INTERPOL Dismantles Sniper Dz Phishing Platform

🟡 Medium | Source: The Hacker News INTERPOL’s Operation Ramz has dismantled Sniper Dz, a long-running phishing-as-a-service platform that enabled criminals to launch phishing campaigns with minimal technical skill. The operation, involving 13 MENA countries, resulted in 201 arrests including the platform’s primary administrator. The takedown removes a significant commodity threat infrastructure that lowered the barrier to entry for phishing attacks globally. Security Architect’s Take: Use this takedown as a prompt to audit your organisation’s anti-phishing controls — review email gateway rules, MFA enforcement, and credential monitoring to ensure residual Sniper Dz-generated phishing infrastructure (domains, kits, harvested credentials) no longer poses a risk to your environment. ...

12 June 2024 Â· ZX Cloud Security

Europol Dismantles AudiA6 Crypto Laundering Service

🟡 Medium | Source: The Hacker News Europol has taken down AudiA6, a cryptocurrency laundering service estimated to have processed over €336 million in illicit funds on behalf of ransomware gangs and cybercriminal networks. The service acted as a key financial layer enabling criminal groups to convert and clean proceeds from attacks. Its disruption removes a significant cash-out mechanism relied upon by multiple threat actors. Security Architect’s Take: Use this as a prompt to review your organisation’s crypto-related transaction monitoring and threat intelligence feeds — if your environment handles or processes cryptocurrency payments, ensure controls are in place to detect anomalous wallet activity. More broadly, cross-reference your ransomware incident response playbooks to confirm you have guidance on evidence preservation for financial forensics should a payment demand arise. ...

12 June 2024 Â· ZX Cloud Security

Word worm crawls into Copilot, spreads chaos

⚪ None | Source: The Register — Security Researcher says months of coordination with Microsoft have yet to produce a robust mitigation Original advisory: Word worm crawls into Copilot, spreads chaos

29 July 2023 Â· ZX Cloud Security

73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack

⚪ None | Source: The Hacker News Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The State of Incident Response Readiness 2026, based on a survey of 600 senior IT security decision makers conducted by Vanson Bourne in January Original advisory: 73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack

29 July 2023 Â· ZX Cloud Security

AI-found bugs aren't proving any easier to exploit despite the hype

⚪ None | Source: The Register — Security VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage Original advisory: AI-found bugs aren’t proving any easier to exploit despite the hype

28 July 2023 Â· ZX Cloud Security

OpenAI Codex Chains HTTP/2 DoS Attacks Autonomously

🟠 High | Source: The Register — Security OpenAI’s Codex AI agent independently discovered and chained together multiple decade-old HTTP/2 denial-of-service techniques to bring down web servers within seconds, creating what researchers are calling an HTTP/2 bomb. This demonstrates that AI coding agents can autonomously rediscover and combine legacy attack methods into novel, highly effective exploits without human guidance. The incident raises significant concerns about the offensive security capabilities of large language model-based agents operating with minimal oversight. ...

4 June 2026 Â· ZX Cloud Security

Amazon Cognito Multi-Region Replication | AWS

🟢 Low | Source: AWS What’s New Amazon Cognito now supports multi-Region replication, allowing user pool data — including credentials, configurations, and federation settings — to be synchronised to a standby Region in near real-time. This improves authentication resilience by enabling traffic failover during a regional outage without forcing users to re-authenticate. The feature is available as a paid add-on across most major AWS Regions. Architect’s Take: Review your existing Cognito-based authentication architectures for single-Region dependencies and assess whether the Essentials or Plus tier add-on cost is justified by your RTO/RPO requirements. Ensure your incident response runbooks are updated to include Cognito traffic redirection procedures, and validate that federated identity providers (SAML/OIDC) are accessible from the secondary Region before declaring it ready for failover. ...

4 June 2026 Â· ZX Cloud Security

Cisco Unified CM CVE-2026-20230: SSRF to Root PoC

🔴 Critical | Source: The Hacker News Cisco has patched a server-side request forgery (SSRF) vulnerability in Unified Communications Manager (Unified CM) that allows an unauthenticated network attacker to write arbitrary files to the system and escalate privileges to root. The flaw is tracked as CVE-2026-20230 and public proof-of-concept exploit code is already available, significantly lowering the barrier to exploitation. Cisco’s PSIRT has not confirmed active exploitation in the wild, but the availability of working PoC code makes patching urgent. ...

4 June 2026 Â· ZX Cloud Security

AWS Cognito New Lambda Trigger for Federated Sign-In

🟢 Low | Source: AWS Security Blog AWS has introduced a new Lambda trigger for Amazon Cognito that allows developers to customise the federated sign-in process when users authenticate via external identity providers such as SAML, OIDC, or social logins. This enables teams to intercept and modify authentication flows at key points, such as attribute mapping or access decisions, without altering core Cognito configuration. The feature improves flexibility for organisations with complex identity federation requirements. ...

4 June 2026 Â· ZX Cloud Security

Claude Code GitHub Action Flaw Enabled Repo Hijack

🔴 Critical | Source: The Hacker News A flaw in Anthropic’s Claude Code GitHub Action allowed an attacker to hijack public repositories simply by opening a malicious GitHub issue, requiring no authentication or special access. Because Anthropic’s own repository used the same vulnerable workflow, a successful attack could have injected malicious code into the action itself, poisoning every downstream project that consumes it. Researcher RyotaK of GMO discovered and reported the issue. ...

4 June 2026 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options