CVE-2026-12080: QEMU Guest Agent Privilege Escalation

🟠 High | Source: Microsoft Security Response Center CVE-2026-12080 is a local privilege escalation vulnerability in the QEMU guest agent, specifically affecting the ‘guest-ssh-add-authorized-keys’ functionality. An attacker with local access inside a virtual machine can exploit a symlink attack to write files to arbitrary locations, potentially gaining elevated privileges on the host or within the guest. This is relevant to Azure environments where QEMU-KVM underpins virtualisation infrastructure. Security Architect’s Take: Assess whether your Azure or self-managed VM infrastructure exposes the QEMU guest agent and apply vendor patches promptly. Review least-privilege controls for guest agent interactions and consider restricting or disabling the SSH authorised keys feature of the guest agent if it is not operationally required. ...

8 August 2025 · ZX Cloud Security

CSS Attacks Break Webmail Defences to Steal Tokens

🟠 High | Source: The Hacker News Newly published research demonstrates that malicious CSS embedded within emails can break out of the message rendering boundary in major webmail clients, including Gmail, Outlook, Proton Mail, and Yahoo Mail. Attackers can exploit these techniques to steal passwords and session tokens, hijack trusted UI elements, and manipulate AI-powered email assistants. The attack surface is broad, affecting widely used consumer and enterprise webmail platforms without requiring any user interaction beyond opening a message. ...

8 August 2025 · ZX Cloud Security

CVE-2026-68480: Azure x86 Safe-RET Interrupt Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-68480 is a Linux kernel vulnerability affecting the x86 architecture’s Safe-RET speculative execution mitigation, which can be undermined by interrupt injection. This weakness could potentially allow an attacker to bypass CPU-level defences against speculative execution attacks such as Spectre variants. It is particularly relevant in cloud environments where shared physical hardware increases the risk of cross-tenant exploitation. Security Architect’s Take: Ensure Azure VMs and any self-managed Linux workloads on x86 hardware are patched promptly once kernel updates incorporating this fix are available; prioritise multi-tenant or high-sensitivity environments where speculative execution attacks pose the greatest risk. Review your patch management pipeline to confirm kernel-level CVEs are tracked alongside application-layer vulnerabilities. ...

8 August 2025 · ZX Cloud Security

Water ICS Controllers Exposed Online: Iran Attack Warning

🟠 High | Source: The Register — Security A former NSA chief has warned that water system industrial controllers should not be internet-facing, following suspected Iranian cyberattacks targeting water infrastructure. The incidents highlight longstanding operational technology (OT) security failures where critical systems remain directly exposed online. This is a recurring pattern that puts public safety at serious risk and demands urgent remediation from asset owners and defenders. Security Architect’s Take: If your organisation manages or consults on any OT or ICS environments — including hybrid cloud-connected SCADA systems — conduct an immediate internet-exposure audit using tools such as Shodan or Censys, then enforce strict network segmentation and remove any direct internet connectivity from PLCs and HMIs, replacing with secure remote access solutions such as zero-trust gateways or jump servers with MFA. ...

7 August 2025 · ZX Cloud Security

800 Malicious npm Packages Drop RAT & Infostealer

🟠 High | Source: The Hacker News Nearly 800 malicious packages have been uploaded to the npm registry, using AI-generated or typo-squatted names to trick developers into installing them. Each package delivers a remote access trojan (RAT) and infostealer capable of running on Windows, macOS, and Linux. This represents a significant software supply chain threat, as compromised developer machines can lead to credential theft and backdoor access across entire development pipelines. ...

7 August 2025 · ZX Cloud Security

ClickFix macOS Stealer Drains Crypto Wallets

🟠 High | Source: The Hacker News A ClickFix-style social engineering attack is being used to deploy a Go-based macOS stealer capable of draining cryptocurrency wallets, harvesting browser-saved passwords, Apple iCloud Keychain credentials, and cached application credentials. The infection chain uses a shell script to fingerprint the victim’s hardware before delivering an architecture-compatible payload. This matters because ClickFix techniques require minimal user sophistication to exploit and increasingly target macOS users who may assume lower risk exposure. ...

7 August 2025 · ZX Cloud Security

UNC6671 Vishing Attacks Target SaaS Credentials

🟠 High | Source: The Hacker News A threat group called UNC6671 is conducting voice phishing (vishing) attacks against employees in financial services, private equity, and professional services, impersonating IT help desk staff to steal SaaS credentials and data. Attackers contact victims on their personal mobile phones, making traditional enterprise call-filtering controls ineffective. The end goal is data extortion, making this a significant threat to organisations handling sensitive client or financial data. ...

7 August 2025 · ZX Cloud Security

Securing AWS S3 Buckets: Fix Over-Permissioned Access

🟠 High | Source: AWS Security Blog Misconfigured Amazon S3 buckets with overly permissive policies or ACLs are a common cause of unintended data exposure in AWS environments. This AWS Security Blog post walks through how to identify buckets with excessive access permissions and provides remediation guidance. Left unchecked, such misconfigurations can lead to unauthorised access to sensitive data at scale. Security Architect’s Take: Run a targeted audit of S3 bucket policies and ACLs using AWS Config rules such as ‘s3-bucket-public-read-prohibited’ and Amazon Macie to surface over-permissioned buckets, then enforce S3 Block Public Access at the account and organisation level as a preventive control. ...

7 August 2025 · ZX Cloud Security

Ransomware Attacks Spike Amid Global AI Distraction

🟠 High | Source: The Register — Security Ransomware attacks are rising sharply as security teams and industry attention remain focused on AI developments, giving threat actors room to operate with less scrutiny. Major ransomware gangs are exploiting this distraction to increase the pace and scale of their campaigns. The trend highlights the risk of collective attention bias in cybersecurity, where emerging technology hype can draw focus away from persistent, high-impact threats. ...

7 August 2025 · ZX Cloud Security

TONTOU Attack Bypasses Spectre Fixes on Intel & AMD

🟠 High | Source: The Register — Security MIT researchers have demonstrated a new ‘TONTOU’ (Time-Of-Notification, Time-Of-Use) attack that bypasses existing Spectre mitigations on Intel and AMD processors by exploiting the window created when timer interrupts temporarily reset branch predictor defences. The researchers produced a working exploit targeting AMD Zen 2 CPUs, showing an attacker can still poison the branch predictor and leak sensitive data from memory. This undermines confidence in widely deployed Spectre mitigations such as IBRS and retpolines, which are currently the primary defences across cloud infrastructure globally. ...

7 August 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options