AI Coding Agents Triggering Endpoint Security Rules

🟡 Medium | Source: The Hacker News Sophos research shows that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are triggering endpoint detection rules designed to catch human attackers, because their automated behaviour closely mirrors attacker techniques — including credential store enumeration and browser credential decryption. The agents themselves are not malicious, but their actions are behaviourally indistinguishable from an intrusion to a standard detection engine. This creates a signal-to-noise problem for security teams, increasing alert fatigue and the risk of genuine threats being missed. ...

8 July 2024 Â· ZX Cloud Security

CISO Guide to Post-Quantum Cryptography on AWS

🟡 Medium | Source: AWS Security Blog Post-quantum cryptography (PQC) migration has moved from theoretical planning to active regulatory mandate across major economies, with CISOs now expected to lead organisation-wide transitions. The core challenge is not selecting new algorithms — it is coordinating change across complex enterprises where asymmetric cryptography is deeply embedded in systems, supply chains, and third-party dependencies. Getting this wrong could leave organisations exposed once cryptographically relevant quantum computers emerge. ...

8 July 2024 Â· ZX Cloud Security

Convicted Felons Behind Zero-Day Vulnerability Startup

🟡 Medium | Source: Krebs on Security A cybersecurity startup offering large sums to acquire zero-day vulnerabilities is reportedly operated by convicted felons with histories of fraud, fake intelligence firms, and AI-based influence operations run under assumed identities. The concern is that vulnerabilities purchased by such a firm could be exploited offensively, sold to hostile actors, or used in ways that circumvent legitimate disclosure processes. This raises serious questions about the integrity of the vulnerability acquisition market and the risks of selling security research to unvetted brokers. ...

8 July 2024 Â· ZX Cloud Security

GitHub Copilot Safety Bypass via Code Prompts

🟡 Medium | Source: The Hacker News Researchers have found that GitHub Copilot and other AI coding assistants (including Claude and Gemini) can be manipulated into producing harmful code by breaking a dangerous request into small, innocuous-looking steps within a code editor — even when the same request is refused outright in chat. This technique, known as prompt decomposition, effectively bypasses the safety guardrails built into these models. The finding is significant because it demonstrates that content moderation on AI tools is inconsistent across interaction modes, creating a practical exploitation path. ...

8 July 2024 Â· ZX Cloud Security

Windows GDID Telemetry Used to Identify Scattered Spider Sus

🟡 Medium | Source: The Register — Security Windows’ anti-piracy telemetry system, known as GDID (Global Device Identifier), has reportedly been used as part of the evidence trail to identify a suspect linked to the Scattered Spider threat group. The tool collects device and activity data that, when combined with other telemetry, makes it significantly harder for threat actors to operate anonymously on Windows systems. This highlights how built-in OS telemetry can serve as a forensic asset in cybercrime investigations. ...

7 July 2024 Â· ZX Cloud Security

Enforce Zero Data Retention in AWS Bedrock with SCPs

🟡 Medium | Source: AWS Security Blog AWS has published guidance on enforcing zero data retention policies in Amazon Bedrock, particularly relevant now that some third-party models such as Claude Fable 5 may share data with external providers. Organisations can use Bedrock Projects alongside AWS Service Control Policies (SCPs) to centrally enforce data retention settings across all accounts in an AWS Organisation. This matters because without central enforcement, individual teams or accounts could inadvertently permit prompt and response data to be retained or shared beyond organisational boundaries. ...

7 July 2024 Â· ZX Cloud Security

Windows Device ID Used to Trace Scattered Spider Hacker

🟡 Medium | Source: The Hacker News US prosecutors have used a persistent Windows device ID to link an alleged Scattered Spider member to a cyberattack on a luxury jewellery retailer in May 2025. Microsoft records tied the device ID to both the attacker’s persistence account during the intrusion and to personal online accounts belonging to 19-year-old suspect Peter Stokes. The case highlights how hardware and software identifiers retained by cloud and identity providers can become powerful forensic artefacts in cybercrime investigations. ...

7 July 2024 Â· ZX Cloud Security

AI Code Generation & Software Supply Chain Risk

🟡 Medium | Source: The Hacker News AI coding assistants and automated code generation tools are introducing new risks into software supply chains that traditional dependency-scanning tools are not designed to detect. Unlike known open-source packages, AI-generated code may contain subtle vulnerabilities, hallucinated dependencies, or insecure patterns that lack provenance and are difficult to audit at scale. This represents a structural shift in where supply chain risk originates — moving from third-party libraries to the code generation layer itself. ...

7 July 2024 Â· ZX Cloud Security

Google Sues Chinese Phishing-as-a-Service Group Using Gemini

🟡 Medium | Source: Schneier on Security Google has filed a lawsuit against a Chinese cybercrime group called Outsider Enterprise, which operated a phishing-as-a-service platform via Telegram. The group provided customers with nearly 300 scam templates and instructions for using Google’s Gemini AI to generate convincing fake websites impersonating Google, YouTube, and government agencies. This case highlights how threat actors are actively exploiting generative AI tools to lower the technical barrier for large-scale phishing campaigns. ...

7 July 2024 Â· ZX Cloud Security

Pro-Russia Hacktivist Arrested in Spain After FBI Tip

🟡 Medium | Source: The Register — Security Spanish authorities have arrested a man in Palencia on suspicion of involvement with pro-Russia hacktivist groups including NoName057(16), CARR, and Z-Pentest, following a tip-off from the FBI. The suspect is also alleged to have assisted a Ukrainian hacker in fleeing to Russia. This arrest highlights growing international law enforcement cooperation in tackling state-aligned hacktivist activity targeting Western infrastructure. Security Architect’s Take: Review your organisation’s DDoS resilience and incident response plans in light of continued NoName057(16) activity against Western targets — ensure scrubbing services and rate-limiting controls are validated and that threat intelligence feeds include known hacktivist IOCs. ...

7 July 2024 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options