CVE-2026-68815 Microsoft Excel RCE Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-68815 is a Remote Code Execution vulnerability in Microsoft Excel. This update is administrative only — an acknowledgement has been amended with no changes to severity, scope, or remediation guidance. No new action is required as a result of this revision. Security Architect’s Take: No immediate action is required from this update; it is a non-substantive acknowledgement change. Ensure your estate has already applied the original patch for CVE-2026-68815 as part of your standard patch management cycle, particularly for any cloud-hosted desktops or M365-integrated environments. ...

12 August 2025 · ZX Cloud Security

CVE-2026-70348 Windows Management Services DoS Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-70348 is a Denial of Service vulnerability affecting Windows Management Services, which could allow an attacker to disrupt management plane operations. This update is administrative only, correcting an acknowledgement entry with no changes to severity, affected versions, or remediation guidance. Organisations that have already applied the relevant patch require no further action. Security Architect’s Take: No new technical action is required — this is a bookkeeping update to acknowledgements only. However, if CVE-2026-70348 has not already been triaged and patched in your Windows Management Services estate, use this as a prompt to verify patch compliance, particularly for Azure-connected or hybrid management infrastructure. ...

12 August 2025 · ZX Cloud Security

ACRO Data Breach: Unpatched CMS & Ignored Alerts

🟠 High | Source: The Register — Security The UK’s ACRO Criminal Records Office suffered a sensitive data breach after failing to patch its content management system and ignoring security alerts. The organisation still cannot confirm whether personal data was actually exfiltrated, raising serious concerns about both its technical controls and incident response capability. This is a significant failure in basic cyber hygiene at a government body handling highly sensitive criminal records data. ...

12 August 2025 · ZX Cloud Security

Akira Ransomware Disables Security Tools via Safe Mode

🟠 High | Source: The Register — Security The Akira ransomware group attempted to disable victim security tools by booting compromised systems into Safe Mode, but inadvertently broke their own encryption process in doing so, preventing successful file encryption. This incident highlights both the evolving tactics ransomware operators use to bypass endpoint defences and the operational errors that can occur when attackers improvise. While the self-inflicted failure limited damage in this case, the underlying technique of neutralising security software remains a serious and repeatable threat. ...

12 August 2025 · ZX Cloud Security

OpenAI, Anthropic & Google API Reasoning Flaw Exposed

🟠 High | Source: The Hacker News Researchers discovered a flaw in how OpenAI, Anthropic, and Google handle encrypted reasoning objects passed between API calls, allowing internal model reasoning — including sensitive data such as API keys and passwords — to be recovered from session logs. The attack works by replaying a reasoning block from one session into another, effectively letting a weaker model decode outputs intended to remain opaque. This affects the reasoning APIs of all three major AI providers simultaneously, making the blast radius unusually broad. ...

12 August 2025 · ZX Cloud Security

ShieldBreak PoC Bypasses CVE-2026-50656 Defender Patch

🟠 High | Source: The Hacker News A security researcher has released a proof-of-concept exploit for ‘ShieldBreak’, a zero-day vulnerability in Microsoft Defender that bypasses the patch for a previously disclosed flaw (CVE-2026-50656, ‘RoguePlanet’). The bypass reportedly allows an attacker to gain SYSTEM-level privileges on Windows, meaning full control of the affected machine. Patch bypasses are particularly serious as organisations that believed themselves protected may in fact remain vulnerable. Security Architect’s Take: Treat any Windows endpoints and servers running Microsoft Defender as potentially unprotected against privilege escalation until Microsoft issues a verified remediation for the bypass; apply additional compensating controls such as enforcing Privileged Access Workstations (PAWs), restricting local admin rights, and monitoring for anomalous SYSTEM-level process creation via your SIEM whilst awaiting an official patch. ...

12 August 2025 · ZX Cloud Security

Cisco ASA & FTD CVE-2026-20349: Remote DoS Exploited

🟠 High | Source: The Hacker News A high-severity vulnerability (CVE-2026-20349) in Cisco’s ASA and FTD firewall software is being actively exploited in the wild, allowing unauthenticated remote attackers to crash the device via malformed HTTP requests. With a CVSS score of 8.6, the flaw requires no credentials to exploit, making it particularly dangerous for internet-facing firewall deployments. Organisations relying on these Cisco products for perimeter security should treat this as an urgent remediation priority. ...

12 August 2025 · ZX Cloud Security

CVE-2026-68820: Windows Driver Zero-Day Patched

🟠 High | Source: The Hacker News Microsoft’s August 2026 Patch Tuesday addresses 398 vulnerabilities, including a zero-day flaw (CVE-2026-68820) in a core Windows kernel network socket driver that is already being actively exploited. The vulnerability allows an attacker who already has a foothold on a machine to escalate their privileges to SYSTEM level. With active exploitation confirmed, this patch should be treated as urgent. Security Architect’s Take: Prioritise deployment of the August 2026 Patch Tuesday updates across all Windows workloads immediately, with particular urgency for internet-facing systems, jump hosts, and cloud-connected Windows VMs (including Azure IaaS and hybrid environments). Verify that your vulnerability management and patch compliance tooling flags CVE-2026-68820 as a critical remediation priority regardless of its CVSS score, given confirmed active exploitation. ...

11 August 2025 · ZX Cloud Security

Kimwolf v7 Botnet Disguises DDoS as Browser Traffic

🟠 High | Source: The Hacker News A new version of the Kimwolf (also known as AISURU) Android and IoT botnet, tracked as v7, has been identified by Palo Alto Networks Unit 42 in February 2026. The updated botnet uses HTTP/2-based DDoS traffic engineered to mimic legitimate browser activity, making it significantly harder to detect and block. This development raises the bar for defenders attempting to filter malicious traffic at the network edge. ...

11 August 2025 · ZX Cloud Security

Sandworm UAC-0145 Fake Job VPN Malware Attack

🟠 High | Source: The Hacker News A Russian state-linked threat group (UAC-0145, a Sandworm subgroup) is targeting Ukrainian IT workers with fake job interview lures, tricking them into installing a malicious VPN client that grants attackers remote command execution on victims’ machines. The campaign is a social engineering operation disguised as legitimate recruitment activity. This matters because IT workers with privileged access to infrastructure are high-value targets, and compromised endpoints can serve as footholds into cloud and enterprise environments. ...

11 August 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options