Google Disrupts NetNut Residential Proxy Network

🟡 Medium | Source: The Hacker News Google, working with the FBI and other partners, has significantly disrupted NetNut (also known as Popa), a large residential proxy network that recruited over two million home devices to relay third-party internet traffic without owners’ knowledge. Such networks are frequently exploited by threat actors to anonymise malicious activity, bypass geo-restrictions, and evade detection. The takedown reduces the available pool of compromised devices by millions, degrading a key tool used for fraud, credential stuffing, and other attacks. ...

2 July 2024 · ZX Cloud Security

AI Hijacking, Apple Email Flaw & BlueHammer Ransomware

🟡 Medium | Source: The Hacker News This week’s security roundup covers a broad range of threats including AI compute hijacking, an Apple email vulnerability, and BlueHammer ransomware, alongside 14 additional stories. The unifying theme is that attackers are exploiting small, overlooked gaps — weak permissions, insufficient validation, and misuse of legitimate tooling — rather than single catastrophic breaches. Individually minor, these weaknesses collectively represent significant exposure across cloud, AI, and enterprise environments. ...

2 July 2024 · ZX Cloud Security

India Challenges WhatsApp Username Rollout Over Security

🟡 Medium | Source: The Register — Security India’s government has given WhatsApp three days to justify its rollout of usernames, raising concerns that the feature could enable impersonation attacks on its largest user base. Authorities want Meta to explain what safeguards are in place before the feature proceeds. The move reflects growing regulatory scrutiny of consumer messaging platforms and their security controls at scale. Security Architect’s Take: If your organisation uses WhatsApp for business communications or customer engagement, review whether the username feature introduces impersonation risks in your threat model and consider whether additional verification steps are needed before employees or customers rely on usernames to confirm identity. ...

2 July 2024 · ZX Cloud Security

AWS Network Firewall Container Attribute Rules for EKS & ECS

🟡 Medium | Source: AWS Security Blog AWS has introduced container attribute-based rules in AWS Network Firewall, enabling fine-grained traffic control for containerised workloads running on Amazon EKS and ECS. Security teams can now write firewall rules that reference container-level attributes such as pod labels or task metadata, rather than relying solely on IP addresses or VPC constructs. This is particularly valuable for AI/ML workloads where lateral movement or egress control is critical. ...

1 July 2024 · ZX Cloud Security

VEIL#DROP: PureLogs Stealer Delivered via Blogger

🟡 Medium | Source: The Hacker News A multi-stage malware campaign dubbed VEIL#DROP is abusing Google’s Blogger platform to host and deliver PureLogs, an information-stealing malware. Attackers use spear-phishing or drive-by downloads to lure victims, leveraging the trusted reputation of Blogger to bypass security controls. The campaign is notable because it exploits a legitimate, widely trusted cloud-hosted service to stage its payload delivery, making detection harder. Security Architect’s Take: Review egress filtering and DNS policies to block or alert on unexpected outbound connections to blogger.com from corporate endpoints and cloud workloads. Additionally, ensure endpoint detection tooling is tuned to flag multi-stage script execution chains, even when the initial download originates from a trusted domain. ...

1 July 2024 · ZX Cloud Security

AWS GuardDuty Adds Sensitive File Modification Detections

🟡 Medium | Source: AWS What’s New Amazon GuardDuty Runtime Monitoring has added three new threat detections that alert on sensitive file modifications across EC2, EKS, and ECS workloads. The detections cover persistence, privilege escalation, and defence evasion tactics by monitoring five low-level file operations directly, making them effective even against obfuscated attacks that evade command-line monitoring. Each finding maps to MITRE ATT&CK tactics and includes remediation guidance, helping teams act quickly on post-compromise activity. ...

1 July 2024 · ZX Cloud Security

Ousaban Trojan Targets Spanish & Portuguese Bank Users

🟡 Medium | Source: The Hacker News Ousaban, a Brazilian banking trojan, is targeting Windows users in Spain and Portugal via phishing emails containing fake corrupted PDF files. The campaign, discovered by Fortinet’s FortiGuard Labs in May 2026, uses geofencing to confirm the victim is in the target region and steganography to conceal its payload within an image file. The ultimate aim is credential theft from Iberian banking customers. Security Architect’s Take: Ensure endpoint security controls block steganographic payload delivery and enforce email gateway policies that quarantine password-protected or visually ‘corrupted’ PDFs. For organisations with staff in Spain or Portugal, consider deploying browser isolation for online banking portals and validate that DNS/proxy controls can detect geofencing callbacks used by the dropper. ...

1 July 2024 · ZX Cloud Security

Microsoft Moves Azure Post-Quantum Deadline to 2029

🟡 Medium | Source: The Hacker News Microsoft is accelerating its post-quantum cryptography (PQC) roadmap, targeting 2029 for replacing existing encryption standards across Azure and its broader ecosystem. The shift is driven by faster-than-expected advances in quantum computing, which threaten to undermine current public-key cryptography such as RSA and ECC. This matters because organisations relying on Azure services need to begin their own cryptographic migration planning now to avoid exposure. Security Architect’s Take: Begin a cryptographic inventory of your Azure workloads and dependencies today — identify where RSA, ECC, and other quantum-vulnerable algorithms are in use across certificates, key vaults, TLS configurations, and custom code. Align your migration roadmap to NIST’s PQC standards (ML-KEM, ML-DSA) and track Microsoft’s published deprecation timelines to avoid a last-minute scramble before 2029. ...

1 July 2024 · ZX Cloud Security

CVE-2026-58013: GLib Buffer Over-Read in Azure

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-58013 is a buffer over-read vulnerability in GLib’s I/O channel handling, specifically within the g_io_channel_read_line_backend function in giochannel.c. A buffer over-read occurs when a programme reads beyond the intended memory boundary, potentially exposing sensitive data from adjacent memory. This vulnerability is relevant to Azure environments where GLib is used as a dependency in Linux-based workloads or services. Security Architect’s Take: Identify any Azure-hosted Linux workloads, containers, or services that depend on GLib and prioritise patching to the remediated version once available. Review your software composition analysis (SCA) tooling to ensure GLib is tracked as a dependency across your estate. ...

1 July 2024 · ZX Cloud Security

CVE-2026-58011: GLib Out-of-Bounds Read in Azure

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-58011 is an out-of-bounds read vulnerability in GLib, a core open-source utility library widely used across Linux-based systems and cloud workloads. The flaw exists in the date/time parsing code and can be triggered by supplying an invalid GDateTime object, potentially allowing an attacker to read memory beyond its intended boundaries. While Microsoft has published this advisory via the MSRC, the impact extends to any Azure or Linux-based environment relying on GLib. ...

1 July 2024 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options