CVE-2026-20253: Critical Splunk RCE Flaw

🔴 Critical | Source: The Hacker News A critical vulnerability (CVE-2026-20253, CVSS 9.8) in Splunk Enterprise allows unauthenticated attackers to perform arbitrary file operations and execute remote code. Affected versions are Splunk Enterprise below 10.2.4 and 10.0.7. The lack of any authentication requirement makes this particularly dangerous, as exploitation requires no foothold within the target environment. Security Architect’s Take: Patch Splunk Enterprise to version 10.2.4 or 10.0.7 immediately. Until patching is complete, restrict network access to Splunk management interfaces and ingestion endpoints using firewall rules or security group policies to limit exposure to trusted IP ranges only. ...

13 June 2026 Â· ZX Cloud Security

CVE-2026-12043: AWS SDK HTTP/2 RCE Vulnerability

🔴 Critical | Source: AWS Security Bulletins A heap double-free vulnerability (CVE-2026-12043) has been identified in the AWS Common Runtime HTTP client library, affecting a wide range of AWS SDK versions for C++ and Java v2. A malicious server could exploit this by sending crafted HTTP/2 HEADERS frames to trigger memory corruption on a connecting client, potentially achieving arbitrary code execution. The vulnerability affects aws-c-http versions 0.4.22 through 0.10.15 and is exposed in widely used SDK releases. ...

12 June 2026 Â· ZX Cloud Security

Velvet Ant Backdoors Linux PAM & OpenSSH for 10 Years

🔴 Critical | Source: The Hacker News A China-linked threat actor tracked as Velvet Ant spent nearly a decade maintaining persistent access to a targeted network by backdooring PAM (Pluggable Authentication Modules) and OpenSSH — the core Linux components that control who can log in. By compromising the authentication layer itself rather than higher-visibility applications, the group was able to survive routine security clean-up efforts. This matters because the same Linux authentication stack underpins the vast majority of cloud workloads, container hosts, and on-premises infrastructure. ...

12 June 2026 Â· ZX Cloud Security

LangGraph RCE Flaw Chain: SQL Injection Risk for AI Agents

🔴 Critical | Source: The Hacker News Three now-patched security vulnerabilities have been disclosed in LangGraph, an open-source framework used to build multi-agent AI applications. The most serious is a critical chain involving SQL injection that can lead to remote code execution on self-hosted deployments. Organisations running LangGraph on their own infrastructure are at risk if they have not yet applied the available patches. Security Architect’s Take: Audit all self-hosted LangGraph deployments and apply the latest patches immediately. Additionally, enforce network-level controls to restrict access to LangGraph API endpoints, and review whether untrusted input can reach any SQL-handling functions within your AI agent pipelines. ...

12 June 2026 Â· ZX Cloud Security

CVE-2026-35273: Oracle PeopleSoft Auth Bypass Flaw

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows an unauthenticated attacker to take full control of the system due to a missing authentication check on a critical function. This flaw requires no credentials to exploit, making it particularly dangerous for any internet-facing or internally accessible PeopleSoft deployment. CISA has added it to its Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild. ...

12 June 2026 Â· ZX Cloud Security

Loongson CPU Cache Flaw Leaks Data from Guest VMs

🟠 High | Source: The Register — Security Researchers have discovered cache side-channel vulnerabilities in Chinese-made Loongson processors that allow attackers to extract sensitive data from memory. Critically, the attack can be executed from within a guest virtual machine, meaning cloud or virtualised environments running on Loongson hardware could be at risk. This class of vulnerability is particularly serious as it bypasses traditional isolation boundaries between workloads. Security Architect’s Take: If your organisation operates or procures infrastructure — particularly in Asia-Pacific supply chains or sovereign cloud environments — that may include Loongson-based hardware, audit your vendor hardware inventory immediately and assess whether workload isolation controls are sufficient pending a microcode or firmware patch from the vendor. ...

13 August 2025 Â· ZX Cloud Security

AI Agent Cyberattack on Taiwan Nuclear Safety Agency

🟠 High | Source: The Register — Security A sophisticated cyberattack using near-autonomous AI agents targeted Taiwan’s nuclear safety agency, marking a significant escalation in the use of agentic AI for state-level offensive operations. The attack demonstrates that AI-driven threat actors can now orchestrate complex, multi-step intrusions with minimal human oversight. This is a watershed moment for critical national infrastructure security, signalling that AI-assisted attacks are no longer theoretical. Security Architect’s Take: Review your detection and response capabilities for high-velocity, multi-vector attacks that may outpace traditional SIEM correlation rules — agentic AI attackers can iterate faster than human red teams. Prioritise behavioural anomaly detection and automated containment playbooks for critical infrastructure workloads, particularly where cloud-hosted systems interface with OT or safety-critical environments. ...

12 August 2025 Â· ZX Cloud Security

AWS SDK for C++ Base64 Flaws: CVE-2026-19642 & 19643

🟠 High | Source: AWS Security Bulletins Two memory-safety vulnerabilities have been identified in the Base64 decoder within the AWS SDK for C++, affecting all versions up to and including 1.11.861. CVE-2026-19642 allows certain inputs to trigger an out-of-bounds heap write, which could crash or corrupt the application’s memory, whilst CVE-2026-19643 may cause an out-of-bounds read on some platforms, potentially crashing the process. Although remote code execution has not been demonstrated, the potential for memory corruption makes these issues significant for any application using the affected SDK. ...

12 August 2025 Â· ZX Cloud Security

CVE-2026-19311: OpenSearch Alerting Plugin Auth Flaw

🟠 High | Source: AWS Security Bulletins A missing authorisation flaw (CVE-2026-19311) in the OpenSearch Alerting plugin’s Execute Monitor API allows any authenticated user holding the alerting_full_access role to read, modify, or delete arbitrary index data by crafting a malicious inline monitor request. The issue affects self-managed OpenSearch versions 2.4.0–2.19.5 and 3.0.0–3.7.0, as well as Amazon OpenSearch Service domains running engine versions 2.4 through 3.5. Fixes are available in open-source releases 2.19.6 and 3.8.0, and in AWS managed service software R20260428-P3. ...

12 August 2025 Â· ZX Cloud Security

Uber Freight Breached: Helix Claims 1M Files Stolen

🟠 High | Source: The Register — Security A threat actor known as Helix has claimed responsibility for breaching Uber Freight, alleging the theft of nearly one million files. Uber Freight states that logistics operations were not disrupted, though the extortion claim suggests sensitive data may be at risk. This incident highlights the growing targeting of logistics and supply chain platforms by extortion-focused criminal groups. Security Architect’s Take: Review your data classification and exfiltration detection controls — particularly egress monitoring and DLP policies on file stores. Ensure third-party logistics platforms and partner integrations are included in your threat modelling and have defined breach notification SLAs. ...

12 August 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options