SourTrade Malvertising: Browsers Build Malware in Pieces

🟠 High | Source: The Hacker News A malvertising campaign called SourTrade, active since late 2024, tricks victims’ browsers into assembling a Windows executable from separate pieces rather than downloading a single malicious file. It impersonates well-known trading platforms such as TradingView, Solana, and Luno to target retail traders, using the legitimate Bun JavaScript runtime as its payload base. This fragmented delivery approach is designed to evade security tools that inspect complete files or block known malicious URLs. ...

25 July 2025 Â· ZX Cloud Security

Insurance Phishing Evolves Into Real-Time Account Hijacking

🟠 High | Source: The Hacker News Phishing campaigns targeting insurance customers have evolved beyond simple credential harvesting into real-time account hijacking, where attackers intercept sessions as they happen rather than using stolen passwords later. This adversary-in-the-middle approach bypasses traditional defences such as password resets and basic MFA, making compromise immediate and harder to detect. The shift represents a significant escalation in sophistication for financially motivated phishing operations. Security Architect’s Take: Review your identity protection controls to ensure MFA implementations use phishing-resistant methods such as FIDO2/passkeys rather than OTP or SMS, which are vulnerable to real-time relay attacks. Additionally, implement continuous session validation and anomalous login detection in your cloud identity platforms to catch hijacked sessions even after initial authentication succeeds. ...

25 July 2025 Â· ZX Cloud Security

DevMan RaaS: Funky Mantis Affiliate Portal Explained

🟠 High | Source: The Hacker News A ransomware-as-a-service (RaaS) operation called DevMan, tracked by PRODAFT under the name Funky Mantis, is running a centralised web portal that allows criminal affiliates to build ransomware payloads, manage victims, and handle financial payouts. This professionalised infrastructure lowers the technical barrier for would-be ransomware attackers, effectively scaling the threat. The existence of a polished affiliate portal signals an organised, ongoing operation with the potential to target organisations across multiple sectors. ...

25 July 2025 Â· ZX Cloud Security

CVE-2026-16807: Chromium Codecs Out-of-Bounds Write

🟠 High | Source: Microsoft Security Response Center A out-of-bounds write vulnerability (CVE-2026-16807) has been identified in the Codecs component of Chromium. Microsoft Edge, being Chromium-based, is affected and has ingested Google’s fix. Out-of-bounds write flaws can allow attackers to execute arbitrary code or crash applications, making prompt patching important. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest version across your organisation’s endpoints and any virtual desktop or cloud-hosted browser environments. If you manage Edge deployments via Intune, Autopatch, or Group Policy, verify the patch has been applied and consider enforcing automatic browser updates for managed devices. ...

25 July 2025 Â· ZX Cloud Security

CVE-2026-16806: Use-After-Free in Edge WebMCP

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability (CVE-2026-16806) has been identified in the WebMCP component of Chromium, which underpins Microsoft Edge. Use-after-free flaws occur when a programme continues to reference memory after it has been freed, potentially allowing an attacker to execute arbitrary code. This affects any environment where Microsoft Edge is deployed, including cloud-connected workstations and virtual desktop infrastructure. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest Chromium-based release as soon as it becomes available via your patch management tooling; prioritise endpoints and VDI images that access sensitive cloud management portals or Azure services, as browser-based code execution could facilitate credential theft or session hijacking. ...

25 July 2025 Â· ZX Cloud Security

CVE-2026-16805: Use After Free in Blink – Edge Risk

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability (CVE-2026-16805) has been identified in Blink, the rendering engine used by Chromium-based browsers. Microsoft Edge inherits this flaw via its Chromium foundation and is affected until patched. Use-after-free bugs can allow attackers to execute arbitrary code by manipulating freed memory, making this a serious browser-level risk. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest Chromium-patched release across all managed endpoints and virtual desktop environments — particularly relevant where Azure Virtual Desktop or browser-based access to cloud consoles is in use. Consider enforcing browser version compliance via Intune or equivalent MDM policy. ...

25 July 2025 Â· ZX Cloud Security

CVE-2026-16804: Use-After-Free in Microsoft Edge Chromium

🟠 High | Source: Microsoft Security Response Center CVE-2026-16804 is a use-after-free vulnerability in the Input component of the Chromium browser engine, which underpins Microsoft Edge. Use-after-free flaws can allow attackers to execute arbitrary code by manipulating freed memory, potentially compromising a user’s system if they visit a malicious page. Microsoft Edge will receive a patch via its regular Chromium ingestion process. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest version across all managed endpoints as soon as the patched build is available; enforce browser update policies via Intune or Group Policy and consider blocking unmanaged Edge installs on corporate devices until the fix is confirmed deployed. ...

25 July 2025 Â· ZX Cloud Security

Vatican Prayer App Leaks 700K+ Users' Personal Data

🟠 High | Source: The Register — Security The official Vatican prayer app has exposed the personal data of over 700,000 users due to a security vulnerability. The breach highlights the risks of inadequate data protection practices in consumer-facing religious and lifestyle applications. With a large and potentially vulnerable user base, the incident raises concerns about regulatory compliance under GDPR and the broader handling of sensitive personal information. Security Architect’s Take: Review any third-party or consumer applications integrated into your organisation’s ecosystem for exposed APIs and misconfigured storage — this incident is a reminder to enforce data minimisation and ensure regular third-party security assessments. If your organisation develops or procures apps handling personal data at scale, mandate penetration testing and cloud storage audits as part of the vendor onboarding process. ...

24 July 2025 Â· ZX Cloud Security

BlueNoroff Zoom Phishing Kit Targets Crypto Wallets

🟠 High | Source: The Hacker News North Korean threat group BlueNoroff is running an active phishing kit that impersonates Zoom and Microsoft Teams to target individuals holding cryptocurrency, profiling crypto wallets before delivering malware. The campaign combines compromised industry contacts with social engineering to establish trust before the attack is launched. This represents a sophisticated, multi-stage operation with significant financial theft potential, particularly for organisations in the crypto and Web3 sectors. ...

24 July 2025 Â· ZX Cloud Security

AI Agent Hermes Used in Autonomous Attack on Thai Finance Mi

🟠 High | Source: The Hacker News A threat actor deployed the Hermes AI agent on a rented server with autonomous mode enabled, directing it to conduct post-exploitation activities against Thailand’s Ministry of Finance without human intervention. The agent independently enumerated hosts, sought privilege escalation paths, and traversed file systems across the ministry’s network. This marks a significant escalation in attacker tooling, demonstrating that AI agents can now be weaponised to conduct complex, multi-stage intrusions at scale with minimal operator involvement. ...

24 July 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options