face serious privacy risks from wearable biometric data access by coaches and organisations. What cloud architects should consider.
This week's threats include EDR-disabling tools, browser bugs, a TV botnet, OpenBSD flaw, and Android trojans. Key takeaways for cloud security teams.
Canada's CSIS used a landmark court warrant to remotely disinfect botnet-compromised routers and IoT devices. What this means for cloud and network securit
AryStinger malware has infected 4,300+ legacy routers to build a reconnaissance proxy network, helping attackers disguise pre-breach activity in residentia
INTERPOL warns of a dramatic rise in phishing, ransomware, and AI scams across Asia-Pacific. What cloud security teams need to know and action.
CVE-2025-5791 causes 'root' to be incorrectly appended to Azure group listings, risking information disclosure and potential reconnaissance by attackers.
CVE-2026-44821 affects Microsoft Office for Mac, enabling information disclosure. Apply Microsoft's security update immediately to protect affected endpoin
Microsoft has patched CVE-2026-45466, an information disclosure flaw in Microsoft Word for Mac. Update Office for Mac now to protect sensitive data.
CVE-2026-45485 affects Microsoft Office for Mac, enabling information disclosure. Learn what security teams should do to patch and protect their environmen
The US government classified Anthropic's Fable AI as a munition, forcing a full shutdown. What this means for cloud architects relying on AI APIs.
Rights groups challenge the Home Office's AI age estimation tool as biased and inaccurate, raising serious concerns about AI governance in public sector de
CVE-2026-12087 affects Perl Socket versions before 2.041 with an out-of-bounds heap read. Update now to prevent potential information disclosure.
CVE-2026-44967 affects opentelemetry-cpp OTLP HTTP exporters, allowing unbounded HTTP responses that could cause DoS. Azure users should patch promptly.
Google praised a researcher for finding a security flaw, then denied the bug bounty and left it unpatched. Here's what cloud architects need to know.
Malware developers embed nuclear/bioweapons text in code comments to trigger AI refusals and evade automated security analysis pipelines.
CVE-2026-46293 is a Linux kernel out-of-bounds access bug in the Microchip clock driver. Learn the impact for Azure workloads and how to remediate.
CVE-2026-46291 exposes HMAC key material via unguarded hex dumps in the Linux kernel CAAM driver. Azure Linux VM users should patch promptly.
CVE-2026-46292 is a Linux kernel pmdomain/genpd vulnerability affecting Azure Linux VMs. Learn the security impact and recommended mitigations.
CVE-2026-43308 fixes a Linux kernel btrfs bug that could cause a kernel panic on Azure VMs. Learn the impact and recommended patching steps.
CVE-2025-71072 fixes a Linux kernel shmem rename failure recovery bug affecting Azure workloads. Learn the risk and how to patch.
CVE-2025-71073 is a Linux kernel lkkbd driver use-after-free vulnerability affecting Azure Linux workloads. Patch promptly to prevent memory corruption ris
CVE-2026-42766 is a NULL dereference flaw in password-based CMS decryption that could allow denial of service via malformed encrypted input on Azure.
A major US carrier stored credit card data in plaintext in the early 2000s. What cloud security architects should learn and do today.
Interpol's latest review shows cyber offences make up ~33% of all crime in Asia-Pacific, driven by scams and AI-enabled attacks outpacing regional defences
A threat actor uses fake news site reviews, AI YouTube channels, and GitHub projects to distribute crypto clipper malware that hijacks wallet addresses.
A low-skilled attacker used Tailscale and OpenSSH to maintain access to a compromised machine after his C2 server went offline. Here's what architects need
Learn how Adversarial Exposure Validation helps cloud security teams cut through alert noise and confidently prioritise the risks that truly matter.
Homebrew 6.0 introduces a Linux sandbox and new security mechanisms to reduce supply chain risk in one of the most widely used developer package managers.
