Levi's Data Breach: Social Engineering Attack Hits Staff PCs

🟠 High | Source: The Register — Security Attackers used social engineering to gain access to three Levi Strauss employee computers, ultimately exfiltrating corporate data. The incident highlights how human manipulation remains one of the most effective entry points for threat actors, bypassing technical controls entirely. No technical vulnerability was exploited — employees were simply talked into granting access. Security Architect’s Take: Review your organisation’s privileged access and endpoint controls to ensure that even a compromised user session has limited blast radius — enforce just-in-time access, endpoint DLP, and behavioural anomaly detection so that social engineering of a single employee cannot lead directly to bulk data exfiltration. ...

10 August 2025 · ZX Cloud Security

Kimsuky Uses Offline AI to Boost Phishing & Malware

🟠 High | Source: The Hacker News North Korean state-sponsored hacking group Kimsuky has deployed a private, offline AI infrastructure to enhance phishing campaigns and automate malware development, removing reliance on monitored public AI services. The group is using retrieval-augmented generation (RAG) techniques to query internal document stores and is collecting AI software components to embed intelligence directly into malware. This marks a significant escalation in nation-state threat actors operationalising AI for offensive cyber operations. ...

10 August 2025 · ZX Cloud Security

Passkey Attacks Bypass Phishing-Resistant MFA (2026)

🟠 High | Source: The Hacker News Three independent research teams have demonstrated practical attacks against passkeys that bypass their phishing-resistance without breaking the underlying cryptography. The techniques include extracting cloud-synced private keys from a compromised machine, replaying signed authentication material exposed by Windows, and abusing a legitimate passkey flow to circumvent phishing-resistant MFA. This matters because passkeys are increasingly being positioned as a gold-standard replacement for passwords, and these findings show that implementation and sync-layer weaknesses can undermine that guarantee. ...

10 August 2025 · ZX Cloud Security

Royal Navy Drones Found Sending Data to China

🟠 High | Source: The Register — Security A cyber vulnerability assessment of Royal Navy drone systems has reportedly uncovered evidence that the devices were transmitting data to China. The finding raises serious concerns about supply chain integrity and the use of Chinese-manufactured components in sensitive military hardware. If confirmed, this represents a significant national security issue with implications for defence procurement and IoT security practices across both public and private sectors. ...

10 August 2025 · ZX Cloud Security

Head Mare Exploits TrueConf Flaws to Spread PhantomCore

🟠 High | Source: The Hacker News The Russian-linked threat actor Head Mare is exploiting unpatched vulnerabilities in TrueConf Server to replace legitimate client installers with the PhantomCore malware, targeting organisations across Russian industry sectors including energy, transport, and IT. Attackers are chaining multiple flaws to achieve this supply-chain-style compromise, meaning any user downloading the tampered installer from an internal TrueConf server could be infected. Kaspersky identified the campaign in July 2026, indicating active, ongoing exploitation. ...

10 August 2025 · ZX Cloud Security

Framework Data Breach: Metabase Zero-Day Attack Exposes Cust

🟠 High | Source: The Register — Security Framework Computer, maker of modular repairable laptops, suffered a data breach after attackers exploited a zero-day vulnerability in Metabase, a popular open-source business intelligence tool used by their accounting partner. Customer personal details were exposed as a result. The incident highlights the risk posed by third-party software vulnerabilities in supplier and partner environments. Security Architect’s Take: Audit your supply chain and third-party partners for exposed Metabase instances immediately — check for the relevant CVE patches and ensure Metabase is not publicly accessible without strong authentication. More broadly, review what customer data partners can access and enforce data minimisation contractually and technically. ...

10 August 2025 · ZX Cloud Security

CVE-2026-54876: Azure OCSP Memory Leak Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-54876 is a client-side memory leak vulnerability in OCSP (Online Certificate Status Protocol) response checking, which is used to verify whether digital certificates have been revoked. A memory leak in this process could allow an attacker to exploit exposed sensitive data from memory or degrade service availability over time. This affects Azure-connected clients or services relying on OCSP validation as part of their certificate management. ...

10 August 2025 · ZX Cloud Security

CVE-2026-63978: Linux Kernel TLS Flaw Affects Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-63978 is a Linux kernel vulnerability in the net/handshake subsystem, where pending TLS handshake requests are not properly drained when a network namespace exits. This can lead to resource mismanagement or potential memory corruption conditions. Microsoft has published this advisory in the context of Azure, suggesting it may affect Linux-based Azure workloads or underlying infrastructure components. Security Architect’s Take: Review any Linux-based Azure VMs or AKS node pools running kernel versions affected by this flaw and apply available patches promptly. Prioritise workloads that handle TLS termination or operate across multiple network namespaces, such as containerised environments, as they carry the greatest exposure. ...

10 August 2025 · ZX Cloud Security

Malicious Solidity VS Code Extensions Steal Crypto & Creds

🟠 High | Source: The Hacker News Two malicious Visual Studio Code extensions posing as Solidity development tools were found stealing cryptocurrency wallet data, API keys, and login credentials from developers. The extensions, published under ‘helper-beeps.solidity-pro’ and ‘web3devtoolsx.solidity-pro’, targeted Web3 and blockchain developers who installed them via the Open VSX marketplace. Although now removed, any developer who installed either extension should treat their credentials and wallets as compromised. Security Architect’s Take: Audit developer workstations and CI/CD pipelines for the presence of these extensions immediately, and enforce an approved VS Code extension allowlist via policy (e.g. VS Code Extension Marketplace restrictions or a curated internal mirror). Any API keys, cloud credentials, or wallet seed phrases accessible from affected developer machines should be rotated as a priority. ...

10 August 2025 · ZX Cloud Security

Ransomware Targets IT Managers: What Architects Must Do

🟠 High | Source: The Register — Security Ransomware gangs are increasingly targeting mid-level IT managers in their 40s rather than C-suite executives, recognising that these individuals often hold privileged access to critical systems and are less protected by executive security measures. This tactic exploits the reality that IT managers frequently have broad administrative rights across cloud and on-premises environments without the same level of monitoring or security awareness training as senior leadership. The shift represents a deliberate social engineering evolution aimed at maximising access while minimising detection. ...

9 August 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options