Tengu Botnet Uses Linux Watchdog to Survive Removal

🟠 High | Source: The Hacker News A new botnet called Tengu, derived from the well-known Mirai malware, can hijack a Linux device’s hardware watchdog timer to force a reboot if defenders try to kill its process — giving its persistence mechanisms another chance to re-establish control. It spreads via brute-forced Telnet credentials and supports at least 25 DDoS attack methods. The self-healing capability makes manual incident response significantly harder on affected devices. ...

28 July 2025 Â· ZX Cloud Security

CVE-2026-47301 Configuration Manager EoP Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-47301 is an elevation of privilege vulnerability affecting Microsoft Configuration Manager, which is widely used to manage devices and software deployments across enterprise environments. Microsoft has issued a correction to the build number listed in the Security Updates table, but this is an informational change only — no new patches or exploitability changes are involved. Organisations should verify they have already applied the previously published fix. ...

28 July 2025 Â· ZX Cloud Security

CVE-2026-50422: Windows NTFS Privilege Escalation

🟠 High | Source: Microsoft Security Response Center CVE-2026-50422 is an elevation of privilege vulnerability affecting Windows NTFS, the file system used across Windows environments including Azure-hosted virtual machines. This update is purely an acknowledgement change with no new technical details or patch modifications. No immediate action is required as a result of this specific update, but the underlying vulnerability warrants attention if patching has not already been applied. Security Architect’s Take: Verify that all Windows-based Azure VMs and hybrid infrastructure have the original patch for CVE-2026-50422 applied; this acknowledgement-only update requires no further remediation action, but use it as a prompt to audit patch compliance across your Windows estate. ...

28 July 2025 Â· ZX Cloud Security

CAF Bank Takes Online Services Offline Over Security Fears

🟠 High | Source: The Register — Security Charity-focused bank CAF Bank has taken its online banking services offline as a precautionary measure following unspecified security concerns, leaving approximately 14,000 charitable organisations unable to make digital payments. Customer funds are reported to be safe, but the outage forces time-sensitive transactions through manual phone-based processes. The incident highlights the operational risk that security-driven service withdrawals can impose on vulnerable third-sector organisations. Security Architect’s Take: Review your organisation’s incident response and business continuity plans to ensure that a security-motivated service withdrawal has a clearly defined fallback for critical payment workflows — particularly for third-party banking dependencies. Assess whether your supply chain includes financial service providers whose resilience posture has been independently verified. ...

28 July 2025 Â· ZX Cloud Security

Nimbus Manticore NightLedger Backdoor & Covert Relays

🟠 High | Source: The Hacker News Iranian state-sponsored threat actor Nimbus Manticore (also known as UNC1549 and several other aliases) has been linked to a new campaign targeting organisations across the Middle East, Africa, and South Asia. The group is deploying a previously unknown Windows backdoor called NightLedger alongside two custom WebSocket tunnelling tools to maintain covert access and route malicious traffic through compromised systems. This matters because the technique of turning victim infrastructure into relay nodes makes attribution and detection significantly harder for defenders. ...

28 July 2025 Â· ZX Cloud Security

CVE-2026-53264: Linux Kernel Root Exploit via AI-Assisted Re

🟠 High | Source: The Hacker News A Linux kernel vulnerability (CVE-2026-53264) in the network traffic-control subsystem allows a local unprivileged user to gain full root access via a use-after-free race condition. The researcher who discovered it used AI tooling to both identify the flaw and accelerate exploit development, lowering the bar for future similar research. CentOS Stream 9 is confirmed affected, and the 7.8 CVSS score reflects the high impact despite requiring local access. ...

28 July 2025 Â· ZX Cloud Security

Dysphoria IoT Botnet Uses Blockchain C2 to Evade Takedown

🟠 High | Source: The Hacker News The Dysphoria IoT botnet has evolved its command-and-control infrastructure to use blockchain-based naming services and relay traffic through compromised devices, following a law enforcement takedown of the JackSkid botnet in March. This architectural shift makes traditional C2 disruption techniques — such as domain seizure and sinkholing — largely ineffective. The botnet poses a persistent threat to organisations with internet-exposed IoT devices, particularly those that are unpatched or using default credentials. ...

27 July 2025 Â· ZX Cloud Security

Rogue AI Agents, Check Point Exploit & Slopsquatting

🟠 High | Source: The Hacker News This weekly security recap covers several notable threats including a rogue OpenAI AI agent, a Check Point vulnerability being actively exploited, slopsquatting attacks targeting AI-generated package names, and ClickFix social engineering lures. The common thread is that attackers are increasingly abusing trusted tools, legitimate services, and emerging AI workflows to evade detection. Each vector represents a different entry point into enterprise cloud environments. Security Architect’s Take: Review your AI agent permissions and blast radius immediately — ensure any agentic workflows operate under least-privilege IAM roles with strict output validation and human-in-the-loop controls for sensitive actions. Additionally, audit your software supply chain for AI-recommended packages and validate all dependencies against known registries before use. ...

27 July 2025 Â· ZX Cloud Security

CVE-2026-50333 Windows Spaceport.sys EoP Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50333 is an elevation of privilege vulnerability in the Windows Spaceport.sys driver, which could allow an attacker to gain higher-level permissions on an affected system. This update is an administrative change only — an acknowledgement has been updated with no changes to the vulnerability details, patches, or severity rating. No new action is required as a result of this revision. Security Architect’s Take: No new remediation action is required from this update; verify that any previously issued patches for CVE-2026-50333 have already been applied across Windows workloads, including Azure VMs and hybrid infrastructure, and confirm your patch compliance reporting reflects the original advisory. ...

27 July 2025 Â· ZX Cloud Security

CVE-2026-50343 Microsoft Install Service EoP Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50343 is an Elevation of Privilege vulnerability in the Microsoft Install Service, which could allow an attacker to gain higher-level permissions on an affected system. This update is an informational change only, revising the acknowledgement section with no changes to severity, mitigation, or technical details. No new action is required as a result of this revision. Security Architect’s Take: No new remediation steps are required from this update — verify that patches addressing CVE-2026-50343 have already been applied across your Windows-based workloads and Azure-hosted VMs, and confirm your patch management tooling reflects the current advisory state. ...

27 July 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options