Ill Bloom Wallet Flaw Exploited: $5M Drained

🔴 Critical | Source: The Hacker News A vulnerability dubbed ‘Ill Bloom’, disclosed by security firm Coinspect, allows attackers to predict cryptocurrency wallet recovery phrases due to weak randomness in how some wallet software generates them. With knowledge of the recovery phrase, an attacker gains full control of the associated wallet and can drain all funds. Exploits are already active, with a confirmed coordinated attack on 27 May resulting in losses exceeding $5 million. ...

10 July 2026 · ZX Cloud Security

CVE-2026-48939: iCagenda File Upload RCE Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in the iCagenda Joomla extension allows attackers to upload arbitrary files — including PHP scripts — via the file attachment feature, enabling remote code execution on the hosting server. This flaw has been confirmed as actively exploited and added to CISA’s Known Exploited Vulnerabilities catalogue, with a remediation deadline of 13 July 2026. Any site running iCagenda is at risk of full server compromise if left unpatched. ...

10 July 2026 · ZX Cloud Security

CVE-2026-56291: Balbooa Forms RCE via File Upload

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in Balbooa Forms allows unauthenticated attackers to upload executable files to affected servers, leading to full remote code execution (RCE). The flaw requires no login or privileges to exploit, making it trivially accessible to any attacker who can reach the application. It has been added to CISA’s Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. Security Architect’s Take: Identify any internet-facing deployments of Balbooa Forms within your environment or those of managed tenants and apply vendor patches immediately — the CISA remediation deadline is 13 July 2026. If patching cannot be completed promptly, restrict public access to the forms endpoint via WAF rules or network controls and implement file upload scanning to block executable content. ...

10 July 2026 · ZX Cloud Security

Ubiquiti UniFi Critical Flaws: CVE-2026-50746 Patched

🔴 Critical | Source: The Hacker News Ubiquiti has released patches addressing multiple critical vulnerabilities across its UniFi product suite, including Connect, Talk, Access, Protect, and OS. The most severe flaw, CVE-2026-50746, carries a perfect CVSS score of 10.0 and involves improper access control in UniFi Connect. Successful exploitation could allow attackers to escalate privileges or execute arbitrary commands on affected devices. Security Architect’s Take: Prioritise immediate patching of all UniFi devices across your estate — a CVSS 10.0 with privilege escalation and command execution potential means these are effectively pre-auth or low-barrier takeover risks. Audit your network segmentation to ensure UniFi management interfaces are not exposed to untrusted networks or the public internet whilst patching is in progress. ...

8 July 2026 · ZX Cloud Security

GhostLock CVE-2026-43499: Linux Root & Container Escape

🔴 Critical | Source: The Hacker News A 15-year-old Linux kernel vulnerability, dubbed GhostLock (CVE-2026-43499), allows any locally authenticated user to gain full root privileges and escape container boundaries without requiring special permissions or unusual configurations. The flaw has been present by default in virtually every mainstream Linux distribution since 2011, making the potential attack surface enormous. Because no network access is needed, the risk is particularly acute in multi-tenant environments such as shared cloud instances and Kubernetes nodes. ...

8 July 2026 · ZX Cloud Security

CISA KEV: Adobe ColdFusion, Joomla & Langflow Flaws

🔴 Critical | Source: The Hacker News CISA has added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalogue, affecting Adobe ColdFusion, Joomla, and Langflow. One flaw in Adobe ColdFusion carries a maximum CVSS score of 10.0 and enables arbitrary code execution via path traversal. Active exploitation means threat actors are already leveraging these weaknesses against real targets, making prompt patching urgent. Security Architect’s Take: Audit your environment immediately for exposed instances of Adobe ColdFusion, Joomla CMS, and Langflow — particularly any internet-facing deployments hosted on cloud infrastructure — and apply available patches or mitigations before CISA’s KEV remediation deadline. If patching cannot be completed immediately, consider placing these services behind a WAF or restricting network access as a temporary control. ...

8 July 2026 · ZX Cloud Security

CVE-2026-14904: AWS RES Symlink File Read Flaw

🔴 Critical | Source: AWS Security Bulletins A path traversal vulnerability (CVE-2026-14904) in AWS Research and Engineering Studio (RES) allows any authenticated user to read arbitrary files on the cluster-manager EC2 instance by replacing their SSH private key with a symbolic link. Because the cluster-manager process runs as root, attackers can access highly sensitive files including other users’ SSH private keys and application secrets. All RES versions up to and including 2026.03 are affected. ...

7 July 2026 · ZX Cloud Security

Writer AI Session Token Leak: Cross-Tenant Flaw

🔴 Critical | Source: The Hacker News A critical vulnerability in Writer, an enterprise AI platform, allowed attackers to leak session tokens across different customer tenants simply by tricking a user into clicking a malicious link. Dubbed ‘WriteOut’ by Sand Security Research, the flaw meant a complete outsider could gain full access to any Writer tenant without prior credentials. The vulnerability has since been patched by Writer. Security Architect’s Take: If your organisation uses Writer, confirm with your vendor that the patch has been applied to your tenant and review recent session and access logs for any anomalous cross-tenant activity. More broadly, this is a prompt reminder to assess any enterprise AI platforms in your stack for session isolation controls and enforce short-lived, scoped session tokens wherever possible. ...

7 July 2026 · ZX Cloud Security

CVE-2026-10536: Azure HTTP/2 UAF Vulnerability

🔴 Critical | Source: Microsoft Security Response Center CVE-2026-10536 is a Use-After-Free (UAF) vulnerability in the HTTP/2 stream-dependency tree handling, affecting Azure services. UAF flaws occur when a programme continues to use memory after it has been freed, which can allow an attacker to execute arbitrary code or cause a service crash. This vulnerability is particularly concerning given how broadly HTTP/2 is used across cloud-native workloads and APIs. Security Architect’s Take: Review any Azure services and self-managed workloads that expose HTTP/2 endpoints, and apply Microsoft’s patches immediately — UAF vulnerabilities with network-reachable attack surfaces can be exploited remotely and should be treated as urgent. Consider temporarily enforcing HTTP/1.1 on critical API gateways or load balancers as a short-term mitigation if patching cannot be completed immediately. ...

7 July 2026 · ZX Cloud Security

Tenda Router Backdoor CVE-2026-11405: CERT/CC Warning

🔴 Critical | Source: The Hacker News Multiple Tenda router firmware versions contain a hidden backdoor (CVE-2026-11405) that allows an attacker to bypass password authentication and gain full administrative access to the device’s web management interface. The backdoor is undocumented, meaning it was not disclosed by the manufacturer, raising concerns about intentional insertion. This poses a significant risk to any network where Tenda devices are deployed, particularly in environments where router management interfaces are internet-facing. ...

7 July 2026 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options