Miinto Data Breach: Shoppers Warned of Phishing Risk

🟡 Medium | Source: The Register — Security Scandinavian fashion marketplace Miinto has disclosed a data breach affecting its order management system, with customer data exposed to an unauthorised third party. The Copenhagen-based company is warning affected shoppers to be vigilant against phishing attempts following the incident. The breach highlights ongoing risks to e-commerce platforms where customer order data — including contact details — can be weaponised for targeted social engineering. ...

10 July 2024 · ZX Cloud Security

Lumen Technologies Scales Asset Inventory to 1.1M

🟡 Medium | Source: The Hacker News Lumen Technologies scaled its asset inventory from 17,000 to 1.1 million assets by overhauling its exposure management programme, highlighting how dramatically underestimated asset counts create blind spots across security operations. A wider industry survey found that fewer than half of organisations consolidate asset and exposure data into a single view, meaning vulnerability and risk programmes are built on incomplete foundations. Accurate asset visibility is a prerequisite for effective exposure management at enterprise scale. ...

10 July 2024 · ZX Cloud Security

AI Surveillance: Cloud Privacy & Security Risks Explained

🟡 Medium | Source: Schneier on Security AI-powered surveillance systems are on the horizon that could monitor behaviour in public and private spaces, automatically linking infractions to official records and notifying authorities in real time. This represents a fundamental shift in how governments and corporations could enforce rules at scale. The implications for civil liberties, data privacy, and the security of centralised identity and behavioural databases are profound. Security Architect’s Take: Cloud security architects should begin assessing the data governance and privacy risk exposure of any systems they build or operate that could feed into large-scale behavioural analytics platforms — particularly around data retention policies, access controls on identity-linked records, and compliance with UK GDPR and the Data Protection Act 2018. ...

10 July 2024 · ZX Cloud Security

NHS Forth Valley Email Data Breach: Maternity Patient Data E

🟡 Medium | Source: The Register — Security NHS Forth Valley is investigating a data breach involving maternity patients’ personal information that was exposed through an email handling error. This is the latest in a series of similar incidents affecting NHS health boards, highlighting systemic failures in basic email data protection practices. The breach raises significant concerns under UK GDPR given the sensitive nature of maternity and health data. Security Architect’s Take: Review your organisation’s email data loss prevention (DLP) controls immediately — ensure policies are in place to prevent bulk sending of sensitive data without encryption or BCC enforcement, and consider deploying Microsoft Purview or equivalent DLP tooling to automatically classify and restrict emails containing special category health data. ...

10 July 2024 · ZX Cloud Security

Ransomware Negotiator Jailed 70 Months for BlackCat Collusio

🟡 Medium | Source: The Hacker News A former ransomware negotiator named Martino has been sentenced to 70 months in US federal prison for secretly colluding with the BlackCat ransomware gang to extort victims rather than genuinely negotiating on their behalf. He also conspired with two other cybersecurity professionals to target additional victims in 2023. The case highlights a significant insider threat risk within the incident response and negotiation industry. Security Architect’s Take: When engaging third-party ransomware negotiators or incident response firms, conduct thorough due diligence including background checks, contractual liability clauses, and ensure all communications and negotiation activity are independently audited. Consider requiring transparency reports and dual-approval processes for any ransom-related decisions. ...

10 July 2024 · ZX Cloud Security

CVE-2026-56289: GNU patch Loop Flaw Affects Azure

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-56289 is a vulnerability in GNU patch involving a loop with an unreachable exit condition, which can cause a program to hang indefinitely — a denial-of-service scenario. This affects Microsoft Azure environments where GNU patch is used in build pipelines, container images, or VM configurations. While not typically a remote code execution flaw, uncontrolled loops can be exploited to exhaust resources and disrupt services. ...

10 July 2024 · ZX Cloud Security

AI to Drive More Microsoft Patches Each Month

🟡 Medium | Source: The Register — Security Microsoft has warned customers that the increasing integration of AI into its products will result in a higher volume of patches being released on Patch Tuesday. More AI-generated or AI-adjacent code means a larger attack surface and more frequent vulnerability disclosures. Conveniently, Microsoft is simultaneously promoting its automated patching tooling as the solution to managing this increased workload. Security Architect’s Take: Review and strengthen your patch management pipeline now — if Patch Tuesday cadence is set to increase, any manual or semi-automated processes will become a bottleneck. Evaluate whether Microsoft’s native auto-patching tools (Azure Update Manager, Autopatch) or third-party alternatives fit your risk tolerance and compliance requirements before the volume spike hits. ...

10 July 2024 · ZX Cloud Security

Dormant GitHub Accounts Used to Map Corporate Orgs

🟡 Medium | Source: The Hacker News Attackers are systematically mapping corporate GitHub organisations, repositories, and user accounts using the GitHub API, according to Datadog Security Labs. They are using automated scraping tools disguised with legitimate-sounding user agents, alongside dormant ‘ghost’ accounts that are often years old, or compromised OAuth tokens. This intelligence-gathering activity likely precedes targeted attacks such as supply chain compromises, credential theft, or targeted phishing. Security Architect’s Take: Audit your GitHub organisation’s visibility settings and restrict public exposure of member lists, repositories, and team structures where possible. Review OAuth token grants and personal access tokens regularly, enforce token expiry policies, and enable GitHub’s audit log streaming to a SIEM to detect unusual API enumeration patterns. ...

9 July 2024 · ZX Cloud Security

npm 12 Disables Install Scripts to Cut Supply Chain Risk

🟡 Medium | Source: The Hacker News npm version 12 has been released with install scripts disabled by default, meaning packages can no longer automatically execute arbitrary code during installation without explicit opt-in. GitHub is also deprecating granular access tokens that could be used to circumvent two-factor authentication. These changes directly reduce the attack surface for supply chain attacks via malicious npm packages. Security Architect’s Take: Review your CI/CD pipelines and developer workstation tooling for any reliance on automatic install scripts — you will need to explicitly enable allowScripts for legitimate use cases. Audit existing npm tokens and rotate any granular access tokens (GATs) ahead of their deprecation, ensuring all service accounts use 2FA-compliant authentication. ...

9 July 2024 · ZX Cloud Security

Cloud Bucket Hijacking & Windows LPE: ThreatsDay Roundup

🟡 Medium | Source: The Hacker News This week’s ThreatsDay roundup covers 20 security stories, including cloud storage bucket hijacking, a Windows local privilege escalation chain, and a global fraud enforcement action. The common thread is mundane misconfigurations and overlooked settings — small administrative oversights that quietly enable serious breaches. Security Architect’s Take: Audit all S3, GCS, and Azure Blob storage buckets for namespace reuse and public accessibility, and review Windows endpoint privilege configurations in your cloud-managed estate — these low-noise attack paths are actively being exploited and are easily missed in routine reviews. ...

9 July 2024 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options