737 Chrome VPN Extensions Routing Traffic via Proxies

🟠 High | Source: The Hacker News 737 free VPN and proxy extensions on the Chrome Web Store were found to secretly route users’ browser traffic through attacker-controlled proxy infrastructure, primarily targeting Russian-speaking users. The extensions, spread across 40 developer accounts, amassed over 75,000 installs and many impersonated legitimate tools. This creates significant risk of traffic interception, credential theft, and data exfiltration. Security Architect’s Take: Audit your organisation’s managed Chrome browser policies to block unapproved extensions using the ExtensionInstallBlocklist or allowlist controls via Chrome Enterprise. Consider enforcing a zero-trust approach where only explicitly approved browser extensions can be installed on corporate devices, and review existing installs against the published list of affected extensions. ...

12 August 2025 Â· ZX Cloud Security

CVE-2022-41127: Dynamics 365 RCE Vulnerability Update

🟠 High | Source: Microsoft Security Response Center CVE-2022-41127 is a remote code execution vulnerability affecting Microsoft Dynamics NAV and Dynamics 365 Business Central running in on-premises deployments. A successful exploit could allow an attacker to execute arbitrary code on affected systems, potentially leading to full system compromise. This update revises the affected build numbers but introduces no new security fixes. Security Architect’s Take: Verify that all on-premises Dynamics NAV and Dynamics 365 Business Central instances are patched to the updated build numbers listed in the revised advisory. If you manage hybrid environments where on-premises Dynamics deployments interact with Azure services, treat unpatched nodes as a potential lateral movement risk and prioritise remediation accordingly. ...

12 August 2025 Â· ZX Cloud Security

CVE-2026-42976 Azure RPC Server Privilege Escalation

🟠 High | Source: Microsoft Security Response Center CVE-2026-42976 is an elevation of privilege vulnerability affecting the Remote Access Management service and its RPC server interface on Azure. If exploited, an attacker could gain higher-level permissions than intended, potentially compromising the integrity of affected systems. Microsoft has issued an informational update to the software table, indicating patch or product scope clarifications rather than a change in severity or exploit status. Security Architect’s Take: Review the updated Software Update table on the MSRC advisory to confirm whether your specific Remote Access Management deployments are in scope, and ensure relevant patches are applied promptly — pay particular attention to any RPC-exposed surfaces in your environment that may be accessible from lower-privileged contexts. ...

12 August 2025 Â· ZX Cloud Security

CVE-2026-50476 Windows Network Connections EoP Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50476 is an elevation of privilege vulnerability in the Windows Network Connections Service, which could allow an attacker to gain higher-level permissions on an affected system. This update is an informational change only, correcting an acknowledgement rather than patching new behaviour. No new technical risk has been introduced by this revision. Security Architect’s Take: No immediate action is required in response to this update — if you have already applied the original patch addressing CVE-2026-50476, your environment remains protected. Confirm patching status across any Windows-based Azure VMs or hybrid infrastructure nodes as standard hygiene. ...

12 August 2025 Â· ZX Cloud Security

CVE-2026-50655: Windows Media Foundation RCE Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-50655 is a remote code execution vulnerability in Microsoft Windows Media Foundation, a core multimedia framework used across Windows environments. An attacker exploiting this flaw could execute arbitrary code on affected systems, potentially leading to full system compromise. This update is an informational change only, revising the acknowledgement section with no changes to severity or remediation guidance. Security Architect’s Take: No immediate re-patching action is required as this update is acknowledgement-only; however, verify that existing patches for CVE-2026-50655 have been applied across Windows-based workloads, particularly Azure VMs and hybrid endpoints, and confirm patch compliance via Microsoft Defender for Cloud or your vulnerability management tooling. ...

12 August 2025 Â· ZX Cloud Security

CVE-2026-50687 Windows Win32k Privilege Escalation

🟠 High | Source: Microsoft Security Response Center CVE-2026-50687 is a Windows Win32k elevation of privilege vulnerability that could allow an attacker to gain elevated permissions on an affected system. This update is purely administrative — Microsoft has revised the acknowledgement section only, with no changes to severity, patch status, or technical details. No action is required beyond what was already recommended when the CVE was originally published. Security Architect’s Take: No new remediation action is required as this is an acknowledgement-only update. Verify that patches for CVE-2026-50687 have already been applied to Windows-based workloads, including Azure VMs and hybrid infrastructure, as part of your standard patch cycle. ...

12 August 2025 Â· ZX Cloud Security

CVE-2026-58538 Windows Bluetooth Privilege Escalation

🟠 High | Source: Microsoft Security Response Center CVE-2026-58538 is an elevation of privilege vulnerability in the Windows Bluetooth Service, meaning a local attacker could potentially gain higher system privileges by exploiting a flaw in Bluetooth handling. Microsoft has issued an update to this advisory, though the change is purely administrative — an acknowledgement was added with no modification to the underlying vulnerability details or patch guidance. No immediate action is required as a result of this specific update. ...

12 August 2025 Â· ZX Cloud Security

CVE-2026-62696 Windows Compatibility Assistant EoP

🟠 High | Source: Microsoft Security Response Center CVE-2026-62696 is an elevation of privilege vulnerability in the Windows Program Compatibility Assistant Service, which could allow an attacker to gain higher-level permissions on an affected system. Microsoft has issued an updated advisory, though this revision is limited to an acknowledgement change with no new technical details or patch information. While the update itself is administrative, the underlying vulnerability remains relevant for Windows-based workloads, including those hosted on Azure virtual machines. ...

12 August 2025 Â· ZX Cloud Security

CVE-2026-62747 Windows Device Association Service EoP

🟠 High | Source: Microsoft Security Response Center CVE-2026-62747 is an elevation of privilege vulnerability in the Windows Device Association Service, which could allow an attacker to gain higher-level permissions on an affected system. Microsoft has issued an update to this advisory, though the change is limited to an acknowledgement correction with no new technical details or patch changes. As a result, the underlying risk profile of this vulnerability remains unchanged. ...

12 August 2025 Â· ZX Cloud Security

CVE-2026-62913: Exchange Server RCE Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-62913 is a remote code execution vulnerability in Microsoft Exchange Server, which could allow an attacker to run arbitrary code on a vulnerable system. This update is an acknowledgement change only and contains no new technical detail or patch information. No immediate action is required beyond ensuring previously issued mitigations or patches are in place. Security Architect’s Take: Verify that any patches or mitigations previously issued for CVE-2026-62913 have been fully applied across all Exchange Server instances in your environment — this advisory change is administrative, but it serves as a useful prompt to confirm compliance with your patch management records. ...

12 August 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options