Proxy Botnets, Browser Ransomware & AI Agent Threats

🟡 Medium | Source: The Hacker News This weekly security recap highlights a cluster of threats that exploited ordinary, trusted components: home streaming devices were conscripted into proxy botnets, browser permission prompts were abused to deliver ransomware, AI agents were manipulated via prompt injection, and fake proof-of-concept repositories were used to distribute malware. The common thread is misplaced trust — in everyday devices, developer tooling, identity flows, and AI systems. These are not exotic attack surfaces; they are the mundane infrastructure most organisations rely on daily. ...

6 July 2024 · ZX Cloud Security

UK Supermarket Expands Facial Recognition to 150 Stores

🟡 Medium | Source: The Register — Security A major British supermarket chain is expanding its facial recognition system to up to 150 additional stores by the end of the year, aiming to reduce shoplifting. The technology identifies individuals on a watchlist and alerts store staff in real time. The rollout has drawn criticism from privacy advocates who argue it constitutes disproportionate surveillance of the general public. Security Architect’s Take: If your organisation is evaluating or operating biometric surveillance systems, ensure your data protection impact assessment (DPIA) is current and reviewed by legal counsel against UK GDPR and the ICO’s biometric data guidance — particularly given the ICO’s increasing scrutiny of facial recognition in retail environments. ...

6 July 2024 · ZX Cloud Security

France ANSSI to End Non-Quantum-Safe Encryption Certs

🟡 Medium | Source: Schneier on Security France’s national cybersecurity agency ANSSI has announced it will stop certifying security products that lack quantum-resistant encryption from 2027, with a target for businesses to purchase only quantum-safe products by 2030. Because ANSSI certification is mandatory for French government agencies and critical infrastructure operators, this effectively mandates a migration away from classical encryption across those sectors. The move signals a broader regulatory shift in Europe towards post-quantum cryptography (PQC) standards. ...

6 July 2024 · ZX Cloud Security

TrojPix: Data Exfiltration from Air-Gapped PCs via Video Cab

🟡 Medium | Source: The Hacker News Researchers have demonstrated a technique called TrojPix that exfiltrates data from air-gapped computers by subtly manipulating on-screen pixels to generate detectable radio emissions from the video cable, which a nearby receiver can decode. The attack requires malware to already be present on the target machine. It represents a novel side-channel threat for high-security environments that rely on physical isolation as a primary defence. Security Architect’s Take: For environments handling sensitive workloads on air-gapped systems — including on-premises infrastructure supporting classified or regulated data — review physical security controls around terminal access and consider RF shielding or Faraday enclosures for the most sensitive machines. Prioritise preventing initial malware compromise, as TrojPix is entirely dependent on a prior foothold. ...

6 July 2024 · ZX Cloud Security

CVE-2026-53223: Azure Linux Kernel Network Flaw

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-53223 is a Linux kernel vulnerability affecting the network stack’s handling of timestamp control messages (cmsgs), where insufficient validation of error queue socket buffers (skbs) could lead to unintended behaviour. The flaw relates to the real error queue path not being properly guarded, which may allow information disclosure or other memory-related issues. This is relevant to Azure environments running Linux-based workloads, particularly those exposed to network-level interactions. ...

4 July 2024 · ZX Cloud Security

CVE-2026-13933: Edge Chromium Password Policy Flaw

🟡 Medium | Source: Microsoft Security Response Center A vulnerability in Chromium’s password policy enforcement (CVE-2026-13933) has been identified, affecting Microsoft Edge due to its Chromium-based architecture. Insufficient policy enforcement in the Passwords component could allow an attacker to bypass intended security restrictions around stored credentials. Microsoft Edge users are affected and should apply the latest browser update to remediate the issue. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest version across all managed endpoints, particularly on devices with access to cloud management consoles or sensitive internal tooling. Consider enforcing browser version compliance via Intune or Group Policy to confirm patched versions are deployed before users access Azure or other cloud portals. ...

3 July 2024 · ZX Cloud Security

CVE-2026-55945: Microsoft Edge Information Disclosure

🟡 Medium | Source: Microsoft Security Response Center A race condition vulnerability in Microsoft Edge (Chromium-based) allows a locally authenticated attacker to access information they should not be able to see. The flaw arises from improper synchronisation when multiple processes share a resource concurrently. While exploitation requires local access, it could expose sensitive data in enterprise environments where Edge is widely deployed. Security Architect’s Take: Prioritise deploying the patched version of Microsoft Edge across your estate, particularly on privileged workstations and developer machines where sensitive cloud credentials or tokens may be present in the browser. Verify that your endpoint management tooling (e.g. Intune or SCCM) is enforcing automatic browser updates. ...

3 July 2024 · ZX Cloud Security

CVE-2026-58522: Edge for Android Info Disclosure

🟡 Medium | Source: Microsoft Security Response Center A relative path traversal vulnerability in Microsoft Edge for Android (CVE-2026-58522) allows a local, unauthorised attacker to access and disclose sensitive information stored on the device. The flaw does not require network access, meaning exploitation is limited to someone with physical or local access to the affected device. While the attack surface is constrained, any information disclosure risk on a mobile browser used to access corporate cloud resources warrants attention. ...

3 July 2024 · ZX Cloud Security

Flock Cameras Track Cars Without Number Plates

🟡 Medium | Source: Schneier on Security Flock Safety’s CCTV camera network, widely deployed by US law enforcement, can identify and track vehicles without requiring a readable number plate by building a ‘Vehicle Fingerprint’ from visual characteristics such as decals, bumper stickers, and roof racks. This capability enables police to search for and correlate vehicle movements across multiple locations using minimal identifying information. The system raises significant privacy concerns around mass surveillance of individuals who have taken steps to avoid plate-based identification. ...

3 July 2024 · ZX Cloud Security

Palo Alto Koi Security Sued Over AI Hallucinated Espionage R

🟡 Medium | Source: The Register — Security A startup called MeetingTV is suing Palo Alto Networks’ Koi Security after an AI-generated threat intelligence report allegedly fabricated a link between the company and Chinese espionage activity. The lawsuit highlights a growing risk with AI-produced security reports: hallucinated or unsupported claims can cause serious reputational and business harm to organisations incorrectly named as threat actors or their associates. This case sets a potentially significant legal precedent for liability around AI-generated threat intelligence outputs. ...

2 July 2024 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options