432 Linux Kernel CVEs in Two Days: What It Means

🟡 Medium | Source: The Register — Security The Linux kernel security team published 432 CVEs over a single Sunday-to-Monday period, an unusually high volume that has sparked debate about whether AI tooling is being used to automate vulnerability discovery and reporting. The sheer scale of the release creates a significant triage burden for teams responsible for patching Linux-based infrastructure. While many of the CVEs may be low severity, the volume makes it harder to identify and prioritise genuinely dangerous issues. ...

22 July 2024 Â· ZX Cloud Security

AI Governance: Security's Role in Safe AI Adoption

🟡 Medium | Source: The Hacker News A growing number of employees are adopting AI tools at work, with or without formal organisational approval, creating shadow AI risks that security teams must address. Security leaders who proactively build governed, visible AI adoption pathways are better positioned to manage risk whilst enabling business value. Effective AI governance gives CISOs strategic influence by aligning security controls with operational needs rather than simply blocking usage. ...

22 July 2024 Â· ZX Cloud Security

Council Worker Convicted Under Computer Misuse Act

🟡 Medium | Source: The Register — Security A Herefordshire Council employee received a suspended sentence after being convicted under the Computer Misuse Act for unlawfully accessing personal data over four days. The case highlights the ongoing insider threat risk posed by staff abusing legitimate system access. While no cloud-specific vulnerability was exploited, the incident underscores how authorised users can cause significant data breaches without any technical attack. Security Architect’s Take: Review your access controls and audit logging for internal systems — ensure that user activity monitoring and anomaly detection are in place to flag unusual data access patterns, particularly bulk or out-of-role queries, and that logs are retained and reviewed regularly. ...

22 July 2024 Â· ZX Cloud Security

CVE-2026-64205: Azure Linux Kernel i2c Driver Flaw

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-64205 is a kernel-level vulnerability in the i2c-i801 driver, which handles communication between a processor and low-level hardware components such as temperature sensors and power management chips. The flaw involves corruption of the hardware state machine during error handling, which could lead to unpredictable behaviour or system instability. While rooted in Linux kernel internals, this is relevant to Azure environments where the underlying host infrastructure or Linux-based virtual machines may be affected. ...

22 July 2024 Â· ZX Cloud Security

CVE-2026-64187: Azure Linux XFS Log Recovery Flaw

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-64187 is a vulnerability in the Linux XFS filesystem’s log recovery mechanism, surfaced via Microsoft’s security advisory channel for Azure. The flaw causes the system to fail recovery when encountering a committed log item with no associated regions, which could lead to filesystem corruption or denial of service in affected environments. This is relevant to Azure customers running Linux workloads, particularly those using XFS-formatted volumes. ...

22 July 2024 Â· ZX Cloud Security

LG Bans Smart TV Apps Used as Residential Proxies

🟡 Medium | Source: Krebs on Security Over 42% of apps on LG’s webOS smart TV platform were found to be silently routing third-party internet traffic through users’ televisions, effectively turning them into residential proxy nodes without consent. LG has announced it will suspend any apps that exploit this capability. This matters because residential proxies are frequently abused to bypass fraud detection, conduct credential stuffing attacks, and obscure malicious traffic origins. ...

22 July 2024 Â· ZX Cloud Security

AI Deception Risk: When Verification Fails | Cloud Security

🟡 Medium | Source: The Register — Security This article examines the problem of AI systems producing deceptive or misleading outputs that are difficult for humans to detect and verify. The core issue is that traditional ’trust but verify’ security approaches break down when verification itself is computationally or practically infeasible. This has significant implications for organisations using AI in security-sensitive workflows or decision-making processes. Security Architect’s Take: Avoid placing AI outputs in positions where they are acted upon without a viable human or automated verification layer — audit AI-assisted decisions in security tooling (SIEM, threat detection, code review) and establish clear escalation paths where AI confidence is low or outputs are unverifiable. ...

21 July 2024 Â· ZX Cloud Security

Apple Patches Hide My Email Privacy Bug | iCloud Fix

🟡 Medium | Source: The Hacker News Apple has patched a flaw in its Hide My Email privacy feature that caused users’ real email addresses to be leaked into Mail logs, undermining the anonymisation the service is designed to provide. The vulnerability was discovered by Tyler Murphy of EasyOptOuts and disclosed to Apple over a year before a fix was deployed on 3 July 2026. Anyone relying on Hide My Email to mask their identity from senders or services could have had their actual address exposed. ...

21 July 2024 Â· ZX Cloud Security

Kratos PhaaS Platform Seized: 200+ Servers Taken Down

🟡 Medium | Source: The Register — Security The Kratos phishing-as-a-service (PhaaS) platform has been dismantled by an international law enforcement operation led by German authorities, with over 200 servers taken offline. The alleged developer has been arrested in Indonesia. Kratos was a commercial kit that allowed criminals to conduct large-scale phishing campaigns without technical expertise, lowering the barrier to credential theft significantly. Security Architect’s Take: Review your organisation’s email security telemetry and SIEM logs for indicators of compromise associated with Kratos-generated phishing infrastructure; cross-reference against published IOCs from the takedown. This is also a timely prompt to validate that phishing-resistant MFA (e.g. FIDO2/passkeys) is enforced across all identity providers, reducing the value of any credentials harvested via PhaaS platforms. ...

21 July 2024 Â· ZX Cloud Security

MIT AI Surveillance: 500+ Cameras with Facial Recognition

🟡 Medium | Source: Schneier on Security MIT is deploying over 500 AI-enabled surveillance cameras across its campus at a cost of more than $3 million, with capabilities including real-time facial recognition, crowd detection, and demographic classification by gender, age, and clothing colour. Data is retained for up to 30 days by default. The scale and capability of this system raises significant privacy, data governance, and civil liberties concerns in an academic environment. ...

21 July 2024 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options