AWS WAF Bot Control for AI Agent Traffic Auth

🟡 Medium | Source: AWS Security Blog AWS has published guidance on using WAF Bot Control to authenticate legitimate AI agent traffic, addressing a growing challenge as automated tools increasingly access web applications. Traditional IP-based filtering breaks down in multi-tenant environments like Amazon Bedrock AgentCore, where many workloads share the same IP space. This matters because organisations need a reliable way to permit genuine AI agent traffic without inadvertently opening the door to malicious bots. ...

14 July 2024 Â· ZX Cloud Security

CVE-2026-34346: Windows WinSock Info Disclosure

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-34346 is a vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys), where sensitive information is transmitted in cleartext, allowing a locally authenticated attacker to read data they should not have access to. The flaw requires local access to exploit, limiting remote attack surface, but it could be leveraged as part of a broader attack chain to harvest credentials or session data. Windows systems running cloud workloads — including Azure VMs and hybrid-joined endpoints — are in scope. ...

14 July 2024 Â· ZX Cloud Security

CVE-2026-34349 Windows Media Info Disclosure Flaw

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-34349 is an information disclosure vulnerability in Windows Media that allows a locally authenticated attacker to access sensitive information they should not be able to see. The flaw requires the attacker to already have a foothold on the affected system, limiting remote exploitation risk. While not critical, it could be chained with other vulnerabilities to facilitate privilege escalation or lateral movement. Security Architect’s Take: Prioritise patching Windows endpoints and Azure VMs running Windows workloads in your next maintenance cycle, particularly where Windows Media components are active. Assess whether your Azure VM images and golden AMIs include the affected Windows Media libraries and update them accordingly. ...

14 July 2024 Â· ZX Cloud Security

CVE-2026-49165: Windows App Store Info Disclosure

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-49165 is an information disclosure vulnerability in the Microsoft Windows App Store, caused by the use of an uninitialised resource. A locally authenticated attacker could exploit this flaw to access sensitive information they should not be able to see. Whilst exploitation requires local access and does not allow remote code execution, unintended data exposure can still facilitate further attacks or privilege escalation. Security Architect’s Take: Ensure Windows endpoints and any Azure-connected devices running the Windows App Store are patched promptly via your patch management tooling; additionally, review least-privilege controls and local user access policies to reduce the risk of a local attacker reaching this attack surface. ...

14 July 2024 Â· ZX Cloud Security

Crypto Wallet Extensions Leak Addresses & Track Users

🟡 Medium | Source: The Hacker News Researchers from KU Leuven analysed 85 popular cryptocurrency wallet browser extensions and found they leak data that can be used to link a user’s separate blockchain addresses together and track them across websites. The communication patterns between wallets, websites, and blockchain nodes expose enough information for third parties to de-anonymise users — even on sites where a real name or email is already known. This undermines a core assumption of crypto wallet privacy. ...

14 July 2024 Â· ZX Cloud Security

Meta Patent: AI Emotion Tracking via Voice All Day

🟡 Medium | Source: The Hacker News Meta has filed a patent for an AI system capable of passively monitoring a user’s voice throughout the day to infer emotional states, logging each reading with timestamps, location data, and device activity. The system would create a detailed, continuous record of a person’s emotional and behavioural patterns without necessarily requiring active engagement. This raises significant privacy and data protection concerns, particularly around continuous passive surveillance and the handling of sensitive biometric and inferred health data. ...

13 July 2024 Â· ZX Cloud Security

AI-Generated PowerShell Used for Active Directory Recon

🟡 Medium | Source: The Hacker News An unknown attacker used an AI-generated PowerShell script to enumerate Active Directory, mapping users, computers, and domain controllers before exporting the results into a structured HTML report. The script’s structure and style suggest it was produced using a generative AI tool, lowering the technical barrier for conducting sophisticated reconnaissance. This matters because it signals that even less-skilled threat actors can now produce effective, tailored attack tooling with minimal effort. ...

13 July 2024 Â· ZX Cloud Security

CVE-2025-38096: Azure Linux iwlwifi Kernel Driver Flaw

🟡 Medium | Source: Microsoft Security Response Center CVE-2025-38096 is a vulnerability in the Linux kernel’s iwlwifi Wi-Fi driver, specifically related to improper warning behaviour when a firmware error occurs. Microsoft has published this advisory in the context of Azure, suggesting it affects Linux-based virtual machines or infrastructure running on Azure. While the summary is sparse, firmware-level driver issues can expose systems to stability or privilege-related risks depending on the underlying flaw. ...

13 July 2024 Â· ZX Cloud Security

CVE-2026-45489: Microsoft Edge Spoofing Vulnerability

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-45489 is a spoofing vulnerability in Microsoft Edge (Chromium-based), meaning an attacker could potentially deceive users by manipulating how content or identity is displayed within the browser. This update is an informational change only, adding a CWE (Common Weakness Enumeration) classification with no change to the underlying vulnerability details or patch status. No new action is required as a result of this update. ...

12 July 2024 Â· ZX Cloud Security

AWS Designated UK Critical Third Party for Finance

🟡 Medium | Source: AWS Security Blog AWS has been officially designated as a Critical Third Party (CTP) to the UK financial sector under a new regulatory regime that came into force on 1 January 2025. This designation, made by HM Treasury, gives the Bank of England, PRA, and FCA direct oversight powers over AWS’s services as they relate to UK financial institutions. For financial sector clients, this means AWS is now subject to formal regulatory scrutiny, which should improve resilience and accountability but also introduces new compliance obligations. ...

10 July 2024 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options