Synthetic Identity Fraud Targeting Machine Identities

🟠 High | Source: The Hacker News Synthetic identity fraud — where attackers fabricate identities by blending real and fictitious data — is increasingly being applied to machine identities such as service accounts, API keys, and non-human identities (NHIs). Because no real person is being impersonated, traditional fraud detection signals are absent, making these fraudulent identities far harder to detect. As organisations scale cloud workloads, the attack surface for synthetic machine identity abuse is growing rapidly. ...

23 July 2025 · ZX Cloud Security

GitHub Actions Abused to Attack cPanel & WHM Servers

🟠 High | Source: The Hacker News Attackers compromised GitHub repositories belonging to a legitimate PHP developer to distribute malicious Packagist packages that weaponise GitHub Actions runners against cPanel and WHM hosting control panel instances. The campaign involved at least 10 tampered development-version packages published over a two-day window in July, effectively turning trusted CI/CD infrastructure into a distributed attack platform. This matters because it demonstrates how supply chain compromise via package registries can be used to pivot into web hosting infrastructure at scale. ...

23 July 2025 · ZX Cloud Security

CVE-2026-64600 RefluXFS Linux Root Flaw on RHEL & AWS

🟠 High | Source: The Hacker News A nine-year-old Linux kernel vulnerability, CVE-2026-64600 (RefluXFS), allows an unprivileged local user to overwrite root-owned files on XFS filesystems and gain persistent root access. Default installations of Red Hat Enterprise Linux, Fedora Server, and Amazon Linux are potentially exploitable. Discovered and demonstrated by Qualys, the flaw poses a serious privilege escalation risk on widely deployed enterprise and cloud Linux environments. Security Architect’s Take: Prioritise patching RHEL, its derivatives, and Amazon Linux instances immediately, particularly any multi-tenant or shared environments where unprivileged local access exists — such as developer VMs, CI/CD build agents, or bastion hosts. In the interim, audit workloads using XFS filesystems and review whether untrusted local users have any interactive access to affected systems. ...

23 July 2025 · ZX Cloud Security

CVE-2026-55973: Azure DNS Stack Buffer Overflow Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-55973 is a stack buffer overflow vulnerability triggered by the DNS configuration option ‘dns-error-reporting: yes’ in an Azure-related component. Stack buffer overflows can allow attackers to overwrite memory, potentially leading to arbitrary code execution or service crashes. This is particularly concerning in DNS infrastructure due to its foundational role in network communications. Security Architect’s Take: Audit your DNS server configurations and disable or avoid ‘dns-error-reporting: yes’ until a patch is applied. Prioritise patching any Azure-hosted or on-premises DNS services exposed to untrusted networks, and review network segmentation to limit blast radius if exploitation occurs. ...

23 July 2025 · ZX Cloud Security

CVE-2026-53910: GNU diffutils Buffer Overflow in Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-53910 is a heap-based buffer overflow vulnerability in GNU diffutils, a widely used open-source utility for comparing files. Microsoft has published an advisory via the MSRC, indicating relevance to Azure environments where diffutils may be present in Linux-based workloads or platform components. Heap-based buffer overflows can potentially be exploited to execute arbitrary code or crash affected processes, making prompt attention warranted. Security Architect’s Take: Audit Linux-based Azure VMs, containers, and any platform images that bundle GNU diffutils, and apply available OS or package manager patches immediately. Additionally, review any CI/CD pipelines or build environments that incorporate diffutils, as supply-chain exposure through tooling is a common attack vector. ...

23 July 2025 · ZX Cloud Security

CVE-2026-63136: Elasticsearch DoS on Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-63136 is a vulnerability in Elasticsearch that allows uncontrolled resource consumption, which can be exploited to cause a Denial of Service (DoS). This affects Azure environments where Elasticsearch is deployed, potentially rendering search and analytics services unavailable. An attacker able to send crafted requests could exhaust system resources, disrupting dependent applications and workloads. Security Architect’s Take: Review any Azure-hosted Elasticsearch deployments and apply available patches or mitigations from Microsoft and Elastic immediately. Additionally, implement rate limiting and network-level controls to restrict access to Elasticsearch endpoints to trusted sources only, reducing the attack surface. ...

23 July 2025 · ZX Cloud Security

CVE-2026-63140: Elasticsearch DoS Flaw on Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-63140 is a reachable assertion vulnerability in Elasticsearch that can be triggered to cause a Denial of Service (DoS), crashing or making the service unavailable. This affects Azure environments where Elasticsearch is deployed, potentially disrupting search and data retrieval capabilities for dependent applications. Although it does not allow data theft or code execution, service availability impact can be significant in production systems. Security Architect’s Take: Review any Azure-hosted Elasticsearch deployments and apply the relevant patch or mitigation guidance from Microsoft and Elastic as soon as it is available; consider implementing network-level controls to restrict who can send queries to Elasticsearch endpoints, reducing the attack surface until patching is complete. ...

23 July 2025 · ZX Cloud Security

CVE-2026-56145: Elasticsearch DoS Flaw on Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-56145 is a vulnerability in Elasticsearch that allows an attacker to consume excessive system resources, potentially causing a Denial of Service (DoS) condition. This affects Azure-hosted environments where Elasticsearch is in use. If exploited, legitimate users and dependent services could be rendered unavailable, impacting business continuity. Security Architect’s Take: Identify all Azure workloads running Elasticsearch and apply any available patches or mitigations from both Microsoft and Elastic immediately. In the interim, consider enforcing strict network access controls and rate limiting to reduce the attack surface for unauthenticated or low-privilege resource exhaustion attempts. ...

23 July 2025 · ZX Cloud Security

Social Engineering Breach Exposes Private Medical Records

🟠 High | Source: The Register — Security A man gained unauthorised access to private medical records by using social engineering — specifically, talking disparagingly about a doctor to manipulate staff into granting him entry to a records room. No technical exploit or stolen credentials were required; human trust was the vulnerability. This incident highlights how physical and social engineering attacks remain a significant threat to sensitive data, even where digital security controls exist. ...

23 July 2025 · ZX Cloud Security

CVE-2026-8933: Ubuntu snap-confine Root Escalation Flaw

🟠 High | Source: The Hacker News A high-severity local privilege escalation vulnerability (CVE-2026-8933) in snap-confine allows an unprivileged local user to gain full root access on default Ubuntu Desktop installations versions 24.04, 25.10, and 26.04. The flaw requires no special permissions to trigger, making it particularly dangerous on multi-user systems or cloud VMs running Ubuntu Desktop. Any organisation running affected Ubuntu versions should treat this as an urgent patching priority. ...

22 July 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options