AWS Egress Controls to Prevent Data Exfiltration

🟡 Medium | Source: AWS Security Blog AWS has published guidance on preventing data exfiltration by implementing egress controls across cloud workloads. Outbound traffic is frequently overlooked in cloud security postures, leaving organisations exposed to data theft via compromised workloads or misconfigured services. The article covers practical AWS-native controls to restrict and monitor what leaves your environment. Security Architect’s Take: Audit your current outbound traffic posture now — apply VPC endpoint policies, restrict S3 bucket access using Service Control Policies (SCPs), and deploy AWS Network Firewall or a third-party egress filtering solution to detect and block unauthorised data flows before an incident occurs. ...

22 June 2024 · ZX Cloud Security

London Hydro Data Breach: Customer Data Exposed

🟡 Medium | Source: The Register — Security London Hydro, a Canadian electricity utility, has disclosed a data breach in which customer names, addresses, and account details may have been exposed. The utility has been vague about the nature and scope of the intrusion, leaving significant questions unanswered. The incident highlights ongoing risks to operational technology and utility sector organisations holding sensitive customer data. Security Architect’s Take: Review data classification and access controls for customer PII held in cloud or hybrid environments, and ensure breach notification runbooks include requirements to capture and disclose key technical indicators — vague disclosures often signal immature incident response. Consider whether your third-party utility or OT suppliers have adequate security controls and contractual obligations around breach reporting. ...

22 June 2024 · ZX Cloud Security

Google Android Developer Verification Deadline Sept 2026

🟡 Medium | Source: The Hacker News Google will begin blocking unverified Android app installs on certified devices in Brazil, Indonesia, Singapore, and Thailand from 30 September 2026. Developers who have not completed identity registration with Google will find their apps cannot be installed through normal channels on these devices. This is a significant supply chain and app distribution security measure aimed at reducing malicious or fraudulent apps reaching end users. ...

22 June 2024 · ZX Cloud Security

Wearables & Athlete Privacy: Biometric Data Risks

🟡 Medium | Source: Schneier on Security Professional athletes wearing biometric tracking devices face significant privacy risks, as coaches and organisations may have access to intimate health data — including sleep patterns and heart rate — that could unfairly influence employment decisions. This mirrors broader concerns about wearable data privacy but with heightened stakes given the commercial and contractual pressures of professional sport. The discussion highlights a gap in consent frameworks and data governance around employer-accessed biometric data. ...

22 June 2024 · ZX Cloud Security

Weekly Security Recap: EDR Killers, Android Trojans & More

🟡 Medium | Source: The Hacker News This weekly threat roundup covers a range of active attack techniques including browser vulnerabilities, tools designed to disable endpoint detection and response (EDR) software, a botnet targeting smart TVs, an OpenBSD security flaw, and Android trojan malware. Many of these threats exploit familiar weaknesses — weak credentials, malicious downloads, overprivileged browser extensions, and vulnerable WordPress installations. The breadth of this week’s threats highlights that attackers continue to have success with well-understood tactics that organisations have yet to fully mitigate. ...

22 June 2024 · ZX Cloud Security

CSIS Botnet Warrant: Canada's First Active Cyber Defence Op

🟡 Medium | Source: The Hacker News Canada’s intelligence agency, CSIS, obtained a court warrant to remotely access and disinfect devices on Canadian soil that had been conscripted into two foreign-operated botnets. This marks the first use of CSIS’s threat reduction warrant powers to actively intervene in compromised infrastructure, including home routers and IoT devices. The ruling sets a significant legal precedent for state-sanctioned defensive cyber operations. Security Architect’s Take: Review your organisation’s exposure to botnet recruitment vectors — particularly internet-facing IoT devices, edge routers, and unpatched servers. Ensure your asset inventory covers all externally reachable infrastructure, and validate that endpoint detection or network anomaly controls would identify command-and-control (C2) traffic before a third party does. ...

22 June 2024 · ZX Cloud Security

AryStinger Malware Hijacks 4,300 Routers as Proxy Network

🟡 Medium | Source: The Hacker News A new malware called AryStinger has compromised at least 4,300 legacy home routers, repurposing them as a distributed proxy and reconnaissance network rather than a traditional DDoS botnet. The infected devices are used to conduct pre-attack intelligence gathering, helping threat actors blend malicious traffic into legitimate residential IP ranges. The infection count is reportedly still growing, making this an active and evolving threat. Security Architect’s Take: Audit your organisation’s egress filtering and threat intelligence feeds to flag or block traffic originating from known residential and SOHO router IP ranges commonly associated with proxy abuse. Additionally, ensure any remote access or perimeter services log and alert on unusual source IP diversity, which may indicate reconnaissance traffic routed through compromised devices like these. ...

22 June 2024 · ZX Cloud Security

INTERPOL: Phishing & Ransomware Surge Across APAC

🟡 Medium | Source: The Hacker News INTERPOL’s 2025/2026 Asia and South Pacific Cyberthreat Assessment Report highlights a dramatic rise in phishing, ransomware, and AI-assisted scams across the region, driven by rapid digitalisation and uneven cybersecurity maturity. Organised criminal networks are exploiting gaps in defences as internet penetration accelerates. The report signals that threat actors are increasingly targeting organisations across APAC with sophisticated, technology-enabled attacks. Security Architect’s Take: Review phishing-resistant authentication controls (e.g. FIDO2/passkeys) across cloud environments with APAC user bases, and ensure anti-phishing policies, email security gateways, and ransomware-resilient backup strategies are current and tested. Pay particular attention to third-party and supply chain exposure in regions with lower cybersecurity maturity. ...

22 June 2024 · ZX Cloud Security

CVE-2025-5791: Azure Root User Group Listing Flaw

🟡 Medium | Source: Microsoft Security Response Center CVE-2025-5791 is a vulnerability in Azure where the ‘root’ user is incorrectly appended to group listings, potentially exposing unintended group membership information. This could allow an attacker or unprivileged user to enumerate group memberships they should not be aware of, aiding reconnaissance. While the direct impact may appear limited, information disclosure in identity and access contexts can facilitate privilege escalation attempts. Security Architect’s Take: Review your Azure environments for any reliance on group membership confidentiality as a security control, and monitor for unusual group enumeration activity. Apply any available patches or mitigations from Microsoft promptly, and audit who can query group listings within your tenants. ...

20 June 2024 · ZX Cloud Security

CVE-2026-44821: Microsoft Office for Mac Info Disclosure

🟡 Medium | Source: Microsoft Security Response Center A security vulnerability (CVE-2026-44821) in Microsoft Office for Mac could allow an attacker to disclose sensitive information from affected systems. Microsoft has released a security update specifically for Mac users running affected versions of Office. Users on other platforms are not affected and do not need to take action. Security Architect’s Take: Ensure any managed Mac endpoints running Microsoft Office are patched promptly via your MDM solution (e.g. Intune or Jamf); validate compliance reporting to confirm affected versions are no longer present in your estate. ...

19 June 2024 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options