CVE-2026-11632: Use-After-Free in Edge TabStrip

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability (CVE-2026-11632) has been identified in the TabStrip component of the Chromium browser engine. Microsoft Edge, being Chromium-based, inherits this flaw and requires patching via a Chromium upstream fix. Use-after-free bugs can allow attackers to execute arbitrary code by manipulating freed memory, potentially compromising the user’s system. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest version across all managed endpoints and virtual desktop environments, including Azure Virtual Desktop deployments. Enforce browser update policies via Intune or Group Policy, and consider restricting Edge usage in privileged-access workstations until the patch is confirmed deployed. ...

16 June 2025 · ZX Cloud Security

CVE-2026-11631: Use-After-Free in Chromium Aura | Edge

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability (CVE-2026-11631) has been identified in the Aura windowing framework within the Chromium engine. Microsoft Edge, being Chromium-based, is affected and has ingested the upstream fix from Google Chrome. Use-after-free flaws can allow attackers to execute arbitrary code by manipulating freed memory, making them potentially serious if exploited via a malicious webpage. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest stable release across all managed endpoints and virtual desktop environments, including Azure Virtual Desktop deployments. Verify that browser update policies are enforced via Intune or Group Policy, and consider temporarily restricting access to untrusted web content on sensitive workstations until patching is confirmed. ...

16 June 2025 · ZX Cloud Security

CVE-2026-11630: Use-After-Free Flaw in Microsoft Edge

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability (CVE-2026-11630) has been identified in the File Input component of Chromium, the open-source browser engine underpinning Microsoft Edge. Use-after-free flaws occur when a programme continues to reference memory after it has been freed, potentially allowing an attacker to execute arbitrary code. Microsoft Edge users and enterprise deployments are affected until the Chromium-based patch is applied. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest Chromium-based release across all managed endpoints and virtual desktop environments, including any Azure Virtual Desktop or Windows 365 deployments. Prioritise enforcement via Intune or Group Policy, and review browser auto-update policies to confirm they are active. ...

16 June 2025 · ZX Cloud Security

CVE-2026-11629: Use-After-Free in Chromium Ozone & Edge

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability (CVE-2026-11629) has been identified in the Ozone windowing framework within the Chromium engine. Microsoft Edge, being Chromium-based, is affected and has ingested the fix from Google Chrome. Use-after-free flaws can allow attackers to execute arbitrary code by manipulating freed memory, potentially compromising the browser and the underlying system. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest Chromium-based release across all managed endpoints and virtual desktop environments, including Azure Virtual Desktop. Prioritise patching for any users accessing sensitive cloud consoles or internal tooling via Edge. ...

16 June 2025 · ZX Cloud Security

CVE-2026-11628: Chromium Use-After-Free in Edge

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability (CVE-2026-11628) has been identified in the Ozone display platform component of Chromium. Microsoft Edge, being Chromium-based, inherits this flaw and has been patched via Google’s upstream Chromium release. Use-after-free bugs can allow attackers to execute arbitrary code by manipulating freed memory, making them potentially severe. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest Chromium-based release across all managed endpoints and virtual desktop environments, including Azure Virtual Desktop deployments. Validate that your browser update policies enforce automatic patching and consider using Microsoft Endpoint Manager or Intune to confirm compliance. ...

16 June 2025 · ZX Cloud Security

Chinese Hackers Abused Google Workspace Rules to Steal Email

🟠 High | Source: The Hacker News A Chinese state-linked espionage group compromised North American medical, academic, and military research organisations by planting a backdoor on REDCap research data servers to harvest credentials. Once inside, the attackers manipulated Google Workspace email forwarding rules to silently copy and exfiltrate sensitive research and defence communications over an extended period. The attack is notable for its stealth and abuse of legitimate platform features, making detection significantly harder. ...

15 June 2025 · ZX Cloud Security

North Korean Hackers Target Developers With Malware

🟠 High | Source: The Hacker News North Korean threat actors known as Contagious Interview are targeting software developers by disguising malware within fake job recruitment and code review scenarios. Attackers use these lures to trick developers into executing malicious code on their machines, effectively turning trusted developer tools and workflows into malware delivery mechanisms. This is significant because developers often have privileged access to cloud environments, source code repositories, and CI/CD pipelines, making them high-value targets. ...

15 June 2025 · ZX Cloud Security

CVE-2026-11931: Kiro IDE Auth Token Exposure

🟠 High | Source: AWS Security Bulletins A vulnerability in Kiro IDE (AWS’s agentic development environment) on macOS and Linux incorrectly sets the authentication token cache file to world-readable permissions (0644) rather than owner-only (0600). This means other local users or processes on the same machine could read the authentication token, potentially allowing unauthorised access to AWS services or the IDE’s AI capabilities. The issue affects all versions prior to 0.11.133. ...

15 June 2025 · ZX Cloud Security

ShinyHunters Breach: PeopleSoft Attacks Hit 100+ Orgs

🟠 High | Source: The Register — Security The hacking group ShinyHunters has breached the Council of Europe by exploiting vulnerabilities in Oracle PeopleSoft, the enterprise HR and administrative software used by many large organisations. The attack also affected Nottingham University and over 100 other unnamed victims, suggesting a widespread, opportunistic campaign targeting PeopleSoft deployments. The breach raises serious concerns about the exposure of sensitive personnel and organisational data held within ERP systems. ...

15 June 2025 · ZX Cloud Security

Microsoft 365 Copilot SearchLeak Flaw: Data Theft Risk

🟠 High | Source: The Hacker News Researchers at Varonis Threat Labs discovered a chain of three vulnerabilities in Microsoft 365 Copilot Enterprise Search, dubbed ‘SearchLeak’, that could be triggered by a single click on a legitimate microsoft.com link. The attack could silently exfiltrate emails, calendar entries, indexed files, and MFA codes without any obvious warning signs. Because the malicious link originated from a trusted Microsoft domain, standard phishing filters and URL-blocking tools would not have flagged it. ...

15 June 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options