Adobe Acrobat Extension CVE-2026-48294 WhatsApp Data Flaw

🟠 High | Source: The Hacker News A now-patched vulnerability in the Adobe Acrobat Chrome extension, used by over 314 million people, allowed malicious websites to silently read a user’s WhatsApp Web data. Dubbed HermeticReader and tracked as CVE-2026-48294, the flaw could expose private messages and files without any interaction from the victim. The sheer scale of the extension’s install base makes this a significant supply-chain and browser security concern. Security Architect’s Take: Audit your organisation’s managed Chrome browser policies to identify unapproved or unvetted extensions with broad host permissions — Adobe Acrobat is a common default install that may not be actively reviewed. Ensure extension allowlisting policies are enforced via Chrome Enterprise and that users are on the latest patched version of the Adobe Acrobat extension. ...

22 July 2025 · ZX Cloud Security

Dophin X Stealer Targets 300+ Apps with AI Profiling

🟠 High | Source: The Register — Security A new Windows-based information stealer called Dophin X has been identified, capable of targeting over 300 applications including browsers, crypto wallets, and cloud credential stores. What makes it particularly dangerous is an integrated AI profiling module that analyses stolen data to identify high-value victims and maximise criminal returns. This represents a significant evolution in stealer malware, combining broad credential harvesting with automated victim prioritisation. ...

22 July 2025 · ZX Cloud Security

CVE-2026-29059: Windmill Path Traversal Exploited

🟠 High | Source: The Hacker News A high-severity path traversal vulnerability (CVE-2026-29059) in the open-source developer platform Windmill is being actively exploited in the wild, allowing unauthenticated attackers to read arbitrary files from the server. The flaw exists in the ‘get_log_file’ API endpoint, where unsanitised user input is concatenated directly into a file path. This means sensitive server files — including credentials, configuration, and secrets — could be exposed without any login required. ...

22 July 2025 · ZX Cloud Security

Ransomware Victims Re-Extorted After Paying Ransom

🟠 High | Source: The Register — Security A Proofpoint study reveals that over a third of ransomware victims who paid a ransom were subsequently extorted a second time by the same threat actors. In some cases, victims never recovered their files even after paying. This highlights the fundamental unreliability of paying ransoms as a recovery strategy and the growing opportunism of ransomware crews. Security Architect’s Take: Treat ransom payment as a non-strategy: architect immutable, air-gapped backups (e.g. AWS Backup Vault Lock, Azure immutable blob storage, or GCP Backup and DR with locked vaults) so recovery never depends on attacker cooperation. Pair this with a tested incident response playbook that explicitly rules out payment as a default response. ...

22 July 2025 · ZX Cloud Security

Why Modern SOCs Need Multi-Layered Detection

🟠 High | Source: The Hacker News Attackers are increasingly bypassing traditional endpoint and malware-based defences, with roughly 79% of intrusions now malware-free according to CrowdStrike’s Global Threat Report. AI-assisted threat actors are evolving faster than conventional detection tools can keep pace with. This shift means Security Operations Centres must adopt multi-layered detection strategies that go beyond signature and file-based approaches. Security Architect’s Take: Prioritise behavioural and identity-based detection controls — such as UEBA, cloud activity anomaly detection, and lateral movement monitoring — rather than relying solely on endpoint protection. Review your SOC detection coverage against MITRE ATT&CK techniques that require no malware, particularly living-off-the-land and credential-based attack chains. ...

22 July 2025 · ZX Cloud Security

Email Account Takeover: Identity Theft via MFA Code

🟠 High | Source: Schneier on Security A first-person account details how a victim lost control of their email account after being socially engineered into handing over a two-factor authentication code. The incident illustrates how a single compromised email account can cascade into full identity theft, as most online accounts rely on email for password resets and recovery. This is a stark reminder that MFA codes are as sensitive as passwords and must never be shared. ...

22 July 2025 · ZX Cloud Security

CVE-2026-56434: NGINX SSI Module Flaw on Azure

🟠 High | Source: Microsoft Security Response Center A vulnerability has been disclosed in NGINX’s ngx_http_ssi_module, tracked as CVE-2026-56434, with details published via the Microsoft Security Response Center in relation to Azure. The ngx_http_ssi_module handles Server Side Includes processing in NGINX, and flaws in this component can potentially allow attackers to manipulate web responses or cause unintended behaviour in hosted applications. This is relevant to Azure customers running NGINX-based workloads, including those using Azure Application Gateway, Azure Kubernetes Service, or self-managed NGINX deployments. ...

22 July 2025 · ZX Cloud Security

CVE-2026-42533: NGINX Map & Regex Vulnerability on Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-42533 is a vulnerability in NGINX’s Map directive and regular expression (regex) matching logic, affecting deployments within Azure environments. An attacker could potentially exploit flawed regex evaluation to bypass intended access controls or cause unexpected application behaviour. This matters because NGINX is widely used as a reverse proxy and load balancer in cloud-hosted architectures, making misconfigured or vulnerable regex rules a significant attack surface. ...

22 July 2025 · ZX Cloud Security

CVE-2026-59885: pyasn1 DoS Flaw Affects Azure

🟠 High | Source: Microsoft Security Response Center A vulnerability in the pyasn1 Python library allows an attacker to trigger excessive CPU consumption by supplying specially crafted OBJECT IDENTIFIER or RELATIVE-OID data, leading to a denial of service. The quadratic time complexity means that as input size grows, processing time grows disproportionately, making it easy to exhaust resources with relatively small payloads. This is particularly relevant for Azure services and applications that rely on pyasn1 for parsing ASN.1-encoded data, such as those handling certificates or SNMP messages. ...

22 July 2025 · ZX Cloud Security

CVE-2026-57215: RabbitMQ Reply Channel Injection Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-57215 is a vulnerability in RabbitMQ’s direct-reply-to feature, where persistent bindings can be exploited to inject unauthorised reply channels, creating ‘phantom’ queues or consumers that persist beyond their intended lifecycle. This could allow an attacker to intercept or manipulate message traffic within a RabbitMQ-backed system. Given the widespread use of RabbitMQ in Azure-hosted microservices and event-driven architectures, the potential for message interception or data leakage is significant. ...

22 July 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options