CVE-2026-63508: Microsoft Planetary Computer Pro EoP

🟠 High | Source: Microsoft Security Response Center A missing authentication flaw in Microsoft Planetary Computer Pro allows an unauthenticated attacker to elevate their privileges over a network without requiring any user interaction. This means an attacker with network access could gain higher-level permissions than intended, potentially compromising sensitive geospatial and environmental data workloads hosted on the platform. The lack of any authentication requirement makes this relatively straightforward to exploit. Security Architect’s Take: Review whether your organisation uses Microsoft Planetary Computer Pro and apply any available patches or mitigations from Microsoft immediately. In the interim, consider restricting network access to the service using Azure network security controls such as private endpoints, NSGs, or Azure Firewall to limit exposure until a fix is confirmed in place. ...

6 August 2025 · ZX Cloud Security

CVE-2026-63522: Azure SQL Database Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A vulnerability in Azure SQL Database allows an authenticated attacker to exploit incorrect permission assignments to elevate their privileges within the service. Because the attack is local and requires existing authorisation, the risk is highest in multi-tenant or shared environments where users may have limited but legitimate access. If exploited, an attacker could gain capabilities beyond their intended level, potentially accessing or modifying data they should not be able to reach. ...

6 August 2025 · ZX Cloud Security

CVE-2026-65667: Microsoft Teams Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A vulnerability in Microsoft Teams allows an attacker with network access to gain elevated privileges without any prior authorisation. The flaw stems from missing authorisation checks, meaning an attacker could potentially escalate their access within an organisation’s Teams environment. This is particularly concerning given how widely Teams is deployed across enterprises for day-to-day communication and collaboration. Security Architect’s Take: Review your network segmentation to limit lateral movement opportunities, and ensure Microsoft Teams is patched to the latest version immediately. Until patching is confirmed, consider monitoring Teams-related activity logs in Microsoft Sentinel or your SIEM for anomalous privilege changes or unexpected API calls. ...

6 August 2025 · ZX Cloud Security

CVE-2026-65668: Microsoft Purview eDiscovery EoP Flaw

🟠 High | Source: Microsoft Security Response Center A vulnerability in Microsoft Purview eDiscovery allows an attacker who already has some level of authorised access to gain higher privileges over a network due to improper access controls. This is particularly concerning in environments where eDiscovery is used to handle sensitive legal, compliance, or HR data. Successful exploitation could allow an attacker to access or manipulate data and configurations far beyond their intended permissions. ...

6 August 2025 · ZX Cloud Security

CVE-2026-68823: Azure Confidential Ledger RCE Flaw

🟠 High | Source: Microsoft Security Response Center A vulnerability in Azure Confidential Ledger exposes a dangerous method or function that allows an attacker who already has authorised access to execute arbitrary code remotely over a network. Azure Confidential Ledger is a tamper-proof service used to store sensitive audit logs and transaction records, making this particularly serious for organisations relying on it for compliance and integrity guarantees. Although exploitation requires prior authorisation, the ability to run arbitrary code within a confidential computing environment undermines the core trust model of the service. ...

6 August 2025 · ZX Cloud Security

CVE-2026-70332: SharePoint XSS Spoofing Vulnerability

🟠 High | Source: Microsoft Security Response Center A cross-site scripting (XSS) vulnerability in Microsoft SharePoint allows an unauthenticated attacker to perform spoofing attacks over a network by injecting malicious content into web pages served by SharePoint. This type of flaw can be exploited to steal session tokens, redirect users to malicious sites, or perform actions on behalf of legitimate users. As SharePoint is widely used for collaboration and document management across enterprises, the potential for data exposure and account compromise is significant. ...

6 August 2025 · ZX Cloud Security

4,400 Rockwell PLCs Exposed Online: Water Utility Risk

🟠 High | Source: The Hacker News Forescout researchers discovered over 4,400 Rockwell Automation PLCs directly exposed to the internet, including 22 located in US cities recently targeted by cyberattacks on water utilities. Nineteen of those 22 controllers shared the same mobile carrier network, suggesting a common deployment pattern. While no confirmed compromises were identified, the exposure represents a significant attack surface against critical national infrastructure. Security Architect’s Take: If your organisation manages or secures OT/ICS environments, audit internet-facing Rockwell PLCs immediately and enforce network segmentation — PLCs should never be directly reachable from the public internet. Where remote access is operationally required, mandate VPN or zero-trust network access (ZTNA) with MFA rather than direct exposure. ...

6 August 2025 · ZX Cloud Security

Sticky Note Credentials on Laptops Led to Breach

🟠 High | Source: The Register — Security An IT department attached sticky notes containing login credentials directly to employee laptops, leaving usernames and passwords physically exposed. This allowed an unauthorised individual to gain access to systems using the visible credentials. The incident highlights how even basic physical security oversights can completely undermine technical controls. Security Architect’s Take: Conduct a physical security audit across your organisation’s office and remote working environments to ensure credentials, MFA codes, and access tokens are never written down or left exposed. Enforce passwordless authentication or SSO with MFA to remove the need for users to remember or write down passwords entirely. ...

6 August 2025 · ZX Cloud Security

AI Prompt Injection via 'Ask AI' Buttons Poisons LLM Memory

🟠 High | Source: The Hacker News A newly documented prompt injection technique embeds hidden instructions inside ‘Ask AI’ deep-link buttons on commercial websites, causing AI assistants to silently absorb attacker-controlled content into their memory or context. The attack requires no malware, exploits, or compromised credentials — only a user clicking a standard-looking button. This is particularly concerning because it can manipulate AI-driven recommendations and persist across user sessions if memory features are enabled. ...

6 August 2025 · ZX Cloud Security

AWS, Google & Vercel AI Agent Flaws Bypass Guardrails

🟠 High | Source: The Hacker News Security researchers discovered flaws in AI agent infrastructure from AWS, Google, and Vercel that allowed attackers to trigger tool calls without a language model ever processing the request. Because the model never ran, safety controls such as system prompts, content filters, and guardrails were entirely bypassed. This means an attacker could invoke agent tools — potentially with real-world side effects — purely through forged or untrusted instructions. ...

6 August 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options