CVE-2026-18830: AWS Bedrock AgentCore Tool Bypass

🟠 High | Source: AWS Security Bulletins A vulnerability in Amazon Bedrock’s AgentCore InvokeHarness API allowed authenticated users to trigger configured tools directly, bypassing the AI model and its associated security controls. The flaw meant that a crafted request containing a tool-use content block could cause the agent to dispatch tools without model mediation. AWS patched the issue on 31 July 2026; the blast radius was bounded by whichever tools were configured on the affected harness. ...

4 August 2025 · ZX Cloud Security

Greatness PhaaS Adds Device Code Phishing to Bypass MFA

🟠 High | Source: The Hacker News The Greatness phishing-as-a-service toolkit has added support for device code phishing, a technique that abuses the OAuth 2.0 Device Authorization Grant flow to bypass MFA and steal authentication tokens. Attackers trick users into entering a device code on a legitimate Microsoft login page, handing over a valid session token without ever exposing their credentials. This makes the attack particularly dangerous because MFA provides no protection — the victim authenticates legitimately, and the attacker receives a fully authorised token. ...

4 August 2025 · ZX Cloud Security

AI Guardrail Bypasses: Easy Exploits for Script Kiddies

🟠 High | Source: The Register — Security Researchers have found that AI model guardrails can be bypassed with trivially simple social engineering techniques — such as claiming to own the server being queried — causing models to comply with requests they should refuse. This highlights a systemic weakness in how large language models assess context and intent rather than applying robust policy enforcement. The low skill threshold required means even unsophisticated attackers can abuse AI systems deployed in enterprise and cloud environments. ...

4 August 2025 · ZX Cloud Security

SMOKE#SCREEN: Fake Adobe & Zoom Updates Deploy ScreenConnect

🟠 High | Source: The Hacker News Attackers are running a multi-wave social engineering campaign, dubbed SMOKE#SCREEN, that tricks users into installing ConnectWise ScreenConnect by disguising it as legitimate Adobe or Zoom software updates, document reviews, or system maintenance tools. Once installed, ScreenConnect gives attackers persistent, legitimate-looking remote access to compromised machines. Because RMM tools are trusted by most security controls, this activity is difficult to detect and evict. Security Architect’s Take: Audit your environment for unauthorised or unexpected ScreenConnect/ConnectWise installations and enforce application allowlisting to block unapproved RMM tools. Ensure endpoint policies restrict the execution of software installers downloaded from the web by standard users, and consider blocking ScreenConnect’s known C2 domains at your proxy or firewall if the tool is not sanctioned in your organisation. ...

4 August 2025 · ZX Cloud Security

Vibe Hacking: AI Lowers the Bar for Cyber Attacks

🟠 High | Source: The Hacker News AI tools are dramatically lowering the barrier to entry for offensive cyber operations, enabling inexperienced attackers to carry out sophisticated attacks that previously required deep technical expertise. This ‘vibe hacking’ trend means organisations can no longer rely on attacker sophistication as a reliable risk filter. The threat landscape is effectively being democratised, expanding the pool of capable adversaries significantly. Security Architect’s Take: Reassess your threat modelling assumptions — remove ’low-sophistication attacker’ as a mitigating factor in your risk register, and prioritise controls that are effective against automated, AI-assisted attack chains such as prompt injection defences, tighter IAM least-privilege enforcement, and improved detection of reconnaissance and enumeration activity. ...

4 August 2025 · ZX Cloud Security

Google Removes ADK AI Workflows After Prompt Injection Risk

🟠 High | Source: The Hacker News Google has removed three AI agent workflows from its Agent Development Kit (ADK) Python repository after researchers at Pillar Security demonstrated that a malicious GitHub issue could manipulate a public triage agent into triggering a privileged code-fixing agent. The attack exploited prompt injection, where crafted text in a public GitHub issue caused the triage agent to post a specific command comment that satisfied the privileged agent’s authorisation check. This highlights the real-world risk of agentic AI pipelines inadvertently treating untrusted user input as trusted instructions. ...

4 August 2025 · ZX Cloud Security

Claude AI Chats Indexed by Google: Data Exposure Risk

🟠 High | Source: Schneier on Security Claude AI conversations shared via public links are being indexed by Google, exposing sensitive user data including cryptocurrency wallet keys, personal addresses, and medical billing information. The root cause is users enabling public sharing on their conversations, which Anthropic says is working as intended. However, the lack of clear user awareness around indexability means sensitive data is being inadvertently published to the open web. ...

4 August 2025 · ZX Cloud Security

DOUBLECUP ClickFix Attack Delivers DeviceManager RAT

🟠 High | Source: The Hacker News DOUBLECUP is a Russian loader-as-a-service operation that uses ClickFix social engineering to trick users into executing malicious code, which then hides malware inside PNG images stored in the browser cache using steganography. This two-stage approach ultimately delivers CountLoader and a new remote access trojan called DeviceManager. The technique is notable because it abuses legitimate browser cache storage to conceal malicious payloads, making detection harder for traditional security tools. ...

4 August 2025 · ZX Cloud Security

CVE-2026-18577: N-able N-central Flaw Added to CISA KEV

🟠 High | Source: The Hacker News CISA has added CVE-2026-18577, a high-severity flaw in N-able N-central (a widely used remote monitoring and management platform), to its Known Exploited Vulnerabilities catalogue following confirmed customer compromises. The vulnerability is an incomplete patch for an earlier flaw (CVE-2026-18556) and carries a CVSS score of 8.2. Because N-central is used by managed service providers to administer client environments, successful exploitation could provide attackers with broad access across multiple downstream organisations. ...

4 August 2025 · ZX Cloud Security

Google Dev Kit: Agent-to-Agent Prompt Injection Attack

🟠 High | Source: The Register — Security Researchers have demonstrated the first known attack where one AI agent manipulates another via prompt injection hidden inside poisoned pull requests, using Google’s developer toolkit. A compromised or malicious code contribution can contain instructions that hijack an AI coding agent’s behaviour, potentially causing it to execute unintended actions on behalf of an attacker. This matters because it shows that agentic AI pipelines introduce a new class of lateral movement risk that traditional security controls are not designed to catch. ...

3 August 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options