CVE-2026-42915 Windows VMSwitch DoS Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-42915 is a Denial of Service vulnerability affecting Microsoft Windows VMSwitch, a core component of Hyper-V networking used in Azure virtualisation infrastructure. The advisory has been updated to correct the CVE description and title, with no change to the underlying vulnerability details or patches. While classified as a DoS vulnerability, its presence in virtualisation switching layers means it could impact availability across hosted workloads. ...

16 June 2025 · ZX Cloud Security

CVE-2026-50656: Microsoft Defender EoP Vulnerability

🟠 High | Source: Microsoft Security Response Center A publicly disclosed elevation of privilege vulnerability, tracked as CVE-2026-50656 and nicknamed ‘RoguePlanet’, has been found in the Microsoft Malware Protection Engine within Microsoft Defender. An attacker exploiting this flaw could gain elevated system privileges on affected machines. Microsoft has acknowledged the issue but has not yet released a patch, meaning systems remain exposed whilst a fix is in development. Security Architect’s Take: With no patch currently available, prioritise compensating controls: ensure Defender is configured with least-privilege service accounts, monitor for anomalous privilege escalation events via Microsoft Sentinel or your SIEM, and consider temporarily increasing alert sensitivity on endpoints running Microsoft Defender until the update is released. ...

16 June 2025 · ZX Cloud Security

Rokarolla Android Trojan Steals PINs & Crypto Funds

🟠 High | Source: The Hacker News A newly documented Android banking trojan called Rokarolla targets 217 banking and cryptocurrency applications, giving attackers near-complete control of infected devices. It can steal lock-screen PINs, intercept SMS-based two-factor authentication codes, and hijack cryptocurrency transactions by silently rewriting clipboard content. With 137 remote commands at an operator’s disposal, the potential for account takeover and financial theft is significant. Security Architect’s Take: Enforce mobile device management (MDM) policies that restrict sideloading and require app allowlisting on any corporate or BYOD devices accessing cloud workloads or financial systems. Additionally, review whether SMS-based MFA is used to protect privileged accounts and migrate to hardware tokens or authenticator apps, as SMS interception renders that second factor useless against this threat. ...

16 June 2025 · ZX Cloud Security

Cardiac Monitor Maker Breached via Social Engineering

🟠 High | Source: The Register — Security A cardiac monitor manufacturer suffered a data breach after attackers used social engineering techniques to compromise third-party business applications and steal patient information. The incident highlights the risk posed by supplier and third-party app integrations in healthcare environments, where sensitive personal and medical data is at stake. Breaches of this nature carry significant regulatory consequences under UK GDPR and can directly harm patient safety and trust. ...

16 June 2025 · ZX Cloud Security

SprySOCKS Backdoor Now Targets Windows via Kernel Driver

🟠 High | Source: The Hacker News Researchers at ESET have discovered two previously unknown Windows variants of SprySOCKS, a backdoor previously thought to be Linux-only and linked to Chinese threat actors. The new variants, internally labelled WIN_DRV and WIN_PLUS, use kernel-level drivers to evade detection and communicate with attacker infrastructure over TCP and UDP. This significantly expands the threat’s attack surface to Windows environments, including cloud-hosted Windows workloads. Security Architect’s Take: Review endpoint detection coverage on Windows-based cloud workloads (e.g. Azure VMs, AWS EC2 Windows instances) to ensure kernel-level driver activity and unsigned or anomalous driver loads are monitored; consider enforcing Windows Defender Application Control (WDAC) or equivalent allowlisting policies to block unauthorised kernel drivers. ...

16 June 2025 · ZX Cloud Security

CVE-2026-34182: Azure CMS AuthEnvelopedData Forgery Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-34182 is a vulnerability in CMS (Cryptographic Message Syntax) AuthEnvelopedData processing that may allow an attacker to submit forged encrypted messages that are incorrectly accepted as valid. This undermines the integrity guarantees of authenticated encryption, potentially enabling an attacker to bypass message authentication checks. The flaw is particularly concerning in any Azure service or component that relies on CMS for secure message handling. ...

16 June 2025 · ZX Cloud Security

APT37 NarwhalRAT via Fake Microsoft Alerts

🟠 High | Source: The Hacker News North Korean state-sponsored group ScarCruft (APT37) is running spear-phishing campaigns that impersonate Microsoft Account security alerts to deliver a remote access trojan called NarwhalRAT. The emails are crafted to alarm recipients about suspicious account activity, prompting them to interact with malicious content. This is a targeted threat with nation-state backing, making it higher risk than typical phishing campaigns. Security Architect’s Take: Ensure your organisation’s email security controls (DMARC, DKIM, SPF) are enforced and that Microsoft-themed phishing lures are included in user awareness training. Consider deploying conditional access policies that reduce the impact of credential theft, and review endpoint detection coverage for RAT-based payloads on any systems handling sensitive cloud workloads. ...

16 June 2025 · ZX Cloud Security

CVE-2026-54411: Linux-PAM Timing Attack Exposes Passwords

🟠 High | Source: Microsoft Security Response Center A timing side-channel vulnerability in Linux-PAM (through version 1.7.2) allows an attacker to recover plaintext passwords by measuring subtle differences in authentication response times. The flaw exists in the pam_userdb module when configured to store credentials in plaintext — a non-default but valid configuration. By repeatedly probing an exposed authentication service, an attacker can deduce the password length and individual characters byte by byte. ...

16 June 2025 · ZX Cloud Security

Cisco CVE-2026-20262: SD-WAN Manager Flaw Exploited

🟠 High | Source: The Hacker News Cisco has patched a medium-severity vulnerability (CVE-2026-20262) in Catalyst SD-WAN Manager that is being actively exploited in the wild. The flaw allows an authenticated remote attacker to create files or URLs via the web UI, posing a risk to organisations managing SD-WAN infrastructure. Active exploitation makes this more urgent than its CVSS score of 6.5 might suggest. Security Architect’s Take: Apply Cisco’s security updates to Catalyst SD-WAN Manager immediately — active exploitation in the wild overrides the medium CVSS rating. Review web UI access controls and restrict SD-WAN Manager exposure to trusted networks or VPN-only access while patching is under way. ...

16 June 2025 · ZX Cloud Security

CVE-2026-54420: LiteSpeed cPanel Plugin Root Escalation

🟠 High | Source: The Hacker News CISA has added CVE-2026-54420, a high-severity privilege escalation flaw in the LiteSpeed cPanel Plugin, to its Known Exploited Vulnerabilities catalogue. The vulnerability carries a CVSS score of 8.5 and allows attackers to escalate privileges to root level on affected systems. US federal agencies must apply patches by 18 June 2026, but active exploitation means all organisations running this plugin should treat this as urgent. ...

16 June 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options