CVE-2026-45466: Microsoft Word Info Disclosure on Mac

🟡 Medium | Source: Microsoft Security Response Center A security vulnerability in Microsoft Word for Mac (CVE-2026-45466) allows information disclosure, potentially exposing sensitive data from affected documents. Microsoft has released security updates for Microsoft Office for Mac to address the issue. Only users running the affected Mac versions of Office need to act; other platforms are unaffected. Security Architect’s Take: Ensure any managed Mac endpoints running Microsoft Office are updated promptly via your MDM solution or patch management tooling. Verify compliance reporting confirms the patch has been applied across your Mac fleet, particularly for users handling sensitive or confidential documents. ...

19 June 2024 · ZX Cloud Security

CVE-2026-45485: Microsoft Office for Mac Info Disclosure

🟡 Medium | Source: Microsoft Security Response Center A security vulnerability in Microsoft Office for Mac (CVE-2026-45485) allows information disclosure, potentially exposing sensitive data to attackers. Microsoft has released security updates to address the flaw, and only users running the affected Mac version of Office need to act. Users of other Microsoft Office platforms are not affected. Security Architect’s Take: Ensure macOS endpoints running Microsoft Office are patched promptly via your MDM or patch management tooling — verify compliance particularly for devices accessing cloud-hosted data in Microsoft 365 or Azure environments. No action is required for Windows or web-based Office deployments. ...

19 June 2024 · ZX Cloud Security

Anthropic Fable AI Export Ban: Cloud AI Risk

🟡 Medium | Source: Schneier on Security Anthropic released its Fable AI model in June 2026, only for the US government to classify it as a dangerous munition three days later and restrict foreign access via export controls. Unable to verify user nationality, Anthropic shut down access entirely. The incident highlights the growing tension between AI capability development and state-level security regulation. Security Architect’s Take: Review your organisation’s dependency on third-party AI APIs and model providers — this incident demonstrates that access can be revoked with minimal notice due to regulatory action outside the vendor’s control. Consider building contingency plans or multi-provider strategies for any AI services integrated into critical workflows. ...

19 June 2024 · ZX Cloud Security

Home Office AI Age Tool Branded Biased for Asylum-Seekers

🟡 Medium | Source: The Register — Security The UK Home Office is using an AI system to estimate the age of asylum-seekers, but rights groups argue the technology is biased and unreliable — particularly at the critical boundary between child and adult classifications. This matters because misclassification could place vulnerable children into adult detention or processing systems, with serious legal and welfare consequences. The controversy raises broader questions about the deployment of AI in high-stakes government decision-making without sufficient transparency or independent validation. ...

19 June 2024 · ZX Cloud Security

CVE-2026-12087: Perl Socket Heap Read Vulnerability

🟡 Medium | Source: Microsoft Security Response Center A heap out-of-bounds read vulnerability exists in the Perl Socket module before version 2.041, which could allow an attacker to read memory beyond intended boundaries. This type of flaw can lead to information disclosure or, in certain conditions, contribute to further exploitation. Although categorised under Azure, the underlying issue affects the Perl Socket library used across many environments including cloud workloads. Security Architect’s Take: Audit any Azure workloads, containers, or pipelines running Perl and ensure the Socket module is updated to version 2.041 or later. Pay particular attention to serverless functions, Azure Kubernetes Service pods, and CI/CD build environments where Perl may be a transitive dependency. ...

19 June 2024 · ZX Cloud Security

CVE-2026-44967: OpenTelemetry-cpp Unbounded HTTP Response Fl

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-44967 is a vulnerability in the opentelemetry-cpp library affecting its OTLP HTTP exporters, which fail to impose any limit on the size of HTTP responses they read. This means a malicious or compromised server could send an oversized response, potentially causing excessive memory consumption or a denial of service in the consuming application. The issue is particularly relevant to Azure environments where OpenTelemetry is used for observability and telemetry collection. ...

19 June 2024 · ZX Cloud Security

Google Denies Bug Bounty for Unpatched Flaw: What It Means

🟡 Medium | Source: The Register — Security A security researcher discovered a vulnerability in a Google product, received praise from the company, but was denied a bug bounty payment after Google classified the flaw as ‘working as intended.’ The issue reportedly remains unpatched, raising concerns about how Google handles responsible disclosure and researcher compensation. This case highlights ongoing tension between bug bounty programmes and vendors’ willingness to acknowledge and remediate reported flaws. ...

18 June 2024 · ZX Cloud Security

Spyware Uses Forbidden Text to Fool AI Security Scanners

🟡 Medium | Source: Schneier on Security Malware authors are embedding text about nuclear and biological weapons inside JavaScript comment blocks within spyware payloads, with the goal of triggering content refusals or confusion in AI-powered code analysis tools. Because the text sits inside a comment, it has no effect on code execution but can derail automated scanners that feed raw file content to language models without properly sandboxing it. This represents a novel evasion technique that exploits weaknesses in AI-assisted security tooling rather than in traditional detection systems. ...

18 June 2024 · ZX Cloud Security

CVE-2026-46293: Linux Kernel Out-of-Bounds Flaw on Azure

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-46293 is a Linux kernel vulnerability affecting the Microchip PolarFire SoC clock controller driver, specifically an out-of-bounds memory access that can occur during clock output registration. Although rooted in low-level kernel code, its presence in the Linux kernel means it could affect Azure infrastructure or Linux-based virtual machines and containers running on Azure. Out-of-bounds access flaws can potentially be exploited to cause system instability or, in more serious scenarios, enable privilege escalation. ...

18 June 2024 · ZX Cloud Security

CVE-2026-46291: Linux CAAM HMAC Key Leak on Azure

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-46291 is a vulnerability in the Linux kernel’s CAAM (Cryptographic Acceleration and Assurance Module) driver, specifically affecting how HMAC key material is handled during hash digest key operations. The flaw can expose sensitive cryptographic key data through unguarded hex dumps, potentially leaking HMAC secrets into kernel logs or debug output. This matters because HMAC keys exposed in this way could undermine the integrity and authenticity guarantees of cryptographic operations running on affected systems, including those hosted in Azure environments using Linux-based virtual machines. ...

18 June 2024 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options