Russian Zero-Click Email Attacks: What You Must Know

🟠 High | Source: The Register — Security A year-long Russian-linked phishing campaign has been exploiting a vulnerability that allows malware to execute simply by a user previewing or opening an email, without clicking any link or attachment. The technique likely abuses zero-click or render-time exploitation, making it exceptionally dangerous as traditional user-awareness training offers little protection. Organisations relying on standard email security controls may be inadequately protected against this class of attack. ...

23 July 2025 Â· ZX Cloud Security

Millions of Cars Hijackable via Shared Bluetooth Key Flaw

🟠 High | Source: The Register — Security Researchers at UC San Diego have discovered that KARR/SWDS aftermarket vehicle security systems, installed by dealers across California, all share a single hardcoded cryptographic key. This means an attacker within Bluetooth range can authenticate to any affected vehicle and potentially unlock, track, or remotely start millions of cars. The scale of deployment makes this a widespread physical security risk affecting everyday consumers. Security Architect’s Take: While this is not a direct cloud infrastructure issue, it is a sharp reminder of the risks of hardcoded shared secrets and the importance of per-device unique key provisioning in any IoT or embedded system your organisation procures or oversees. If your fleet management or connected vehicle strategy involves aftermarket telematics devices, audit vendor key management practices immediately and enforce unique credential requirements in procurement contracts. ...

23 July 2025 Â· ZX Cloud Security

CVE-2026-16584: AWS MCP Server Policy Bypass

🟠 High | Source: AWS Security Bulletins A security flaw in the AWS API MCP Server (versions 0.2.13 to 1.3.47) means that if the server fails to load its security policy on startup, it silently continues running without enforcing that policy for the remainder of the process lifetime. This creates a window where an attacker could trigger AWS API operations that the policy was intended to block or gate, bypassing controls the operator believed were in place. Crucially, IAM permissions are unaffected, but any additional guardrails provided by the MCP security policy are rendered ineffective. ...

23 July 2025 Â· ZX Cloud Security

Oracle 1,449 Patches: AI Bug Hunting Changes the Game

🟠 High | Source: The Register — Security Oracle has released a record-breaking 1,449 security patches in a single quarterly update, a volume experts are attributing in part to the growing use of AI-assisted vulnerability discovery. The sheer scale of patching required signals a structural shift in the threat landscape, where defenders must process and prioritise far more fixes than before. Security teams relying on traditional patch management cadences may find themselves perpetually behind if processes are not adapted. ...

23 July 2025 Â· ZX Cloud Security

Android Spyware, PLC Attacks & AI Prompt Injection Threats

🟠 High | Source: The Hacker News This week’s threat roundup covers a broad range of attack vectors including Android spyware disguised as legitimate apps, prompt injection via AI-processed images, malicious browser extensions enabling remote access, and attacks targeting industrial PLCs. The common thread is adversaries abusing trusted surfaces — app stores, AI pipelines, and open systems — to deliver malicious payloads. The variety and sophistication of these threats highlights how quickly attack surface is expanding across both enterprise and operational technology environments. ...

23 July 2025 Â· ZX Cloud Security

Iran-Linked Hackers Target US ICS Devices – CISA Alert

🟠 High | Source: The Register — Security Iran-linked threat actors are actively scanning and probing internet-exposed industrial control systems (ICS) across US critical infrastructure, with CISA expanding its alert beyond Rockwell Automation controllers to cover a broader range of operational technology (OT) devices. The activity suggests reconnaissance that could precede destructive attacks or sabotage against energy, water, and manufacturing sectors. This is significant because OT environments often lack robust monitoring and patching cadences, making them attractive and vulnerable targets. ...

23 July 2025 Â· ZX Cloud Security

CVE-2026-49159: Microsoft Graph Info Disclosure Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-49159 is an information disclosure vulnerability in Microsoft Graph, the API layer underpinning much of Microsoft 365 and Azure. An authenticated attacker can exploit this flaw over a network to access sensitive data they should not be able to see. Because Microsoft Graph is widely used to access emails, calendar data, user profiles, and organisational data, the potential exposure is significant. Security Architect’s Take: Review your Microsoft Graph API permissions and enforce least-privilege OAuth scopes across all registered applications and service principals; monitor Azure AD sign-in and Graph audit logs for anomalous data access patterns while Microsoft’s patch or mitigation guidance is confirmed and applied. ...

23 July 2025 Â· ZX Cloud Security

CVE-2026-54120 Microsoft Surface RCE Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-54120 is a remote code execution vulnerability in Microsoft Surface devices caused by improper input validation. An attacker who already has some level of authorised access can exploit this flaw over a network to execute arbitrary code on an affected device. This poses a significant risk in enterprise environments where Surface devices are widely deployed and potentially connected to sensitive cloud or corporate resources. ...

23 July 2025 Â· ZX Cloud Security

CVE-2026-56160: Azure Red Hat OpenShift Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A vulnerability in Azure Red Hat OpenShift (ARO) allows an attacker who already has some level of authorised access to gain higher privileges than they should be permitted, exploitable over a network. The flaw stems from improper authorisation controls within the managed OpenShift service. If exploited, an attacker could move beyond their intended access boundaries, potentially compromising cluster workloads or underlying infrastructure. Security Architect’s Take: Review RBAC configurations and least-privilege access policies across all ARO clusters, and apply any Microsoft-issued patches or mitigations immediately. Additionally, audit recent access logs for anomalous privilege usage whilst the patch is being rolled out. ...

23 July 2025 Â· ZX Cloud Security

CVE-2026-56167: Azure AI Search Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A server-side request forgery (SSRF) vulnerability in Azure AI Search allows an attacker who already has some level of authorised access to escalate their privileges over a network. This could enable them to access resources or perform actions beyond their intended permissions. The risk is particularly significant in multi-tenant or shared Azure AI Search deployments where privilege boundaries are critical. Security Architect’s Take: Review and tighten network access controls around Azure AI Search endpoints, applying private endpoints and restricting outbound network access where possible. Monitor Microsoft’s update guidance for patches or mitigations and assess whether any authorised users could abuse this to reach sensitive downstream resources. ...

23 July 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options