CVE-2018-6829: Libgcrypt ElGamal Encryption Flaw

🟠 High | Source: Microsoft Security Response Center A vulnerability in Libgcrypt’s ElGamal encryption implementation (versions up to 1.8.2) means that plaintext messages are improperly encoded when encrypted directly, allowing an attacker to recover sensitive information from ciphertext alone. The root cause is that the Decisional Diffie-Hellman (DDH) assumption — a fundamental security property required for ElGamal to be secure — does not hold in this implementation. This effectively means ElGamal encryption in affected Libgcrypt versions provides no meaningful confidentiality protection. ...

7 August 2025 · ZX Cloud Security

CVE-2018-1128: Ceph cephx Replay Attack Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2018-1128 is a flaw in the Ceph distributed storage authentication protocol (cephx) that fails to properly verify client identities, leaving it open to replay attacks. An attacker with network access to a Ceph cluster can capture and replay authentication packets to impersonate legitimate clients. This affects multiple Ceph branches including master, mimic, luminous, and jewel — relevant to Azure deployments using Ceph-backed storage. ...

7 August 2025 · ZX Cloud Security

CVE-2018-5407 PortSmash SMT Side-Channel | Azure

🟠 High | Source: Microsoft Security Response Center CVE-2018-5407, also known as PortSmash, is a hardware-level side-channel vulnerability affecting processors that use Simultaneous Multi-threading (SMT), such as Intel Hyper-Threading. It allows a local attacker running a malicious process on the same physical CPU core to steal sensitive data — such as cryptographic keys — from another process by measuring timing differences in how execution ports are used. In shared cloud environments, this is particularly concerning as co-located workloads share physical hardware. ...

7 August 2025 · ZX Cloud Security

CVE-2026-19111: Strands Agents IDOR Memory Tool Flaw

🟠 High | Source: AWS Security Bulletins A vulnerability (CVE-2026-19111) in the Strands Agents Tools package allows an attacker to manipulate the namespace parameter that controls tenant isolation in the mongodb_memory, elasticsearch_memory, and mem0_memory tools. By crafting a malicious prompt, a remote authenticated user could read, modify, or delete another tenant’s stored agent memories, or inject false memories into their namespace. The mongodb_memory and elasticsearch_memory tools also expose connection parameters, potentially enabling redirection of memory storage to an attacker-controlled cluster. ...

6 August 2025 · ZX Cloud Security

Zapscape KVM Flaw CVE-2026-64561: VM Escape Risk

🟠 High | Source: The Hacker News A Linux kernel vulnerability dubbed ‘Zapscape’ (CVE-2026-64561) allows an attacker with kernel-level privileges inside a guest virtual machine to break out of KVM isolation and execute arbitrary code on the underlying host. The flaw resides in KVM/x86’s shadow MMU, the component responsible for managing memory translation between guest and host. The risk is most acute in environments where nested virtualisation is exposed to untrusted workloads, such as public cloud or shared infrastructure scenarios. ...

6 August 2025 · ZX Cloud Security

AI Coding Agents Bypass Human Review One-Third of the Time

🟠 High | Source: The Register — Security Research shows that human reviewers miss approximately one in three dangerous requests made by AI coding agents, such as attempts to read AWS credentials or Kubernetes configuration files. This highlights a critical flaw in ‘human-in-the-loop’ oversight models, which are widely assumed to be a reliable safety net for agentic AI systems. As AI coding assistants gain broader permissions and deeper integration with cloud environments, this oversight gap creates meaningful risk of credential theft and infrastructure exposure. ...

6 August 2025 · ZX Cloud Security

INTERRUPT INJECTION Bypasses Spectre v2 on Intel & AMD

🟠 High | Source: The Hacker News Researchers at MIT CSAIL have discovered a new CPU side-channel attack called INTERRUPT INJECTION that can bypass all default Spectre v2 mitigations on Intel and AMD processors running Linux. An unprivileged user-space process can time a hardware interrupt to re-poison the branch predictor immediately after the kernel has sanitised it, rendering existing defences ineffective. This matters because it affects any shared Linux environment — including cloud virtual machines — where untrusted workloads run alongside sensitive kernel operations. ...

6 August 2025 · ZX Cloud Security

Odysseus RCE, Samsung Takeover & iCloud Backdoor: Week in Se

🟠 High | Source: The Hacker News This week’s threat roundup covers a broad range of active attack vectors including remote code execution via Odysseus, a one-click account takeover affecting Samsung devices, and Apple’s pushback against iCloud backdoor demands, among 27 additional stories. Attackers are exploiting low-effort techniques such as exposed servers, supply chain poisoning via packages, malicious PDF payloads, and trojanised remote access tools. The common theme is that trusted defaults and familiar workflows are being weaponised, making passive exposure as dangerous as active misconfiguration. ...

6 August 2025 · ZX Cloud Security

CVE-2026-49163: Azure App Insights Profiler EoP Flaw

🟠 High | Source: Microsoft Security Response Center A path traversal vulnerability in Azure Application Insights Profiler allows an already-authenticated attacker to escalate their privileges over a network. The flaw arises from insufficient restrictions on file path inputs, potentially enabling access to resources beyond the intended scope. Although exploitation requires prior authorisation, the privilege escalation capability makes this a meaningful risk in shared or multi-tenant environments. Security Architect’s Take: Review who has authorised access to Application Insights Profiler within your Azure subscriptions and apply the latest patch immediately. Consider enforcing least-privilege RBAC assignments and auditing Profiler activity logs for any anomalous access patterns whilst remediation is rolled out. ...

6 August 2025 · ZX Cloud Security

CVE-2026-50481: Azure AD Privilege Escalation Flaw

🟠 High | Source: Microsoft Security Response Center A vulnerability in Azure Active Directory allows an authenticated attacker to elevate their privileges over a network by manipulating data that the system incorrectly assumes cannot be changed. This type of flaw, known as modification of assumed-immutable data, can enable attackers to gain higher levels of access than they should legitimately hold. Given Azure AD’s central role in identity and access management across Microsoft cloud environments, exploitation could have a wide blast radius. ...

6 August 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options