AWS IAM Identity Center: Programmatic Account Access for App

🟡 Medium | Source: AWS What’s New AWS IAM Identity Center now allows customer-managed applications to programmatically access AWS accounts on behalf of users, using tokens from a trusted external identity provider. Applications can discover assigned accounts and roles, and retrieve temporary credentials without requiring users to re-authenticate. This simplifies access flows but introduces new governance considerations around which applications are permitted to obtain AWS account credentials. Security Architect’s Take: Review all existing customer-managed applications integrated with IAM Identity Center and apply the principle of least privilege when deciding which applications to enable for AWS account access. Ensure only management account or delegated administrators can grant this capability, and audit trusted token issuer configurations regularly to prevent credential abuse via compromised third-party IdPs. ...

30 June 2024 · ZX Cloud Security

AI Video Surveillance: What Security Teams Need to Know

🟡 Medium | Source: Schneier on Security AI is fundamentally transforming video surveillance capabilities, enabling natural language queries against video footage rather than relying on a limited set of preset searches. This shift, evidenced by deployments in conflict zones such as Israel/Iran and Russia, means mass surveillance is now far more accessible and powerful than traditional CCTV analytics. The implications for civil liberties, insider threat monitoring, and physical security intelligence are significant. ...

30 June 2024 · ZX Cloud Security

CVE-2026-53325: Azure Linux Kernel AGP AMD64 Bug Fix

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-53325 addresses a broken error propagation bug in the Linux kernel’s AGP AMD64 driver, specifically within the agp_amd64_probe() function. Microsoft has published this advisory in the context of Azure, suggesting it affects Linux-based virtual machines or underlying infrastructure. Improper error handling in kernel code can lead to unpredictable system behaviour, potential privilege escalation, or denial of service if exploited. Security Architect’s Take: Review whether your Azure Linux VMs or AKS node pools are running kernel versions affected by this CVE, and apply available patches promptly. Ensure your VM patching pipeline includes kernel-level updates and monitor Microsoft’s update guide for a confirmed fix version. ...

30 June 2024 · ZX Cloud Security

CVE-2026-41991: GNU gzip Predictable Temp File Flaw

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-41991 is a vulnerability in GNU gzip involving the use of predictable temporary file names, which can be exploited by local attackers to perform symlink attacks or overwrite arbitrary files. This type of flaw can lead to privilege escalation or data corruption, particularly in environments where gzip is invoked by privileged processes. It is relevant to Azure and other cloud environments where gzip is commonly present in Linux-based workloads and container images. ...

30 June 2024 · ZX Cloud Security

Russia Refocuses Influence Ops on US and Europe in 2026

🟡 Medium | Source: The Register — Security Four years after Russia’s invasion of Ukraine, Kremlin-linked influence operations are increasingly targeting audiences in the US and Europe, shifting focus back to Western democracies. These campaigns aim to sow division, undermine support for Ukraine, and erode public trust in institutions. The shift represents a significant escalation in information warfare directed at Western civil society and political infrastructure. Security Architect’s Take: Cloud security architects supporting government, media, or critical national infrastructure clients should review controls around social media integrations, content delivery pipelines, and employee phishing resilience — influence ops increasingly leverage compromised cloud-hosted assets and fake accounts to amplify narratives. Ensure threat intelligence feeds include geopolitical and hybrid threat indicators, not just technical IOCs. ...

29 June 2024 · ZX Cloud Security

AWS CIRT June 2026 Threat Technique Catalog Update

🟡 Medium | Source: AWS Security Blog AWS’s Customer Incident Response Team (CIRT) has released its June 2026 update to the Threat Technique Catalog, documenting recurring attack patterns observed across real-world AWS incident response engagements. The catalog serves as a practical reference for defenders, mapping common adversary techniques to AWS-specific services and controls. Staying current with this catalog helps security teams understand how attackers are actively targeting AWS environments and where detection or prevention gaps may exist. ...

29 June 2024 · ZX Cloud Security

AI vs Human Error: Why Passwords Still Win | Cloud Security

🟡 Medium | Source: The Register — Security Despite rapid advances in AI-powered vulnerability discovery, the most exploited weaknesses remain rooted in poor human behaviour — particularly weak and reused passwords. The article argues that attackers don’t need sophisticated AI tooling when basic credential hygiene continues to fail at scale. This serves as a reminder that technical innovation in offensive security is outpacing the fundamentals of user and organisational hygiene. Security Architect’s Take: Prioritise enforcing phishing-resistant MFA and passwordless authentication across all cloud environments, and audit your identity stores for weak or reused credentials using tools like Have I Been Pwned integrations or cloud-native identity protection services — these remain far more likely attack vectors than AI-assisted zero-days. ...

29 June 2024 · ZX Cloud Security

Post-Quantum Cryptography: Why Credentials Come First

🟡 Medium | Source: The Hacker News Quantum computers, whilst not yet capable of breaking today’s encryption, are advancing rapidly enough that data and credentials captured now could be decrypted in the future — a threat known as ‘harvest now, decrypt later’. Post-quantum cryptography (PQC) standards are emerging to address this, and credentials represent the highest-priority migration target due to their long-term sensitivity. Organisations that delay PQC adoption risk exposing critical authentication material retroactively. ...

29 June 2024 · ZX Cloud Security

CVE-2026-23207: Linux SPI Driver Flaw in Azure

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-23207 is a vulnerability in the Linux kernel’s SPI (Serial Peripheral Interface) driver for NVIDIA Tegra210 hardware, specifically related to an unprotected check in an interrupt request (IRQ) handler. While rooted in a low-level hardware driver, this flaw could be present in Azure infrastructure or VM instances running affected kernel versions. The issue centres on a race condition that may lead to unpredictable behaviour or system instability. ...

28 June 2024 · ZX Cloud Security

CVE-2025-21870: Linux Kernel SOF ALH Copier Flaw

🟡 Medium | Source: Microsoft Security Response Center CVE-2025-21870 is a vulnerability in the Linux kernel’s Audio over HDA (ALH) copier lookup loops within the Sound Open Firmware (SOF) IPC4 topology component. While categorised under Azure advisories via the Microsoft Security Response Center, this is a Linux kernel-level flaw that could affect Azure infrastructure or Linux-based virtual machines running affected kernel versions. The hardening of these loops suggests a potential out-of-bounds access or logic error that could be exploited to cause instability or unexpected behaviour. ...

28 June 2024 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options