152 Adware Chrome Extensions Found with 105K Installs

🟡 Medium | Source: The Hacker News Researchers have identified 152 Chrome extensions posing as wallpaper and new tab add-ons that are secretly distributing adware and generating fake web traffic. Spread across 38 publisher accounts and tied to three backend domains, the extensions have accumulated over 105,000 installs from the Chrome Web Store. The campaign highlights ongoing abuse of browser extension ecosystems to deliver unwanted software at scale. Security Architect’s Take: Enforce browser extension allowlisting policies via your endpoint management platform (e.g. Chrome Enterprise or Intune) to block unapproved extensions across your organisation, and audit existing installs against the known malicious publisher accounts and domains: tabplugins[.]com, yowgames[.]com, and chromewallpaper[.]com. ...

15 June 2024 · ZX Cloud Security

FCC Proposes to Ban Burner Phones via ID Rules

🟡 Medium | Source: Schneier on Security The FCC is proposing rules that would require US telecoms to collect and store government-issued ID numbers and physical addresses for all phone customers, effectively eliminating anonymous prepaid ‘burner’ phones. The stated aim is to combat scammers and fraud, but privacy advocates warn this mirrors identity-linked mobile registration practices seen in authoritarian regimes. The knock-on effects for cybersecurity operations, whistleblowing, and personal privacy could be significant. ...

15 June 2024 · ZX Cloud Security

Sniper Dz Phishing Scams Target MENA Users on Facebook

🟡 Medium | Source: The Hacker News The Sniper Dz phishing-as-a-service operation is targeting users across the Middle East and North Africa (MENA) region using fake Facebook accounts impersonating politicians, public figures, and government organisations to promote fraudulent offers such as free mobile data and financial subsidies. Victims are lured via social engineering on social media and browser-based alerts, ultimately leading to credential theft or malware delivery. The campaign is notable for its scale, regional targeting, and abuse of trusted brand identities to lower victims’ defences. ...

15 June 2024 · ZX Cloud Security

AI Security Limits: Prompting Can't Fix Bad AI Judgement

🟡 Medium | Source: The Register — Security This piece explores the fundamental limitation that AI models are deterministic software systems — they cannot reason beyond their training and architecture simply because a user asks them to. Despite clever prompting tricks, AI tools consistently accept flawed or misleading inputs, which has direct implications for any security tooling or code review processes that rely on AI judgement. For cloud security teams integrating AI into pipelines, this is a timely reminder that AI outputs require human validation. ...

14 June 2024 · ZX Cloud Security

CVE-2023-5678 OpenSSL DH DoS Flaw Affects Azure

🟡 Medium | Source: Microsoft Security Response Center CVE-2023-5678 is a vulnerability in OpenSSL where processing a Diffie-Hellman (DH) key or parameter with an excessively large Q value can cause the application to hang, consuming significant CPU time. This creates a denial-of-service risk for any service that processes externally supplied DH parameters. Microsoft has published guidance via the MSRC as it affects components within the Azure ecosystem. Security Architect’s Take: Review any Azure services or workloads using OpenSSL for TLS/cryptographic operations and ensure OpenSSL is patched to a version addressing CVE-2023-5678. Pay particular attention to services that accept client-supplied DH parameters, and consider disabling legacy DH cipher suites where not required. ...

13 June 2024 · ZX Cloud Security

CVE-2026-52859: Vim Out-of-Bounds Read on Azure

🟡 Medium | Source: Microsoft Security Response Center CVE-2026-52859 is an out-of-bounds read vulnerability in Vim, a widely used text editor, specifically within its terminal screen snapshot functionality. This type of flaw can allow an attacker to read memory beyond intended boundaries, potentially exposing sensitive data or aiding further exploitation. While the advisory is published via Microsoft’s Security Response Center under the Azure category, the underlying vulnerability resides in Vim itself, which may be present across Linux-based Azure virtual machines and containerised workloads. ...

13 June 2024 · ZX Cloud Security

NanoClaw + JFrog: Securing AI Agent Package Downloads

🟡 Medium | Source: The Register — Security NanoClaw, an AI agent framework, has integrated JFrog Artifactory registries to enforce safer package downloads for autonomous AI agents. The move addresses growing concern that AI agents operating with broad permissions can inadvertently — or maliciously — pull down tampered or malicious packages from untrusted sources. By routing downloads through a governed, scanned registry, organisations gain a layer of supply chain control over what their AI agents can fetch and execute. ...

12 June 2024 · ZX Cloud Security

Google Sues Chinese Smishing Network Using Gemini AI

🟡 Medium | Source: The Hacker News Google is taking legal action against a Chinese cybercrime network accused of abusing its Gemini AI to craft and send phishing SMS messages targeting US users. The group operates a phishing-as-a-service platform called ‘Outsider’, making sophisticated smishing campaigns accessible to a wider criminal ecosystem. This case highlights the emerging risk of threat actors weaponising legitimate AI services to scale and refine social engineering attacks. ...

12 June 2024 · ZX Cloud Security

Google Sues Chinese Phishing Group Over AI Fraud Ops

🟡 Medium | Source: The Register — Security Google has filed a lawsuit against an alleged Chinese cybercriminal group, dubbed ‘Outsider Enterprise’, accused of running AI-powered phishing and fraud operations via Telegram. The group is alleged to have sent millions of scam texts impersonating trusted brands, exploiting Google’s infrastructure in the process. The case highlights the growing use of AI tooling to scale phishing campaigns and the legal avenues platforms are increasingly pursuing against threat actors. ...

12 June 2024 · ZX Cloud Security

Rethinking MDR in the Age of AI-Powered Attacks

🟡 Medium | Source: The Hacker News The traditional Managed Detection and Response (MDR) model is under pressure as AI enables attackers to operate faster and at greater scale than legacy MDR services were designed to handle. The article argues that the assumptions underpinning MDR — chronic analyst shortages and overnight coverage gaps — are being disrupted by AI-augmented tooling on both sides of the threat landscape. Organisations relying solely on conventional MDR arrangements may find their detection and response capabilities increasingly mismatched against modern attack velocity. ...

12 June 2024 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options