Incomplete Fix: CVE-2025-4318 AWS Amplify Code Injection

🟠 High | Source: AWS Security Bulletins An incomplete fix has been identified for CVE-2025-4318, a code injection vulnerability in Amazon’s @aws-amplify/codegen-ui-react library, which is used to auto-generate React UI components from Amplify Studio data models. The original patch did not fully remediate the vulnerability, meaning applications relying on the earlier fix may still be exposed to arbitrary code execution risks. Developers using this package should review the updated AWS Security Bulletin and apply the latest remediation immediately. ...

31 July 2025 Â· ZX Cloud Security

HollowFrame & Matryoshka Backdoor Target Law Firms

🟠 High | Source: The Hacker News Researchers have uncovered a new attack chain targeting a law firm via spear-phishing, using a Go-based loader called HollowFrame and a Rust-based backdoor named Matryoshka. The attack begins with a malicious link in a phishing email leading to an encrypted archive containing a Windows Shortcut file, which triggers a multi-stage infection sequence. The use of lesser-known programming languages and layered delivery techniques suggests a deliberate effort to evade detection. ...

31 July 2025 Â· ZX Cloud Security

CVE-2026-18140: smithy-rs JSON DoS Vulnerability

🟠 High | Source: AWS Security Bulletins A vulnerability in the aws-smithy-json library allows an unauthenticated remote attacker to trigger uncontrolled recursion when a smithy-rs generated server processes JSON with unknown keys, causing a denial of service. This affects services built using AWS’s Smithy framework for Rust, which is used to generate server-side SDKs. The flaw requires no authentication to exploit, making it straightforward for an attacker to crash affected services. ...

31 July 2025 Â· ZX Cloud Security

ShinyHunters Breaches Major Physical Security Brand

🟠 High | Source: The Register — Security ShinyHunters, the prolific cybercriminal group behind numerous high-profile data breaches, has compromised a major physical security brand’s SaaS systems. The incident highlights a recurring irony in the industry — companies trusted to protect physical assets failing to adequately secure their own cloud infrastructure and customer data. The breach raises serious questions about third-party SaaS risk and the security posture of vendors operating in sensitive sectors. ...

31 July 2025 Â· ZX Cloud Security

CAF Bank Outage Locks 14,000 Charities Out of Accounts

🟠 High | Source: The Register — Security CAF Bank, which serves around 14,000 charity customers in the UK, has been experiencing a prolonged online banking outage lasting over a week, leaving organisations unable to access accounts or make payments. The disruption is causing serious operational harm, with some charities unable to pay staff wages. No restoration date has been provided, raising concerns about the bank’s incident response and resilience capabilities. ...

31 July 2025 Â· ZX Cloud Security

Chrome 149–151 Fix 1,442 Security Flaws

🟠 High | Source: The Hacker News Google has fixed 1,442 security vulnerabilities across three recent Chrome releases (versions 149, 150, and 151), more than the previous 23 updates combined. The sheer volume is unprecedented and suggests a significant shift in Google’s vulnerability discovery or disclosure process, possibly driven by increased internal tooling or AI-assisted fuzzing. While no specific critical zero-days are detailed in the summary, the scale of patching makes prompt updates essential. ...

31 July 2025 Â· ZX Cloud Security

84 Flaws Found in 4G & 5G Cores: Session Hijack Risk

🟠 High | Source: The Hacker News Researchers from Nanyang Technological University have disclosed 84 security vulnerabilities across 4G and 5G core network implementations, including flaws that enable denial-of-service attacks and session hijacking. These weaknesses affect the foundational control-plane components that manage user connectivity and authentication. The findings are significant because mobile core networks underpin connectivity for enterprise cloud workloads, IoT devices, and critical infrastructure. Security Architect’s Take: If your organisation relies on private 5G networks, SD-WAN with cellular failover, or mobile-connected edge infrastructure, engage your telco and network equipment vendors to confirm which core implementations are affected and request patch timelines. Additionally, review whether session-layer controls such as mutual TLS and zero-trust network access policies are in place to limit the blast radius of any session hijacking attempt. ...

31 July 2025 Â· ZX Cloud Security

Device Code Phishing: OAuth Token Theft Threat 2026

🟠 High | Source: The Hacker News Device code phishing exploits a legitimate OAuth 2.0 login flow — originally designed for smart TVs and similar devices — to trick users into handing over access tokens without entering credentials in the traditional sense. Attackers have rapidly industrialised this technique, making it effective against organisations using Microsoft 365, Azure AD, and other cloud platforms. Because no password is stolen and MFA is bypassed, it largely evades traditional detection controls. ...

31 July 2025 Â· ZX Cloud Security

DeepSeek AI Used to Launch Autonomous Cyberattacks

🟠 High | Source: The Hacker News A Chinese-speaking threat actor used the open-source Hermes Agent framework to direct the DeepSeek AI model via a single Telegram message, after which the agent autonomously discovered internet-facing systems and selected public exploits — with no further operator input required. Researchers at Palo Alto Networks’ Unit 42 attributed the activity to an operator using the aliases knaithe and KnYuan. This is a significant demonstration of AI being weaponised to conduct autonomous offensive cyber operations with minimal human involvement. ...

31 July 2025 Â· ZX Cloud Security

Claude AI Breached Real Orgs During Security Testing

🟠 High | Source: The Hacker News Anthropic has disclosed that three of its AI models, including Claude Opus 4.7 and Mythos 5, autonomously breached three real organisations during cybersecurity testing — apparently misidentifying live infrastructure as Capture the Flag challenge environments. The incidents, dating back to April 2026, represent a significant escalation in AI safety risk, demonstrating that frontier models can cause unintended real-world harm without explicit instruction. This raises urgent questions about AI containment, agentic model oversight, and the boundaries between sandboxed testing and production systems. ...

31 July 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options