Android TV Boxes Turn Broadband Into Proxy Networks

🟡 Medium | Source: The Hacker News Cheap Android TV boxes manufactured by a Chinese IoT firm have been found pre-loaded with apps that spoof their device identity to impersonate major smartphone brands, committing ad fraud on behalf of the manufacturer. The same apps also silently enrol owners’ home broadband connections into a residential proxy network, effectively monetising victims’ internet bandwidth without consent. Dubbed ‘Fuyao’ by Bitsight researchers, the operation has been attributed to Zhejiang Fengwo IoT Technology Co., Ltd. ...

31 July 2024 · ZX Cloud Security

MSG Facial Recognition: Surveillance & Privacy Risks

🟡 Medium | Source: Schneier on Security Madison Square Garden has been using facial recognition technology to identify and flag individuals entering its venues, including activists who oppose the use of facial recognition itself. The system was notably disabled for Taylor Swift’s wedding, highlighting a two-tier privacy model where wealth and influence can buy exemptions from mass surveillance. This case illustrates the broader societal tension around biometric data collection in public and semi-public spaces. ...

31 July 2024 · ZX Cloud Security

AWS Control Framework for AI Coding Agent Security

🟡 Medium | Source: AWS Security Blog AWS has published a control framework for managing the security risks introduced by AI coding agents such as Kiro and Claude Code, which can autonomously generate and submit code at scale. Because these agents operate at machine speed, they can introduce vulnerabilities, make unintended changes, or be manipulated through prompt injection before a human reviewer notices. The framework provides guardrails to help teams maintain oversight without sacrificing the productivity benefits of AI-assisted development. ...

30 July 2024 · ZX Cloud Security

TV Streaming Sticks Used in Ad Fraud & Proxy Abuse

🟡 Medium | Source: Krebs on Security Generic TV streaming sticks sold with promises of unlimited content are being used in large-scale fraud operations. Beyond the known risk of these devices acting as residential proxies — silently renting out the user’s internet connection — new research reveals they also impersonate mobile devices to fraudulently click ads on AI-generated websites, defrauding advertisers and merchants. This represents a significant expansion in the known threat posed by these consumer devices. ...

30 July 2024 · ZX Cloud Security

GrapheneOS Duress Password: US Border Prosecution

🟡 Medium | Source: Schneier on Security A US citizen is facing prosecution after using a duress password feature in GrapheneOS to wipe his phone when border officials demanded access during a search. The case hinges on whether activating a built-in security feature constitutes obstruction, and challenges the legal grey area of constitutional rights at US borders. This sets a significant precedent for how device security features can be treated as potential evidence of wrongdoing. ...

30 July 2024 · ZX Cloud Security

Network Security as the AI Control Plane Explained

🟡 Medium | Source: The Hacker News Traditional network firewalls were designed for a world where users connect to applications in predictable ways, but AI workloads are fundamentally disrupting this model with dynamic, non-human traffic patterns between agents, APIs, and data pipelines. As AI becomes embedded in enterprise infrastructure, the network is emerging as the primary control plane for enforcing security policy across these new interaction patterns. Security teams that fail to adapt their network controls risk blind spots in AI-driven environments where conventional perimeter assumptions no longer hold. ...

30 July 2024 · ZX Cloud Security

FCC Bans New Foreign Robots & Inverters Over Cyber Risk

🟡 Medium | Source: The Hacker News The FCC has added foreign-manufactured mobile robots and networked power inverters to its Covered List, effectively blocking new models from being imported, marketed, or sold in the US due to national security and cyber risk concerns. Existing authorisations and devices already in use are unaffected, but federal procurement is likely restricted. The move reflects growing regulatory concern about hardware supply chain threats embedded in critical infrastructure and operational technology. ...

30 July 2024 · ZX Cloud Security

AI Legal Liability: Cloud Teams Can't Blame the Algorithm

🟡 Medium | Source: The Register — Security Legal experts are warning that organisations cannot use AI autonomy as a defence when their AI systems cause harm or make unlawful decisions. Responsibility remains firmly with the humans and organisations that deploy and oversee AI, regardless of how the system behaves. This has significant implications for cloud-based AI deployments where automated decision-making can have real-world consequences at scale. Security Architect’s Take: Ensure your AI and ML workloads have clearly documented human oversight mechanisms, audit trails, and governance policies — courts will look for evidence that your organisation exercised reasonable control, so build accountability into your architecture from the outset. ...

30 July 2024 · ZX Cloud Security

Nine-Year Clone Site Fraud Targets Russian Firms

🟡 Medium | Source: The Hacker News A nine-year fraud campaign has been uncovered in which threat actors created convincing clone websites of major Russian companies — including fertiliser and petrochemical firms — to trick international businesses into making advance payments for goods that never arrive. Discovered by Russian cybersecurity vendor F6, the operation has been running since at least 2016 and targets companies conducting cross-border trade. The campaign highlights the enduring risk of domain spoofing and brand impersonation in B2B procurement fraud. ...

29 July 2024 · ZX Cloud Security

AI Is Shrinking Exploit Windows: Fix Your Vuln Triage

🟡 Medium | Source: The Hacker News A commentary piece examines how AI tooling — specifically referencing ‘Mythos’ — is dramatically shortening the time between vulnerability disclosure and working exploits. The core argument is that this shift exposes long-standing weaknesses in traditional vulnerability management programmes, rather than simply accelerating an existing threat. For cloud security teams, this is a signal that reactive, CVSS-score-driven patching workflows may already be dangerously inadequate. Security Architect’s Take: Audit your vulnerability prioritisation pipeline now: if it still relies primarily on CVSS scores and scheduled patch cycles, consider integrating exploit-likelihood signals (e.g. EPSS) and automated patch orchestration to close the window that AI-assisted exploit generation is shrinking. Treat high-severity cloud-exposed vulnerabilities as requiring near-real-time response, not sprint-cycle remediation. ...

29 July 2024 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options