INC Ransomware Exploiting SonicWall SMA 1000 Flaws

🔴 Critical | Source: The Hacker News The INC Ransomware group has been identified as the primary threat actor actively exploiting recently disclosed vulnerabilities in SonicWall SMA 1000 series VPN appliances. Activity has accelerated significantly since August 2026, with multiple victims listed on the group’s data leak site. This is particularly concerning as VPN appliances sit at the network perimeter and their compromise can provide attackers with broad access to internal and cloud-connected environments. ...

3 August 2026 · ZX Cloud Security

CVE-2026-18577: N-central Auth Bypass Exploited

🔴 Critical | Source: The Hacker News Attackers exploited an authentication bypass vulnerability (CVE-2026-18577) in N-able’s N-central remote monitoring and management platform to gain full administrative control of affected servers. Because N-central is used to manage customer endpoints at scale, compromised servers provide attackers with a direct path into the networks of all downstream managed clients. N-able’s initial patch was insufficient; build 2026.3.1.7, released 2 August, is the first fully remediated version. ...

3 August 2026 · ZX Cloud Security

CVE-2026-18577: N-able N-central Auth Bypass

🔴 Critical | Source: CISA Known Exploited Vulnerabilities A critical authentication bypass vulnerability in N-able N-central allows attackers to circumvent login controls and take over accounts without valid credentials. This flaw is particularly concerning because it represents an incomplete fix for a previously patched vulnerability (CVE-2026-18556), meaning organisations that believed they were protected may still be exposed. N-central is widely used by managed service providers to remotely manage client endpoints, so a compromise could have cascading effects across multiple downstream organisations. ...

3 August 2026 · ZX Cloud Security

Coldcard Wallet PRNG Flaw Behind $70M Bitcoin Theft

🔴 Critical | Source: The Hacker News A firmware bug introduced into Coldcard hardware wallets in March 2021 routed Bitcoin seed generation through a deterministic software PRNG rather than a true hardware random number generator, making private keys predictable. An attacker exploited this to sweep 1,196 Bitcoin addresses in just 41 minutes on 30 July, stealing approximately $70.2 million worth of BTC. The incident highlights the critical dependency on entropy quality in cryptographic key generation, even within dedicated hardware security devices. ...

1 August 2026 · ZX Cloud Security

Adobe Campaign Classic CVE-2026-48449 CVSS 10.0 RCE Flaw

🔴 Critical | Source: The Hacker News Adobe has patched a maximum-severity (CVSS 10.0) vulnerability in Campaign Classic, its enterprise marketing automation platform, tracked as CVE-2026-48449. The flaw stems from incorrect authorisation and can lead to arbitrary code execution without any user interaction, meaning an attacker could potentially compromise a server remotely with no victim involvement. Given the zero-interaction requirement and perfect CVSS score, this represents an extremely serious risk for organisations running ACC. ...

1 August 2026 · ZX Cloud Security

CVE-2026-18420: RCE in OpenSearch Dashboards TSVB

🔴 Critical | Source: AWS Security Bulletins A remote code execution vulnerability has been identified in the TSVB (Time Series Visual Builder) plugin within OpenSearch Dashboards, tracked as CVE-2026-18420. The flaw stems from prototype pollution, a JavaScript attack technique that allows an attacker to manipulate an application’s core objects and potentially execute arbitrary code on the server. This is significant for AWS customers running Amazon OpenSearch Service with Dashboards enabled, as exploitation could lead to full compromise of the Dashboards environment. ...

31 July 2026 · ZX Cloud Security

CVE-2026-66803: Azure Cosmos DB RCE Vulnerability

🔴 Critical | Source: Microsoft Security Response Center A vulnerability in Azure Cosmos DB allows an unauthenticated attacker to remotely execute arbitrary code over a network without requiring any user interaction or elevated privileges. The flaw stems from improper access control within the service. This is particularly serious given Cosmos DB’s widespread use as a managed database backend in enterprise and cloud-native applications. Security Architect’s Take: Review all Cosmos DB instances for exposure to public or untrusted networks and apply any available Microsoft patches or mitigations immediately. Consider restricting Cosmos DB access to private endpoints and virtual network service endpoints while awaiting a full fix, and monitor for anomalous activity in Azure Monitor and Defender for Cloud. ...

30 July 2026 · ZX Cloud Security

Azure Cosmos DB CosmosEscape Flaw: Cross-Tenant Risk

🔴 Critical | Source: The Hacker News A now-patched vulnerability in Azure Cosmos DB allowed an attacker to escape the Gremlin query sandbox and gain full read/write access to databases belonging to other tenants on the same platform. Discovered by Wiz and dubbed CosmosEscape, the exploit chain started with a specially crafted Gremlin query on an attacker-controlled database, ultimately yielding a platform-wide key. This is significant because a single exploit could have compromised data across every customer using the affected service. ...

30 July 2026 · ZX Cloud Security

North Korea Hijacked npm debug & chalk Packages

🔴 Critical | Source: The Hacker News North Korean threat actor Sapphire Sleet has been attributed by Amazon to the September 2025 hijacking of the widely used npm packages debug and chalk, which together account for over 2 billion weekly downloads. A maintainer was phished via a lookalike npm domain, allowing attackers to push a wallet-draining script into at least 18 downstream packages. The scale of the supply chain compromise makes this one of the most significant npm incidents on record. ...

30 July 2026 · ZX Cloud Security

CVE-2026-66066: Critical Rails File Read Flaw

🔴 Critical | Source: The Hacker News A critical vulnerability (CVE-2026-66066, CVSS 9.5) in Ruby on Rails’ Active Storage component allows unauthenticated attackers to read arbitrary files from the server by uploading specially crafted images. Sensitive data exposed includes secret keys, master keys, database credentials, and cloud storage secrets. Rails has released patches and immediate upgrade is strongly advised. Security Architect’s Take: Audit all Rails applications using Active Storage and apply the vendor patch immediately; in the interim, consider blocking image upload endpoints at the WAF or API gateway layer and rotate any potentially exposed credentials — including cloud storage keys and database passwords — on affected systems. ...

29 July 2026 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options