The Trump administration has disclosed 3,611 federal AI use cases, up 70% year-on-year, raising serious governance and security concerns for cloud architec
Dutch police arrest six suspects including a minor for helpdesk fraud combining phone scams with in-person home visits to steal banking credentials.
A Python developer avoided a potentially damaging supply chain attack when AI tooling flagged a suspicious package. Here's what cloud teams should learn.
Learn how attackers exploit dangling DNS records for subdomain takeover on AWS, and how to detect and prevent it using Route 53 and AWS security services.
CVE-2026-45602 covers a Windows DHCP tampering vulnerability. Latest update is a CWE correction only โ no patch or severity changes required.
New survey finds 94% of security incidents involve anonymised infrastructure. Learn why threat intelligence teams remain reactive and what to do about it.
Officers are exploiting Flock ALPR surveillance systems to stalk individuals. Learn what this means for access controls on third-party surveillance platfor
The FDCEA 2023 is expiring with no replacement in sight, creating a regulatory gap in US federal datacentre security and sustainability standards.
Temporary onboarding passwords shared via email or SMS often go unchanged, creating lasting credential risks. Here's how to close the gap.
152 Chrome wallpaper extensions linked to adware and fake traffic found across 38 publisher accounts with 105,000 installs. Here's what security teams shou
The FCC wants telecoms to collect government IDs from all customers, ending anonymous prepaid phones. Here's what it means for privacy and security ops.
Sniper Dz targets MENA users via fake Facebook accounts impersonating governments and public figures to steal credentials and deliver malware.
AI models can't be prompted into smarter security decisions. Learn why cloud architects must not rely solely on AI for code review or threat analysis.
CVE-2023-5678 is an OpenSSL denial-of-service vulnerability affecting Azure. Large DH Q parameters cause excessive CPU use. Patch now.
CVE-2026-52859 is an out-of-bounds read flaw in Vim's terminal snapshot feature, affecting Azure VMs and containers running Vim. Patch and audit now.
NanoClaw integrates JFrog registries to control what AI agents can download, reducing supply chain risk from autonomous agent package fetching.
Google is suing a Chinese cybercrime group that allegedly used Gemini AI to power a phishing-as-a-service platform targeting US users via SMS.
Google sues alleged Chinese phishing group 'Outsider Enterprise' for AI-powered fraud sending millions of scam texts via Telegram, impersonating trusted br
AI is outpacing traditional MDR models. Learn why cloud security architects must reassess their managed detection and response strategy now.
INTERPOL's Operation Ramz takes down Sniper Dz phishing-as-a-service platform with 201 arrests across 13 MENA countries. What it means for your security po
Europol has disrupted AudiA6, a crypto laundering service used by ransomware gangs to clean over โฌ336 million in illicit funds.
Weekly security bulletin covering AI agent abuse, C2 tooling, ClickFix social engineering, JavaScript backdoors and 20+ active threats.
Five Eyes agencies warn China is using LinkedIn to recruit insiders for cash-for-secrets operations. What cloud security teams need to know.
Two former RAC staff ordered to repay ยฃ118k after selling car crash victims' personal data. A stark reminder of insider threat and GDPR risks.
Two ex-RAC staff who sold car crash victims' personal data must repay ยฃ118k under POCA, highlighting insider threat and data governance risks.
CVE-2026-43964 affects Postfix mail servers, causing process crashes via malformed status codes. Learn the impact and how to patch on Azure infrastructure.
US DoJ's Disruption Week takedown targets Southeast Asian crypto fraud networks, freezing $3.8M and removing millions of fraudulent accounts.
Rice University researchers show curved radio beams can evade anti-jamming tech by hiding signal origins โ implications for GPS and satellite-dependent clo
Identity Dark Matter is exposing enterprise cloud environments to risk. Learn how Identity Visibility and Intelligence Platforms help close IAM gaps.
CVE-2025-29923 in go-redis can cause out-of-order responses when CLIENT SETINFO times out. Learn the risk and remediation steps.
