CVE-2026-46140 Linux Bluetooth btmtk Kernel Flaw

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-46140 is a vulnerability in the Linux kernel’s Bluetooth subsystem, specifically in the btmtk driver, where WMT event socket buffer (SKB) lengths are not validated before accessing internal data structures. This could allow an attacker to trigger out-of-bounds memory access, potentially leading to information disclosure or system instability. The issue is relevant to Azure environments running Linux-based virtual machines or container workloads that expose Bluetooth functionality. ...

25 June 2024 · ZX Cloud Security

Restrict AWS Console Access with Sign-In RCPs

🟡 Medium | Source: AWS Security Blog AWS has introduced support for resource-based policies and resource control policies (RCPs) on AWS Sign-In, allowing organisations to restrict who can access the AWS Management Console and CLI based on network origin. This means administrators can limit sign-in attempts to known corporate networks, on-premises data centres, or specific VPCs. It is a significant preventive control against unauthorised console access from unexpected or untrusted locations. ...

24 June 2024 · ZX Cloud Security

Microsoft AI Links StealC & Amadey in Racketeering Suit

🟡 Medium | Source: The Register — Security Microsoft has used AI-assisted analysis to connect two separate malware operations — StealC and Amadey — and has taken legal action under racketeering laws, resulting in the takedown of over 200 command-and-control servers. The AI tooling allowed investigators to identify infrastructure overlaps that would have been difficult to establish manually. This marks a notable use of AI in active threat disruption and legal attribution. ...

24 June 2024 · ZX Cloud Security

Met Police Live Facial Recognition Hits London West End

🟡 Medium | Source: The Register — Security The Metropolitan Police has deployed live facial recognition cameras in London’s West End, expanding biometric surveillance of the general public in one of the UK’s busiest commercial and entertainment districts. Critics, including civil liberties groups, argue that continuous biometric monitoring of public spaces is fundamentally incompatible with the British principle of policing by consent. The deployment raises significant questions around data retention, algorithmic bias, legal basis under UK GDPR and the Police Act, and the erosion of anonymity in public life. ...

24 June 2024 · ZX Cloud Security

Malware Uses Forbidden Text to Fool AI Security Tools

🟡 Medium | Source: Schneier on Security Malware developers are embedding text about nuclear and biological weapons inside JavaScript comment blocks to confuse AI-powered security analysis tools. Because the text sits in a comment, it has no effect on code execution but can cause AI scanners and analyst copilots to refuse processing, misclassify the file, or halt analysis before reaching the actual malicious payload. This represents a deliberate adversarial technique targeting weaknesses in AI-augmented security pipelines rather than traditional antivirus signatures. ...

24 June 2024 · ZX Cloud Security

CVE-2026-46285 Linux Kernel Use-After-Free in Azure

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-46285 is a use-after-free vulnerability in the Linux kernel’s MTD (Memory Technology Device) subsystem, specifically in the docg3 driver’s release function. Use-after-free flaws occur when memory is accessed after it has been freed, which can potentially be exploited to execute arbitrary code or escalate privileges. This vulnerability appears in the Linux kernel underlying Azure infrastructure, making it relevant to cloud environments running Linux-based workloads. ...

24 June 2024 · ZX Cloud Security

DoJ Seizes Huione Cloud Account in Scam Laundering Case

🟡 Medium | Source: The Hacker News The US Department of Justice has seized a cloud computing account used by subsidiaries of HuiOne Group, a Cambodian conglomerate, to launder proceeds from cyber scams. Simultaneously, the US Treasury imposed fresh sanctions on nine individuals and 26 entities linked to the Prince Group. HuiOne has been previously identified as a key financial infrastructure provider for Southeast Asian cyber fraud operations, including pig butchering scams. ...

24 June 2024 · ZX Cloud Security

US Federal Post-Quantum Crypto Deadline Set for 2030

🟡 Medium | Source: The Hacker News President Trump has signed Executive Order 14409, mandating that US federal agencies migrate high-value systems to post-quantum cryptography by 31 December 2030, with digital signatures following by end of 2031. The order responds to the ‘harvest now, decrypt later’ threat, where adversaries collect encrypted data today intending to decrypt it once sufficiently capable quantum computers exist. National security systems are handled under a separate track. ...

23 June 2024 · ZX Cloud Security

OpenAI GPT-5.5-Cyber: AI-Powered Vulnerability Patching

🟡 Medium | Source: The Hacker News OpenAI has released an enhanced version of its GPT-5.5-Cyber model to vetted security defenders through its Daybreak programme, positioning it as its most capable model for identifying and remediating software vulnerabilities. The model is designed to perform sustained, deep analysis across large codebases, making it potentially useful for vulnerability discovery at scale. This matters because AI-assisted vulnerability research is rapidly shifting the economics of both offensive and defensive security work. ...

23 June 2024 · ZX Cloud Security

Open Source CLI Detects Stale AI Dependency Advice

🟡 Medium | Source: The Register — Security A new open source CLI tool has been released to help developers and security teams identify outdated or stale AI-generated advice embedded in code, particularly around dependency overrides that may introduce vulnerabilities. Package dependency configurations are a common attack surface, and AI coding assistants can perpetuate insecure patterns if their recommendations are not validated against current security guidance. This tool aims to surface those risks before they reach production. ...

23 June 2024 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options