DeadLock Ransomware Abuses Polygon Blockchain Infrastructure

🟠 High | Source: The Hacker News The DeadLock ransomware group is leveraging Polygon blockchain smart contracts and the Session decentralised messaging network to host extortion infrastructure, making it significantly harder for law enforcement and defenders to take down. By moving victim communications and data leak operations onto decentralised platforms, the group reduces its reliance on traditional web hosting that can be seized or disrupted. This represents a notable evolution in ransomware operational security that other threat actors are likely to adopt. ...

11 August 2025 · ZX Cloud Security

DEF CON Attendee Suspected of Hacking Delta In-Flight Wi-Fi

🟠 High | Source: The Register — Security A suspected security researcher or attendee from the DEF CON hacking conference has allegedly attempted to compromise Delta Air Lines’ in-flight Wi-Fi system. The incident highlights the real-world risks posed by individuals with offensive security skills targeting live operational technology outside controlled environments. If confirmed, it raises serious concerns about the security posture of aviation network infrastructure and the potential for broader passenger data or safety system exposure. ...

11 August 2025 · ZX Cloud Security

Geopolitical DDoS Attacks Hit 1 Tbps, Up 519%

🟠 High | Source: The Register — Security Geopolitically motivated DDoS attacks linked to the conflicts in Ukraine and Iran, as well as the FIFA World Cup, have driven a 519% surge in attack traffic, with peaks reaching 1 Tbps. Publishers and media organisations are the primary targets, likely due to their role in shaping public narrative. The scale and frequency of these attacks represent a significant operational risk for internet-facing infrastructure. ...

11 August 2025 · ZX Cloud Security

CVE-2026-50472: Windows LUAFV Privilege Escalation

🟠 High | Source: Microsoft Security Response Center CVE-2026-50472 is a heap-based buffer overflow vulnerability in the Windows LUA File Virtualization Filter Driver (LUAFV), a component that underpins User Account Control file virtualisation. An attacker who already has local access to a system can exploit this flaw to gain elevated privileges, potentially achieving full system control. This is particularly relevant in cloud environments where Windows VMs and shared infrastructure could be compromised if an attacker gains an initial foothold. ...

11 August 2025 · ZX Cloud Security

CVE-2026-56174 Windows Narrator Braille EoP Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-56174 is a privilege escalation vulnerability in Windows Narrator’s Braille support, caused by an untrusted search path flaw. An attacker who already has local access to a Windows system can exploit this to gain elevated privileges. Whilst the attack requires existing access, it represents a meaningful stepping stone in a broader attack chain. Security Architect’s Take: Ensure Windows endpoint patching pipelines cover Azure Virtual Machines and AVD (Azure Virtual Desktop) session hosts, particularly those running accessibility features. Prioritise patching any Windows environments accessible to multiple users or lower-privileged accounts, and review local access controls to limit the blast radius of privilege escalation attempts. ...

11 August 2025 · ZX Cloud Security

CVE-2026-57105: SharePoint XSS Spoofing Vulnerability

🟠 High | Source: Microsoft Security Response Center A cross-site scripting (XSS) vulnerability in Microsoft SharePoint allows an authenticated attacker to inject malicious scripts into web pages viewed by other users, enabling spoofing attacks over a network. Because the attacker only needs an existing account to exploit this, the barrier to attack is relatively low. If successfully exploited, this could be used to steal session tokens, redirect users to malicious sites, or impersonate legitimate users. ...

11 August 2025 · ZX Cloud Security

CVE-2026-62827: SharePoint Server EoP Vulnerability

🟠 High | Source: Microsoft Security Response Center A vulnerability in Microsoft SharePoint Server allows an already-authenticated attacker to gain higher-level privileges than they should have, purely over the network. This is concerning because it lowers the bar for an insider threat or a compromised account to cause significantly more damage. Organisations running SharePoint Server on-premises or in hybrid configurations should treat this as an urgent patching priority. Security Architect’s Take: Apply the relevant Microsoft security update immediately, particularly for any SharePoint Server instances exposed to internal networks or the internet. In the interim, review and restrict SharePoint permissions to least-privilege and monitor audit logs for unexpected privilege changes or unusual administrative activity. ...

11 August 2025 · ZX Cloud Security

CVE-2026-62829: SharePoint Server XSS Spoofing Flaw

🟠 High | Source: Microsoft Security Response Center A cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server allows an authenticated attacker to perform spoofing attacks over a network by injecting malicious content into web pages generated by the application. Because the attacker only needs to be an authorised user rather than an administrator, the barrier to exploitation is relatively low. This is particularly concerning in organisations where SharePoint is widely used for internal collaboration and document management. ...

11 August 2025 · ZX Cloud Security

CVE-2026-62837 SharePoint Path Traversal Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-62837 is a path traversal vulnerability in Microsoft SharePoint Server that allows an authenticated attacker to access files or data they should not be able to reach across a network. Because it requires only valid credentials rather than administrative access, the risk surface is broad in organisations where SharePoint is widely used. It was patched by Microsoft and organisations should apply the relevant update promptly. ...

11 August 2025 · ZX Cloud Security

CVE-2026-63512 Microsoft SharePoint Tampering Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-63512 is a tampering vulnerability in Microsoft SharePoint Server caused by incorrect authorisation controls. An already-authenticated attacker can exploit this flaw over a network to manipulate SharePoint data or configuration without proper permission. Organisations relying on SharePoint for document management and collaboration are at risk of unauthorised data modification. Security Architect’s Take: Apply Microsoft’s patch immediately and review SharePoint access controls to ensure least-privilege principles are enforced; consider temporarily restricting external network access to SharePoint Server instances until patching is confirmed across all nodes. ...

11 August 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options