CVE-2026-46292: Linux Kernel pmdomain Flaw in Azure

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-46292 is a Linux kernel vulnerability affecting the power management domain (pmdomain) subsystem, specifically a flaw in the detach procedure for virtual devices within the Generic Power Domain (genpd) framework. While published via Microsoft’s Security Response Centre in the context of Azure, this is a kernel-level issue that could affect Linux-based virtual machines and container hosts. Improper handling of virtual device detachment may lead to memory corruption or instability, with potential security implications depending on exploitability. ...

18 June 2024 Â· ZX Cloud Security

CVE-2026-43308: Linux btrfs Kernel Panic Fix – Azure

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-43308 is a Linux kernel vulnerability in the btrfs filesystem driver, where an unexpected delayed reference type could trigger a kernel panic (BUG()). The fix prevents the kernel from crashing in this scenario by handling the unexpected condition gracefully. Although published via Microsoft’s security advisory channel for Azure, the underlying issue affects any Linux system using the btrfs filesystem, including Azure Linux-based virtual machines. ...

18 June 2024 Â· ZX Cloud Security

CVE-2025-71072: Azure Linux Kernel shmem Rename Fix

🟡 Medium | Source: Microsoft Security Response Center CVE-2025-71072 addresses a flaw in the Linux kernel’s shared memory (shmem) subsystem related to improper recovery handling during rename failures. This type of vulnerability can lead to memory corruption or inconsistent filesystem state. While details remain limited, kernel-level memory management bugs can be exploited to cause instability or, in certain conditions, may be leveraged for privilege escalation. Security Architect’s Take: Review whether your Azure Linux-based workloads — including AKS nodes, Linux VMs, and container hosts — are running kernel versions affected by this shmem rename issue, and prioritise patching via Azure Update Manager or your node image upgrade pipeline. ...

18 June 2024 Â· ZX Cloud Security

CVE-2025-71073: Azure Linux Kernel lkkbd Driver Flaw

🟡 Medium | Source: Microsoft Security Response Center CVE-2025-71073 is a Linux kernel vulnerability in the lkkbd (Linux keyboard) driver, where pending work is not properly cancelled before the device is freed, potentially causing a use-after-free condition. Although published via Microsoft’s Security Response Center under the Azure category, this is a kernel-level issue that could affect Linux-based virtual machines or containerised workloads running on Azure. If exploitable, such vulnerabilities can lead to memory corruption, system instability, or privilege escalation. ...

18 June 2024 Â· ZX Cloud Security

CVE-2026-42766: NULL Dereference in CMS Decryption

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-42766 is a potential NULL dereference vulnerability affecting password-based CMS (Cryptographic Message Syntax) decryption, disclosed via Microsoft’s Security Response Centre. A NULL dereference flaw can cause an application or service to crash when processing malformed or malicious encrypted data, potentially leading to denial of service. This matters because CMS is widely used in certificate handling, S/MIME email, and PKI workflows, meaning affected services could be disrupted by a crafted payload. ...

18 June 2024 Â· ZX Cloud Security

US Telco Stored Credit Cards in Plaintext: Lessons

🟡 Medium | Source: The Register — Security A retrospective account has emerged of a major US telecommunications carrier storing customer credit card data in plaintext during the early 2000s, a practice discovered by an employee on their very first day. This highlights how poor data handling hygiene was commonplace before PCI DSS mandated encryption standards, and serves as a reminder of the long-term reputational and regulatory risks of inadequate data protection. While historical, the story resonates today as organisations continue to misconfigure data storage in cloud environments. ...

18 June 2024 Â· ZX Cloud Security

Cybercrime Now a Third of All Crime in Asia-Pacific

🟡 Medium | Source: The Register — Security Interpol’s latest regional review reveals that cyber offences now constitute approximately one third of all recorded crime across Asia and the Pacific. Scam-based fraud remains the dominant threat vector, while AI-enabled attack capabilities are outpacing the defensive resources available to many cash-strapped nations in the region. The findings highlight a widening gap between attacker sophistication and institutional capacity to respond. Security Architect’s Take: Organisations operating in or with supply chain exposure to the Asia-Pacific region should review third-party risk postures and ensure fraud detection controls — particularly for business email compromise and social engineering — are tuned to regional threat patterns. Consider whether your threat intelligence feeds include APAC-specific indicators, and assess whether AI-assisted phishing simulation is part of your current red team programme. ...

18 June 2024 Â· ZX Cloud Security

Crypto Clipper Malware Abuses GitHub & Fake Reviews

🟡 Medium | Source: The Hacker News A threat actor is running a crypto clipper malware campaign using fake reviews on legitimate news sites, AI-generated YouTube content, and GitHub/SourceForge projects to lend credibility to malicious software. The campaign uses a WordPress phishing hub and VirusTotal comment sections to spread links, targeting users into downloading malware that silently replaces cryptocurrency wallet addresses to redirect funds. This matters because it abuses trusted platforms to evade detection and build false legitimacy. ...

17 June 2024 Â· ZX Cloud Security

Tailscale & OpenSSH Abused for Persistent Backdoor Access

🟡 Medium | Source: The Hacker News A low-skilled, French-speaking attacker compromised a small French automotive firm, deploying a keylogger to steal banking and email credentials. Crucially, before his command-and-control infrastructure went offline, he installed OpenSSH and Tailscale on the victim machine to create a resilient, C2-independent backdoor. This technique demonstrates how legitimate networking tools can be abused to maintain persistent access even after primary attacker infrastructure is taken down. Security Architect’s Take: Audit your environment for unauthorised installations of legitimate remote-access and mesh-networking tools such as Tailscale, ZeroTier, and OpenSSH — these can bypass traditional C2 detection entirely. Implement application allowlisting and egress filtering to prevent unapproved software from establishing outbound tunnels, and alert on new SSH daemon processes or VPN agent installations on endpoints. ...

17 June 2024 Â· ZX Cloud Security

Adversarial Exposure Validation: Prioritise Cloud Risk

🟡 Medium | Source: The Hacker News Security teams are increasingly overwhelmed not by a lack of visibility into potential threats, but by the inability to confidently determine which findings actually matter. Adversarial Exposure Validation (AEV) addresses this by using active, attack-simulation techniques to test whether identified exposures are genuinely exploitable in the real environment. This shifts the focus from alert volume to validated, prioritised risk — helping teams act with greater confidence and less noise. ...

17 June 2024 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options