CVE-2026-47636 SharePoint Server Spoofing Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-47636 is a spoofing vulnerability affecting Microsoft SharePoint Server, which could allow an attacker to impersonate another user or system within the platform. Spoofing vulnerabilities can undermine trust and authentication controls, potentially enabling further attacks such as phishing, data exfiltration, or lateral movement. This update is an acknowledgement change only and carries no new technical detail or patch. Security Architect’s Take: Verify that the latest SharePoint Server cumulative updates are applied across your estate, and review audit logs for any anomalous authentication or identity-related activity. No immediate action is required in response to this specific advisory update, but treat the underlying CVE as a prompt to confirm patch compliance. ...

17 June 2025 · ZX Cloud Security

Malicious JetBrains Plugins Steal AI API Keys

🟠 High | Source: The Hacker News Attackers published at least 15 malicious plugins to the JetBrains Marketplace, disguising them as AI coding assistants powered by DeepSeek and similar models. These plugins silently steal API keys for AI services such as OpenAI, Anthropic, and others from developers’ machines. A related wave of malicious Chrome extensions is also capturing conversations from AI chatbot interfaces, broadening the attack surface. Security Architect’s Take: Audit all JetBrains plugins installed across your engineering fleet immediately and remove any AI assistant plugins not sourced from a verified, internal allowlist. Enforce secrets scanning in CI/CD pipelines and rotate any AI provider API keys that may have been exposed on developer workstations, treating them as compromised until confirmed otherwise. ...

17 June 2025 · ZX Cloud Security

Top 10 Cloud Attack Surface Exposures in 2026

🟠 High | Source: The Hacker News A roundup of the top ten attack surface exposures expected to dominate 2026 highlights how common misconfigurations and credential weaknesses remain the primary entry points for attackers, alongside newly emerging vulnerabilities such as ‘MongoBleed’, which allows unauthenticated extraction of credentials and session tokens from server memory. The article stresses that time-to-exploit for newly disclosed vulnerabilities has shortened dramatically, meaning internet-facing assets are at risk almost immediately upon disclosure. Understanding and reducing your exposed attack surface is now a core defensive priority, not just a best practice. ...

17 June 2025 · ZX Cloud Security

144 Mastra npm Packages Hijacked in Supply Chain Attack

🟠 High | Source: The Hacker News 144 npm packages in the Mastra AI framework namespace were compromised after an attacker hijacked a contributor’s npm account, in an attack dubbed ’easy-day-js’. The malicious packages could have been pulled into AI application builds by developers unaware of the compromise. This is a classic software supply chain attack, where trust in a legitimate open-source project is exploited to distribute malicious code at scale. ...

17 June 2025 · ZX Cloud Security

Cyberattack Hits Mackay Sugar During Harvest Season

🟠 High | Source: The Register — Security Australian sugar producer Mackay Sugar suffered a cyberattack during its peak cane crushing season, disrupting operations at a particularly damaging time for the business. The attack prevented crops from being processed, causing direct economic harm tied to the seasonal and time-critical nature of sugar production. This is a clear example of threat actors targeting operational technology (OT) environments in critical agricultural infrastructure where downtime has immediate, real-world consequences. ...

17 June 2025 · ZX Cloud Security

Python Supply Chain Attack Blocked by AI Warning

🟠 High | Source: The Register — Security A Python developer narrowly avoided a potentially destructive supply chain attack after both their own intuition and an AI tool flagged a suspicious package repository before installation. The incident highlights how malicious packages can masquerade as legitimate dependencies, posing significant risks to developer environments and downstream systems. AI-assisted code review is emerging as a practical last line of defence against this growing threat vector. ...

16 June 2025 · ZX Cloud Security

Google Vertex AI SDK Flaw: Bucket Squatting Attack

🟠 High | Source: The Hacker News A vulnerability in the Google Cloud Vertex AI Python SDK allowed an attacker with no prior access to a victim’s project to intercept and replace machine learning model uploads by claiming a predictable Google Cloud Storage bucket name — a technique dubbed ‘Pickle in the Middle’ by Palo Alto Networks Unit 42. Because ML models are typically serialised using the Python Pickle format, a malicious model could execute arbitrary code within Google’s Vertex AI serving infrastructure. No exploitation in the wild has been observed, and the issue was responsibly disclosed via Google’s bug bounty programme. ...

16 June 2025 · ZX Cloud Security

ClickFix Malware Campaigns: BabaDeda & New Loaders

🟠 High | Source: The Hacker News Multiple ClickFix social engineering campaigns are actively distributing three new malware loaders — BabaDeda, Lorem Ipsum, and Potemkin — targeting education and financial sectors. ClickFix tricks users into manually executing malicious commands by presenting fake error messages or software update prompts. The campaigns have been flagged by three independent security vendors, indicating broad and active threat actor interest in this delivery technique. Security Architect’s Take: Review and tighten endpoint execution policies to block PowerShell and cmd invocations triggered from browser processes; consider deploying application control rules that prevent users from manually running scripts copied from web pages. Ensure security awareness training explicitly covers ClickFix-style lures, particularly for staff in education and finance verticals. ...

16 June 2025 · ZX Cloud Security

Malware Hides C2 Traffic in Microsoft Teams

🟠 High | Source: The Register — Security Attackers have developed custom malware that routes command-and-control traffic through Microsoft Teams, disguising malicious communications as legitimate corporate collaboration activity. By abusing trusted Microsoft services, the malware makes it significantly harder for security tools and analysts to distinguish attacker traffic from normal business use. This technique lowers the risk of detection and complicates incident response, particularly in organisations that heavily rely on Teams. ...

16 June 2025 · ZX Cloud Security

CVE-2026-40371: Dynamics 365 On-Prem EoP Fix

🟠 High | Source: Microsoft Security Response Center A privilege escalation vulnerability in Microsoft Dynamics 365 on-premises has been assigned CVE-2026-40371, allowing an attacker to gain elevated permissions within the application. Microsoft has corrected its remediation guidance: the fix is contained in Dynamics 365 Server v9.1 Update 1.45 (build 9.1.0045.0011), not the previously stated version 6.2. Organisations that applied the earlier guidance should verify they are running the correct build to ensure they are actually protected. ...

16 June 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options