CVE-2026-56191: Exchange Online Tampering Flaw

🟠 High | Source: Microsoft Security Response Center A vulnerability in Microsoft Exchange Online allows an unauthenticated attacker to tamper with data or functionality over a network due to improper authentication controls. This is a remotely exploitable flaw requiring no user interaction or prior access, making it particularly concerning for organisations relying on Exchange Online for business communications. If exploited, an attacker could manipulate email data, settings, or related services without legitimate credentials. ...

23 July 2025 · ZX Cloud Security

CVE-2026-57106 Azure Data Quality SSRF Privilege Escalation

🟠 High | Source: Microsoft Security Response Center CVE-2026-57106 is a server-side request forgery (SSRF) vulnerability in Microsoft Azure Data Quality that allows an unauthenticated attacker to elevate their privileges over a network. SSRF flaws can enable attackers to make requests on behalf of the server, potentially accessing internal resources or cloud metadata endpoints. The unauthenticated nature of this exploit significantly raises the risk, as no prior access is required. Security Architect’s Take: Review network access controls to restrict exposure of Azure Data Quality endpoints, particularly from untrusted or public networks, and apply Microsoft’s patch immediately. Audit logs for unusual outbound requests from Data Quality services that may indicate prior exploitation. ...

23 July 2025 · ZX Cloud Security

CVE-2026-58275: Azure DNS Privilege Escalation Flaw

🟠 High | Source: Microsoft Security Response Center A missing authorisation flaw in Azure DNS allows an unauthenticated attacker to elevate their privileges over a network without requiring any user interaction. This type of vulnerability is particularly dangerous because it can be exploited remotely, potentially allowing attackers to gain elevated control over DNS-related resources within an Azure environment. DNS is a foundational service, so compromise can have wide-reaching consequences including traffic interception and service disruption. ...

23 July 2025 · ZX Cloud Security

CVE-2026-58630: Azure App Service Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A vulnerability in Azure App Service on Azure Stack Hub allows an attacker with network access to gain elevated privileges without proper authorisation. The flaw stems from improper access controls, meaning an unauthenticated attacker could potentially take actions beyond their intended permissions. Organisations running Azure App Service on Azure Stack Hub should treat this as a priority remediation given the network-accessible attack vector. ...

23 July 2025 · ZX Cloud Security

CVE-2026-62835: Azure Online Services Info Disclosure

🟠 High | Source: Microsoft Security Response Center CVE-2026-62835 is an improper authorisation vulnerability in Microsoft Online Services that allows an unauthenticated attacker to access information they should not be able to see, exploitable remotely over a network. The flaw stems from insufficient access controls, meaning no credentials are required to trigger it. This makes it a meaningful risk for organisations relying on affected Azure-connected online services to protect sensitive data. ...

23 July 2025 · ZX Cloud Security

Claude Cowork VM Sandbox Escape Hits 500k Mac Users

🟠 High | Source: The Hacker News A sandbox escape vulnerability has been discovered in Anthropic’s Claude Cowork desktop application, allowing an AI agent to break out of its Linux virtual machine and read or write files anywhere on the host macOS system. The flaw affects approximately 500,000 macOS users and means a compromised or manipulated AI agent could access sensitive files far beyond its intended boundaries. This is significant because it demonstrates that AI agent sandboxing is not yet a reliable security boundary. ...

23 July 2025 · ZX Cloud Security

Chaos Ransomware msaRAT Routes C2 via Headless Chrome

🟠 High | Source: The Hacker News The Chaos ransomware group has deployed a Rust-based implant called msaRAT that routes all command-and-control traffic through the victim’s own browser (Chrome or Edge running in headless mode), communicating only on localhost to evade network detection. Cisco Talos discovered the implant on a compromised Windows host, where it was staged ahead of the ransomware encryptor being deployed. This technique is significant because it abuses trusted, signed browser processes to blend C2 traffic into normal web activity, making it extremely difficult to detect with conventional network monitoring. ...

23 July 2025 · ZX Cloud Security

ChatGPT Flaw Enables Rogue AI Agent via Single Link

🟠 High | Source: The Register — Security Researchers discovered a flaw in OpenAI’s ChatGPT that could allow a malicious link to deploy a rogue AI agent within a corporate environment, inheriting the victim’s access and permissions. Once triggered, the agent could operate autonomously — exfiltrating data, sending messages, or performing actions on behalf of the compromised user. This represents a novel prompt injection attack vector that bypasses traditional security controls by exploiting trusted AI tooling. ...

23 July 2025 · ZX Cloud Security

JadeProx TriBack Loader: Alibaba Cloud APT Attack

🟠 High | Source: The Hacker News A China-linked threat actor tracked as JadeProx has been targeting government, healthcare, and education organisations across Asia and Latin America using a newly discovered Windows malware loader called TriBack Loader. The operation was uncovered after Group-IB found an exposed Alibaba Cloud server in Singapore containing infrastructure and tooling linked to the campaign. The discovery highlights ongoing state-aligned espionage activity leveraging cloud infrastructure for staging and command-and-control. ...

23 July 2025 · ZX Cloud Security

Stadler Rail Refuses $12.3M Ransom After Supply Chain Breach

🟠 High | Source: The Register — Security Swiss rail manufacturer Stadler has refused to pay a $12.3 million ransom demand from the Everest ransomware group after attackers exfiltrated sensitive technical data via a third-party supplier platform. The incident highlights the persistent risk of supply chain entry points, where a compromised vendor portal becomes the attack vector into a well-defended primary target. Stadler’s refusal to pay is notable and reflects growing industry consensus that paying ransoms rarely guarantees data deletion or prevents further extortion. ...

23 July 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options