CVE-2026-50697 Windows CLFS Elevation of Privilege

🟠 High | Source: Microsoft Security Response Center CVE-2026-50697 is an elevation of privilege vulnerability in the Windows Common Log File System (CLFS) Driver, a core Windows component also present in Windows Server environments underpinning Azure workloads. This update is an informational change only — an acknowledgement has been amended with no change to severity or remediation guidance. CLFS elevation of privilege vulnerabilities are historically favoured by ransomware operators to gain SYSTEM-level access, making awareness of this CVE important even when updates are administrative. ...

27 July 2025 · ZX Cloud Security

Microsoft Defender for Endpoint Linux Bug Leaves Systems Unp

🟠 High | Source: The Register — Security A recent update to Microsoft Defender for Endpoint (MDE) introduced two bugs affecting Linux systems: one caused the security service to fail on restart, leaving machines unprotected, and another blocked installation entirely on hardened Red Hat Enterprise Linux (RHEL) systems. Organisations relying on MDE as their primary endpoint detection and response tool on Linux infrastructure may have had a gap in coverage without realising it. Microsoft has since acknowledged the issues and is working on fixes. ...

27 July 2025 · ZX Cloud Security

n8n Sandbox Escape: OS Command Execution CVE Fix

🟠 High | Source: The Hacker News A high-severity sandbox escape vulnerability in the workflow automation platform n8n allows an authenticated user with workflow editing permissions to break out of the expression sandbox and execute arbitrary operating system commands directly on the host server. The flaw was discovered by Security Joes as a bypass of a previous February patch for CVE-2026-27577. Versions below 2.31.5 and between 2.32.0 and 2.32.1 are affected; users should upgrade to 2.31.5 or 2.32.1 immediately. ...

27 July 2025 · ZX Cloud Security

Operation BlueDash: Fake Teams Update Drops RMM Tools

🟠 High | Source: The Hacker News Operation BlueDash is a phishing campaign that impersonates Microsoft Teams update prompts, directing victims through compromised websites to fake Microsoft Store pages. Once deceived, victims install legitimate RMM tools — Level RMM and ScreenConnect — which attackers abuse to gain persistent, stealthy remote access. This matters because using trusted, signed software bypasses many endpoint security controls and leaves little suspicious artefact for defenders to detect. ...

27 July 2025 · ZX Cloud Security

Cruciferra Crypter: BYOVD & Process Ghosting Malware

🟠 High | Source: The Hacker News A sophisticated crypter service called Cruciferra is being used by multiple threat actors, including a China-linked group targeting Indian taxpayers via phishing lures, to conceal Windows malware. It employs advanced evasion techniques including Bring Your Own Vulnerable Driver (BYOVD) and Process Ghosting to bypass endpoint security controls. The fact it is available across unrelated criminal clusters suggests it may be offered as a service, significantly broadening its potential reach. ...

27 July 2025 · ZX Cloud Security

TELESHIM Malware Uses Telegram C2 in Middle East Attacks

🟠 High | Source: The Hacker News A threat actor linked to East Asia has been conducting targeted cyberattacks against government organisations in the Middle East, deploying three previously unknown malware families: TELESHIM, MIXEDKEY, and BINDCLOAK. TELESHIM notably abuses Telegram’s platform as a command-and-control (C2) channel, making malicious traffic harder to detect and block. The campaign was identified by Zscaler ThreatLabz and represents an active, ongoing threat to public sector targets. ...

27 July 2025 · ZX Cloud Security

CVE-2026-16461: rpcbind Stack Buffer Overflow on Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-16461 is a stack buffer overflow vulnerability in rpcbind, specifically within the rpcinfo rpcbdump() function when formatting version lists in short mode. This type of memory corruption flaw can potentially allow an attacker to crash the service or execute arbitrary code. It is relevant to Azure environments where rpcbind is running on Linux-based virtual machines or container workloads. Security Architect’s Take: Audit Azure VM and container workloads for exposed rpcbind services and apply vendor patches as soon as they become available; in the interim, restrict network access to rpcbind (port 111) via NSGs and firewall rules to limit the attack surface. ...

27 July 2025 · ZX Cloud Security

CVE-2026-8450: HTTP::Daemon Perl RCE via send_file()

🟠 High | Source: Microsoft Security Response Center A vulnerability in HTTP::Daemon, a Perl web server module, allows attackers to inject and execute operating system commands via the send_file() function in versions before 6.17. This is a classic OS command injection flaw, meaning an attacker could potentially run arbitrary commands on the underlying server. The issue is notable because HTTP::Daemon is a commonly used Perl dependency that may appear in Azure-hosted workloads or containerised applications. ...

27 July 2025 · ZX Cloud Security

CVE-2026-16277: rpcbind Stack Buffer Overflow in Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-16277 is a stack buffer overflow vulnerability in rpcbind, specifically within the rpcinfo rpcbaddrlist() function. Stack buffer overflows can allow attackers to overwrite memory and potentially execute arbitrary code, depending on how the vulnerable function handles untrusted input. This vulnerability is relevant to Azure environments where Linux-based workloads or services rely on rpcbind for RPC service discovery. Security Architect’s Take: Audit Azure Linux VMs and container workloads for exposed rpcbind services and apply vendor patches immediately; consider blocking external access to rpcbind (port 111) via NSGs and Azure Firewall as a compensating control where patching cannot be applied at once. ...

27 July 2025 · ZX Cloud Security

CVE-2026-64530: Linux Kernel net/sched Flaw on Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-64530 is a Linux kernel vulnerability in the traffic control (net/sched) subsystem, specifically in the cls_api component, where the TC_ACT_CONSUMED return code is not correctly handled by tcf_qevent_handle. This flaw can lead to undefined behaviour in network packet processing, potentially enabling denial of service or memory corruption in affected environments. Azure workloads running Linux-based virtual machines or containers may be exposed if the underlying kernel is unpatched. ...

27 July 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options