CVE-2026-63514: SharePoint Server RCE Vulnerability

🟠 High | Source: Microsoft Security Response Center A remote code execution vulnerability in Microsoft SharePoint Server allows an authenticated attacker to run arbitrary code over the network by exploiting unsafe handling of untrusted data during deserialization. Because SharePoint is widely used for collaboration and document management, successful exploitation could give an attacker significant control over affected systems and potentially the wider network. The requirement for prior authorisation limits opportunistic attacks but does not remove the risk, particularly in environments with broad user access. ...

11 August 2025 · ZX Cloud Security

CVE-2026-63516: SharePoint Server Spoofing Flaw

🟠 High | Source: Microsoft Security Response Center A spoofing vulnerability in Microsoft SharePoint Server allows an authenticated attacker to exploit unsafe deserialisation of untrusted data over a network, potentially impersonating other users or systems. Deserialisation flaws are particularly dangerous as they can be chained with other weaknesses to escalate impact. Although the attacker must already be authorised, the network-based attack vector lowers the bar for exploitation in environments with broad internal access. ...

11 August 2025 · ZX Cloud Security

Kimsuky Uses Local LLMs to Power AI Phishing Attacks

🟠 High | Source: The Register — Security North Korean threat group Kimsuky is deploying locally-run large language models (LLMs) to enhance the quality and scale of their phishing campaigns, making malicious emails harder to detect through traditional means. By running AI models on-premise, the group avoids reliance on commercial AI services that have abuse controls in place. This represents a significant evolution in nation-state threat tradecraft, lowering the barrier to highly convincing, targeted spear-phishing at scale. ...

10 August 2025 · ZX Cloud Security

Storm-1175 Deploys StormEncryptor via N-central Flaw

🟠 High | Source: The Hacker News Microsoft has identified a China-linked financially motivated threat actor, Storm-1175, deploying a new ransomware strain called StormEncryptor, believed to be delivered via a vulnerability in N-central, an IT management platform. Written in C++ and appending the ‘.encrypted’ extension to files, StormEncryptor represents a shift away from the group’s previous use of Medusa ransomware. This is notable because it signals the group is developing bespoke tooling, making detection and attribution more complex. ...

10 August 2025 · ZX Cloud Security

Metabase 0-Day, MCP Supply-Chain & Router Backdoors

🟠 High | Source: The Hacker News This weekly security recap covers a cluster of notable threats including a Metabase zero-day vulnerability, supply-chain attacks targeting the Model Context Protocol (MCP), AI systems behaving unexpectedly, and backdoors discovered in consumer routers. The common thread is that attackers are exploiting trust — in defaults, in repositories, in familiar workflows — rather than needing sophisticated entry points. These issues collectively represent a broad attack surface spanning development toolchains, analytics platforms, and network infrastructure. ...

10 August 2025 · ZX Cloud Security

CVE-2024-21380 Microsoft Dynamics BC/NAV Info Disclosure

🟠 High | Source: Microsoft Security Response Center CVE-2024-21380 is an information disclosure vulnerability affecting Microsoft Dynamics Business Central and NAV, which could allow attackers to access sensitive data they should not be able to see. Microsoft has issued an update to build numbers associated with the advisory, though this latest change is administrative rather than a new patch. Organisations running affected versions should verify they are on patched builds to ensure they are protected. ...

10 August 2025 · ZX Cloud Security

CVE-2024-38225 Dynamics 365 EoP Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2024-38225 is an elevation of privilege vulnerability affecting Microsoft Dynamics 365 Business Central, a cloud-based ERP platform hosted on Azure. Successful exploitation could allow an attacker to gain higher-level permissions than intended within the application. This update revises the affected build numbers and is informational in nature, with no new patches issued. Security Architect’s Take: Verify that your Dynamics 365 Business Central environment is running a build number confirmed as patched in the updated advisory, and ensure auto-update policies are active for your tenant. Review privileged role assignments within Business Central to reduce the blast radius should exploitation occur. ...

10 August 2025 · ZX Cloud Security

CVE-2026-40417 Dynamics 365 Business Central EoP Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-40417 is an elevation of privilege vulnerability affecting Microsoft Dynamics 365 Business Central, a cloud-based ERP platform. This update revises the affected build numbers but introduces no new technical findings. Organisations running Business Central should verify whether their deployed version falls within the updated scope. Security Architect’s Take: Review the updated build numbers published by Microsoft to confirm whether your Dynamics 365 Business Central environment is affected, and ensure automatic updates are enabled or apply the relevant patch manually if running a self-managed deployment. ...

10 August 2025 · ZX Cloud Security

CVE-2026-50309: Windows NTFS RCE Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50309 is a Remote Code Execution vulnerability affecting Windows NTFS, the file system underpinning many Windows Server and Azure environments. This update is an administrative change only — an acknowledgement has been added, with no changes to severity, patch status, or technical details. No immediate action is required as a result of this specific update. Security Architect’s Take: No new action is required from this update alone; however, ensure CVE-2026-50309 is tracked in your vulnerability register and that the relevant Windows patches are applied across any Windows Server workloads running on Azure VMs or hybrid infrastructure. Confirm your patch compliance posture via Microsoft Defender for Cloud or your chosen CSPM tooling. ...

10 August 2025 · ZX Cloud Security

CVE-2026-50357: Windows ReFS Privilege Escalation

🟠 High | Source: Microsoft Security Response Center CVE-2026-50357 is an elevation of privilege vulnerability in the Windows Resilient File System (ReFS), a file system used across Windows Server environments including Azure-hosted virtual machines. If exploited, an attacker with limited local access could gain higher-level system privileges, potentially taking full control of an affected machine. This type of vulnerability is particularly concerning in shared or multi-tenant cloud environments where privilege containment is critical. ...

10 August 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options