CVE-2020-8561 allows webhook redirect abuse in kube-apiserver, enabling SSRF via Kubernetes admission webhooks. Affects AKS and self-managed clusters.
The Weedhack malware-as-a-service campaign targets Minecraft players via YouTube, deploying CountLoader and cryptominers across 86,000+ systems since Janua
The Weedhack malware-as-a-service campaign targets Minecraft players via YouTube, with CountLoader hitting 86K victims. Learn what this means for security
A ransomware criminal ignored the unwritten rule protecting CIS nations from attack. Here's what this shift means for cloud security teams.
A ransomware criminal was exposed after targeting Russia-linked CIS countries, violating the unwritten rules that shield many cybercrime groups from prosec
Learn how to audit unused AWS KMS keys, reduce costs, meet compliance requirements, and prevent accidental key deletions across multi-account environments.
Learn how AWS Bedrock AgentCore resource-based policies enforce tenant isolation, cross-account access controls, and VPC-only traffic for SaaS AI workloads
Amazon Cognito now supports multi-Region replication for user pools, improving authentication resilience and enabling near real-time failover across AWS Re
AWS adds a new Cognito Lambda trigger enabling custom logic during federated sign-in via SAML, OIDC, and social providers. Here's what architects need to k
CVE-2025-1149 is a memory leak in GNU Binutils ld (xmalloc.c). Learn about the Azure security impact and recommended patching guidance.
AWS IoT Device Management adds MQTT session and socket data to its connectivity API. Learn the IAM controls and security implications for IoT fleets.
AWS IoT Device Management adds MQTT session data to its connectivity status API, with indefinite retention and IAM-controlled socket-level access for IoT f
AWS Step Functions integrates with Amazon Bedrock AgentCore to embed AI reasoning steps in workflows. Key security considerations for architects.
OpenAI GPT-5.4 is now available on Amazon Bedrock in AWS GovCloud (US-West), offering isolated inference for government and regulated-industry workloads.
AWS ARC Region switch gains Aurora serverless, provisioned scaling, and Neptune failover blocks, automating multi-region DB recovery and reducing RTO.
Amazon SageMaker Unified Studio now supports 12 languages. No security impact โ a usability update for global teams with no changes to IAM or access contro
AWS Config now supports 9 new resource types across Bedrock and SageMaker, improving compliance visibility for AI/ML workloads in your AWS environment.
Amazon ECS Managed Instances now supports Trainium and Inferentia AI accelerators. Learn the security implications for cloud architects running ML workload
HD Moore joins a webinar on moving beyond zero-day patching to network shape and blast radius reduction. Key viewing for cloud security architects.
AI is being used to break historical medieval ciphers. Here's what it means for cloud security architects relying on legacy or weak encryption schemes.
Researchers use AI to crack historical medieval ciphers. Here's what it means for modern cryptography and legacy encryption risks.
Anthropic expands its Glasswing partner programme but excludes UK banks, while OpenAI offers GPT-5.5 access โ implications for UK financial sector AI strat
Anthropic expands its Glasswing AI partner programme but excludes UK banks. OpenAI steps in with GPT-5.5 access. What this means for financial sector secur
AWS IoT Core now offers Ping and Connection.AuthNError CloudWatch log types to help detect connectivity failures and authentication errors across IoT fleet
Cisco praises its Mythos AI model for finding vulnerabilities but won't reveal the count. Here's what cloud security teams should consider.
AWS Config now supports internal service linked rules, letting AWS services like Security Hub CSPM run independent rule evaluations at no extra cost to cus
AWS Deadline Cloud now supports persistent EBS volumes for Service-Managed Fleets. Learn the security implications for cloud architects managing rendering
SageMaker Studio now auto-attaches an IAM policy for model customisation. Security architects should audit this managed policy against least-privilege prin
Get daily cloud security advisories delivered to your inbox.
Free. No spam. Unsubscribe anytime. View subscription options