CVE-2026-12019: Chromium Out-of-Bounds Write in Codecs

🟠 High | Source: Microsoft Security Response Center A out-of-bounds write vulnerability has been identified in the Codecs component of Chromium, tracked as CVE-2026-12019. Microsoft Edge inherits this flaw due to its Chromium-based architecture. Out-of-bounds write vulnerabilities can allow attackers to corrupt memory and potentially execute arbitrary code, making this a serious concern for organisations using Edge in corporate environments. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest stable release as soon as a patched version is available, and prioritise this across managed endpoints via Intune or your preferred patch management tooling. If Edge is deployed in Azure Virtual Desktop or used to access cloud management portals, treat this as elevated risk and expedite deployment. ...

15 June 2025 Â· ZX Cloud Security

CVE-2026-12016: Chromium DevTools Input Validation Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-12016 is a vulnerability in Chromium’s DevTools component involving insufficient validation of untrusted input. Microsoft Edge (Chromium-based) is affected as it inherits this flaw from the upstream Chromium project. Google has issued a fix via Chrome Desktop Updates, and Microsoft is consuming that patch into Edge. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest version across all managed endpoints and virtual desktop environments, particularly where users access cloud consoles or DevTools in browser-based workflows. Enforce browser update policies via Intune or Group Policy to minimise exposure windows. ...

15 June 2025 Â· ZX Cloud Security

CVE-2026-12015: Edge Chromium Autofill Use-After-Free

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability (CVE-2026-12015) has been identified in the Autofill component of Chromium, the open-source browser engine underpinning Microsoft Edge. Use-after-free flaws occur when a programme continues to reference memory after it has been freed, potentially allowing an attacker to execute arbitrary code. Microsoft Edge inherits this vulnerability from Chromium and is addressed via Google’s upstream patch. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest stable release across all managed endpoints and virtual desktop environments, including Azure Virtual Desktop and Windows 365 deployments. Validate that your browser update policies via Intune or Group Policy are enforcing timely Chromium-based Edge updates, particularly for privileged users accessing cloud management consoles. ...

15 June 2025 Â· ZX Cloud Security

CVE-2026-12012: Use-After-Free in Microsoft Edge & Chromium

🟠 High | Source: Microsoft Security Response Center CVE-2026-12012 is a use-after-free vulnerability in the Network component of Chromium, the open-source browser engine underpinning Microsoft Edge. Use-after-free flaws occur when a programme continues to use memory after it has been freed, potentially allowing an attacker to execute arbitrary code. Microsoft Edge inherits this vulnerability from Chromium and is addressed via Google’s upstream patch. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest version across all managed endpoints and virtual desktop environments — prioritise any Azure Virtual Desktop or Windows 365 deployments where browser-based access to cloud resources is common. Verify your endpoint management tooling (e.g. Intune) is enforcing the patched Edge build. ...

15 June 2025 Â· ZX Cloud Security

CVE-2026-12008: Edge Chromium Use-After-Free Flaw

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability (CVE-2026-12008) has been identified in the Chromium DigitalCredentials component, affecting Microsoft Edge due to its Chromium-based architecture. Use-after-free flaws occur when a programme continues to reference memory after it has been freed, potentially allowing an attacker to execute arbitrary code. This is particularly relevant in browser-based environments where users access cloud management portals and sensitive web applications. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest stable release as soon as Microsoft publishes a patched build ingesting the fixed Chromium version; consider enforcing browser version compliance via Intune or Group Policy to reduce exposure across managed endpoints accessing Azure portals and cloud consoles. ...

15 June 2025 Â· ZX Cloud Security

PRC Spies Infiltrate Medical & Military Networks via Gmail

🟠 High | Source: The Register — Security Google has revealed that Chinese state-linked threat actors infiltrated medical research and military networks for over a year, using Gmail as a covert communications channel to exfiltrate sensitive data. The targets included drone technology, pathogen research, and other strategically valuable information. The prolonged dwell time and breadth of targets highlight the sophistication and patience of PRC-affiliated advanced persistent threat groups. Security Architect’s Take: Review your organisation’s outbound traffic policies to ensure sanctioned cloud services such as Gmail cannot be abused as covert command-and-control or exfiltration channels; implement CASB controls, egress filtering, and anomaly detection on email API usage, particularly for sensitive network segments handling research or defence-adjacent data. ...

15 June 2025 Â· ZX Cloud Security

Chrome 0-Day, UniFi Exploits & VPN Flaw: Weekly Recap

🟠 High | Source: The Hacker News This weekly roundup covers several concurrent security issues including a Chrome zero-day, exploits targeting Ubiquiti UniFi devices, macOS information-stealing malware, and a VPN vulnerability. The common thread is attackers leveraging neglected or deprecated software, abandoned packages, and phishing-as-a-service tooling to gain initial access. These are not novel attack classes — they reflect persistent failures in asset lifecycle management and patch hygiene. Security Architect’s Take: Audit your attack surface for deprecated login endpoints, end-of-life network appliances (particularly UniFi devices exposed to the internet), and any third-party packages in your pipelines that may have been abandoned by their maintainers. Prioritise patching Chrome across managed endpoints and validate VPN appliance versions against current vendor advisories. ...

15 June 2025 Â· ZX Cloud Security

Arch Linux AUR Locked Down After Malicious Package Wave

🟠 High | Source: The Register — Security Arch Linux has temporarily frozen new account registrations on the Arch User Repository (AUR) after attackers submitted a wave of malicious package updates designed to compromise systems that install from the community-maintained repository. AUR packages are not officially vetted, making them a high-value target for supply chain attacks. This incident highlights the ongoing risk of depending on community repositories in build pipelines and development environments. ...

15 June 2025 Â· ZX Cloud Security

WordPress Plugin Supply-Chain Backdoor: PushEngage & OptinMo

🟠 High | Source: The Hacker News Attackers tampered with JavaScript files distributed by three popular WordPress plugins — PushEngage, OptinMonster, and TrustPulse — injecting malicious code that creates a rogue admin account and installs a hidden backdoor plugin when a logged-in administrator loads the compromised script. The attack is a supply-chain compromise targeting the plugin delivery mechanism rather than WordPress itself, meaning sites that kept plugins updated may still have been affected. Any site running these plugins while an admin was active during the compromise window should be treated as potentially backdoored. ...

15 June 2025 Â· ZX Cloud Security

CVE-2026-46433: lldpd Heap OOB Read in Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-46433 is a heap out-of-bounds read vulnerability in lldpd, the open-source Link Layer Discovery Protocol daemon, triggered during VLAN decapsulation via a flawed memmove operation. An attacker able to send crafted LLDP frames on an adjacent network could exploit this to read sensitive memory contents, potentially leaking information from affected hosts. This affects Azure environments where lldpd is running on underlying infrastructure or customer-managed VMs. ...

15 June 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options