Cisco Patches 12 SD-WAN & IOS XE Flaws (3 CVSS 9.8)

🔴 Critical | Source: The Hacker News Cisco has released patches addressing 12 security vulnerabilities across its Catalyst SD-WAN and IOS XE Software, including three rated 9.8 out of 10 on the CVSS severity scale — the highest possible for exploitability. These flaws affect a wide range of Cisco networking infrastructure regardless of device configuration, meaning the attack surface is broad. Unpatched devices could allow remote attackers to take full control of affected systems without requiring authentication. ...

6 August 2026 · ZX Cloud Security

Snowflake Extortion: Canadian Hacker Pleads Guilty

🔴 Critical | Source: Krebs on Security Connor Riley Moucka, a 26-year-old Canadian, has pleaded guilty to hacking and extorting over 165 organisations that used the Snowflake cloud data platform, in one of 2024’s most damaging cybercrime campaigns. The attacks exploited poor credential hygiene — specifically the absence of multi-factor authentication on Snowflake accounts — allowing mass data theft including over 100 million AT&T customer records. The case underscores the severe real-world consequences of inadequate access controls on cloud data warehousing platforms. ...

6 August 2026 · ZX Cloud Security

CVE-2026-50516: Azure Kubernetes Service EoP Flaw

🔴 Critical | Source: Microsoft Security Response Center A vulnerability in Microsoft Azure Kubernetes Service (AKS) allows an unauthenticated attacker to elevate their privileges over a network by exploiting a missing authentication check on a critical function. This means an attacker with network access could gain elevated control over Kubernetes workloads without needing valid credentials. Given the widespread use of AKS in production environments, the potential blast radius is significant. Security Architect’s Take: Review network exposure of your AKS API server and control plane endpoints immediately, ensuring they are not publicly accessible without strict network controls. Apply any available Microsoft patches or mitigations without delay, and audit recent access logs for anomalous unauthenticated requests to AKS endpoints. ...

6 August 2026 · ZX Cloud Security

CVE-2026-62873: Microsoft 365 Admin Centre EoP Flaw

🔴 Critical | Source: Microsoft Security Response Center A vulnerability in Microsoft 365 Admin Center allows an attacker to gain elevated privileges over a network by exploiting improper verification of cryptographic signatures. Because Microsoft 365 Admin Center is used to manage users, licences, and security settings across an organisation’s Microsoft 365 tenancy, a successful exploit could give an attacker significant administrative control. This makes it a high-value target for threat actors seeking to compromise corporate environments. ...

6 August 2026 · ZX Cloud Security

CryptoJS Weak RNG: $5.7M Crypto Wallet Drains Explained

🔴 Critical | Source: The Hacker News A weak random number generator in the widely-used CryptoJS JavaScript library has been exploited to drain at least $5.7 million from five cryptocurrency wallet applications. The vulnerable function, CryptoJS.lib.WordArray.random(), has been present in the library for 12 years and produces insufficiently random entropy when generating wallet recovery phrases. Attackers were able to predict or reconstruct private keys derived from this weak entropy, leading to two waves of theft since late May. ...

6 August 2026 · ZX Cloud Security

Oracle SQL Injection Leads to SYSTEM Access via khunt

🔴 Critical | Source: The Hacker News Attackers exploited a SQL injection vulnerability in a public-facing web application to gain access to an Oracle database, then used a post-exploitation toolkit called ‘khunt’ to execute commands directly inside the database engine by compiling Java source code into stored schema objects — no executable written to disk. This technique effectively turns the Oracle database process itself into a command execution environment, bypassing many traditional endpoint detection controls. The attack ultimately resulted in SYSTEM-level access on the underlying Windows host, dramatically escalating the blast radius beyond the database. ...

6 August 2026 · ZX Cloud Security

Zbtlink Routers Ship With Root Shell Backdoor

🔴 Critical | Source: The Hacker News At least 20 router models from Chinese manufacturer Zbtlink have been found to ship with a pre-installed backdoor that grants unauthenticated root-level access. The backdoor is present across all 21 firmware images available from the vendor, spanning over two years of production, and automatically beacons to external infrastructure. This represents a supply chain compromise affecting any organisation using these devices, as the backdoor is baked in before the hardware reaches the customer. ...

6 August 2026 · ZX Cloud Security

IBM Langflow RCE Flaw Under Active Attack – Patch Now

🔴 Critical | Source: The Register — Security A critical remote code execution (RCE) vulnerability in Langflow, IBM’s agentic AI platform, is being actively exploited in the wild, according to CISA. The flaw affects default deployments, meaning organisations using out-of-the-box configurations are immediately at risk without additional misconfiguration required. Active exploitation raises the stakes significantly, making prompt patching essential rather than discretionary. Security Architect’s Take: Audit your environment immediately for any Langflow deployments — including those spun up by development or data science teams outside of standard change control — and apply the vendor patch without delay. If patching cannot be completed immediately, consider isolating Langflow instances from public-facing network access and restricting ingress to trusted IP ranges as a temporary control. ...

5 August 2026 · ZX Cloud Security

Critical Flaws Patched in Veeam, Terraform MCP & Django

🔴 Critical | Source: The Hacker News HashiCorp, Veeam, and the Django Software Foundation have issued patches addressing 11 vulnerabilities, including two critical flaws: a CVSS 10.0 cross-tenant token reuse bug in HashiCorp’s Terraform MCP Server and a CVSS 9.5 unauthenticated credential exposure flaw in Veeam Service Provider Console. These vulnerabilities could allow attackers to hijack Terraform operations across tenant boundaries or extract managed agent credentials without authentication. Organisations using these tools in multi-tenant or service provider environments face significant exposure if unpatched. ...

5 August 2026 · ZX Cloud Security

CVE-2026-59774: Critical Gitea File-Read Flaw

🔴 Critical | Source: The Hacker News A critical vulnerability in Gitea versions 1.22.1 through 1.27.0 allows any unauthenticated attacker to read arbitrary files accessible to the Gitea service account, simply by crafting malicious Org-mode markup in a public repository. No credentials or write access are required, making exploitation trivially easy. The flaw is patched in Gitea 1.27.1 and carries a CVSS score of 9.8. Security Architect’s Take: Upgrade all Gitea instances to version 1.27.1 immediately; if patching is not possible right now, restrict public repository access and place Gitea behind network-level controls to limit unauthenticated exposure. Additionally, audit the permissions of the Gitea service account to minimise the blast radius of any file-read exploitation. ...

5 August 2026 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options