Open Source AI Powers Enterprise Network Worms

🟠 High |Ā Source: The Register — Security Researchers have demonstrated that freely available open source AI models are sufficient to build self-spreading computer worms capable of exploiting known vulnerabilities at scale across enterprise networks — no expensive or specialised AI tools required. The study shows attackers no longer need cutting-edge proprietary models to automate vulnerability exploitation, dramatically lowering the barrier to entry for large-scale attacks. This represents a meaningful shift in the threat landscape, where mass exploitation of known but unpatched vulnerabilities becomes significantly cheaper and faster to operationalise. ...

4 June 2026 Ā· ZX Cloud Security

DoJ Freezes $3.8M in Southeast Asia Crypto Fraud Bust

🟔 Medium |Ā Source: The Hacker News The US Department of Justice ran a coordinated ā€˜Disruption Week’ operation from May 2026 targeting Southeast Asian criminal networks running cryptocurrency and cyber-enabled fraud schemes against American victims. The action involved both government agencies and private sector partners, resulting in the takedown of millions of fraudulent social media, email, and internet accounts, and the freezing of $3.8 million in assets. These operations are typically linked to pig butchering and romance scam networks, which increasingly exploit cloud-hosted infrastructure and social engineering at scale. ...

4 June 2026 Ā· ZX Cloud Security

Passwords in Active Directory Description Fields Risk

🟠 High |Ā Source: The Register — Security Passwords were found stored in plaintext within Active Directory user and computer description fields, making them trivially accessible to any authenticated user on the network. Because AD description fields are readable by all domain users by default, a low-privilege attacker or compromised account could harvest credentials at scale with a simple LDAP query. This represents a significant credential exposure risk in any hybrid or cloud-connected environment where AD is the identity backbone. ...

4 June 2026 Ā· ZX Cloud Security

Rethinking Cloud Resilience Against AI-Driven Attacks

🟠 High |Ā Source: The Register — Security Commvault is urging organisations to fundamentally reassess their cyber resilience strategies as AI-powered attackers increasingly target backup and recovery infrastructure, leaving victims unable to restore operations. The concern is that traditional backup plans are insufficient if they are not regularly tested and hardened against modern threat actors who specifically seek to neutralise recovery capabilities. This matters because the failure point is no longer just data loss — it is the complete inability to recover. ...

3 June 2026 Ā· ZX Cloud Security

Rethinking Cloud Resilience Against AI-Powered Attacks

🟠 High |Ā Source: The Register — Security Commvault is urging organisations to fundamentally rethink their resilience strategies as AI-powered attackers increasingly target backup and recovery infrastructure, leaving victims unable to recover. The warning highlights that traditional backup plans are insufficient if they are not regularly tested under realistic attack conditions. As ransomware operators and AI-assisted threat actors specifically seek out and corrupt backup systems, untested recovery capabilities offer a false sense of security. ...

3 June 2026 Ā· ZX Cloud Security

AWS IoT Device Management MQTT Session Data API

🟢 Low |Ā Source: AWS What’s New AWS IoT Device Management has enhanced its connectivity status API to include detailed MQTT session data, such as session timeout and expiry values, plus optional socket-level details including IP addresses, ports, and VPC endpoint IDs. Unlike the IoT Core GetConnection API, which only retains data for 30 minutes post-disconnect, this API stores connection history indefinitely. This is useful for security auditing, forensic investigation of disconnect events, and monitoring connection patterns across large IoT fleets. ...

3 June 2026 Ā· ZX Cloud Security

AWS IoT Device Management: MQTT Session Data in API

🟢 Low |Ā Source: AWS What’s New AWS IoT Device Management has enhanced its connectivity status API to include detailed MQTT session data, such as session timeout and expiry values, plus optional socket-level details including IP addresses, ports, and VPC endpoint IDs. Unlike the AWS IoT Core GetConnection API, which only retains data for 30 minutes post-disconnect, this API stores connection history indefinitely, improving long-term auditability. Access to sensitive socket-level information is controlled via IAM policies, allowing organisations to limit visibility to authorised teams. ...

3 June 2026 Ā· ZX Cloud Security

Curved Radio Beams Can Defeat Anti-Jamming Systems

🟔 Medium |Ā Source: The Register — Security Researchers at Rice University have demonstrated that curving radio beams can defeat anti-jamming systems by making it difficult to pinpoint the true origin of a jamming signal. Traditional anti-jamming defences rely on locating and neutralising the source of interference, but bent beams confound that localisation process. This has significant implications for secure wireless communications, including satellite links and GPS systems that underpin cloud and critical infrastructure connectivity. ...

3 June 2026 Ā· ZX Cloud Security

AWS Step Functions Adds AI Agent Steps via AgentCore

🟢 Low |Ā Source: AWS What’s New AWS Step Functions now integrates with Amazon Bedrock AgentCore (currently in preview) to allow AI agent reasoning steps — such as document classification and data extraction — to be embedded directly into automated workflows. This enables multiple agents to run in parallel or sequence within a single workflow, with human approval gates and full audit trails via CloudWatch. For security teams, this introduces AI-driven decision-making into business-critical automation pipelines, expanding the attack surface and governance considerations. ...

3 June 2026 Ā· ZX Cloud Security

OpenAI GPT-5.4 on AWS Bedrock GovCloud (US-West)

🟢 Low |Ā Source: AWS What’s New OpenAI’s GPT-5.4 model is now generally available on Amazon Bedrock within AWS GovCloud (US-West), extending access to government and regulated-industry customers. The deployment leverages Bedrock’s isolated inference infrastructure, ensuring prompts and responses remain within the customer’s AWS environment and are not used for model training. This expands the options available for sensitive workloads requiring complex reasoning and document analysis under strict compliance controls. Architect’s Take: Evaluate data residency and access control policies before enabling GPT-5.4 for sensitive workloads — confirm that Bedrock resource policies, VPC endpoints, and CloudTrail logging are configured to meet your organisation’s compliance requirements, particularly if handling OFFICIAL-SENSITIVE or equivalent data in GovCloud. ...

3 June 2026 Ā· ZX Cloud Security

šŸ“¬ Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options