Kratos Phishing Kit Dismantled: M365 MFA Bypass

🟠 High | Source: The Hacker News German and US law enforcement have dismantled the infrastructure behind Kratos, a widely-used phishing kit designed to steal Microsoft 365 session tokens and bypass multi-factor authentication. Indonesian authorities have arrested the individual alleged to have built and operated the service. The takedown is significant because adversary-in-the-middle phishing kits of this type represent one of the most effective methods for circumventing MFA protections that organisations rely upon. ...

22 July 2025 · ZX Cloud Security

Trojanised NuGet Package Targets Digitain Betting Platform

🟠 High | Source: The Hacker News A malicious NuGet package named ‘Newtonsoftt.Json.Net’ has been discovered masquerading as the widely-used Newtonsoft.Json library through typosquatting. Unlike typical supply chain attacks targeting credential theft, this trojanised fork embeds code designed to manipulate live game results on the Digitain sports betting platform. Seven versions of the package were published, making it a persistent and targeted threat. Security Architect’s Take: Audit your organisation’s NuGet package references immediately for typosquatted dependencies, paying particular attention to high-usage libraries like Newtonsoft.Json. Enforce private package feeds with allowlisting policies and integrate software composition analysis (SCA) tooling into your CI/CD pipelines to flag unverified or suspicious package names before build. ...

22 July 2025 · ZX Cloud Security

Azure DevOps MCP Prompt Injection Hijacks AI PR Agents

🟠 High | Source: The Hacker News A prompt injection vulnerability in Microsoft’s official Azure DevOps MCP (Model Context Protocol) server allows an attacker to embed hidden malicious instructions within a pull request comment or description. When an AI coding agent reviews that PR, it can be manipulated into accessing repositories and resources beyond its intended scope, silently exfiltrating data. This matters because AI-assisted code review is rapidly becoming standard practice, and the attack requires no elevated privileges from the attacker — just the ability to post a PR comment. ...

22 July 2025 · ZX Cloud Security

CVE-2026-16317 & CVE-2026-16318: AWS s2n-tls Flaws

🟠 High | Source: AWS Security Bulletins Two vulnerabilities have been identified in s2n-tls, AWS’s open-source TLS/SSL library. CVE-2026-16317 allows an active man-in-the-middle attacker to silently drop TLS 1.3 application data records without either endpoint detecting the tampering, due to incomplete AEAD authentication coverage. CVE-2026-16318 causes a memory leak in QUIC-enabled TLS 1.3 connections during HelloRetryRequest handshakes, which could be exploited to exhaust server memory over time. Security Architect’s Take: Audit your use of s2n-tls across services and dependencies — including any AWS-managed services leveraging it — and apply the patched version immediately; prioritise internet-facing TLS 1.3 endpoints and QUIC-enabled workloads as these are directly exploitable by an on-path attacker or through repeated handshake triggering. ...

21 July 2025 · ZX Cloud Security

CVE-2026-15957: smithy-rs DoS via Recursive Deserialisation

🟠 High | Source: AWS Security Bulletins A vulnerability (CVE-2026-15957) in the smithy-rs Rust code generation framework allows an unauthenticated attacker to crash any service built with it by sending a small HTTP request containing deeply nested data structures. The flaw affects JSON, CBOR, and XML deserialisers generated by smithy-rs, triggering a stack overflow and process abort. Any application using aws-sdk-rust crates prior to release-2026-06-0 is exposed, including custom Smithy-generated servers. ...

21 July 2025 · ZX Cloud Security

AWS Kiro Prompt Injection Flaw Enables RCE

🟠 High | Source: The Hacker News A prompt injection vulnerability in AWS Kiro, an agentic AI coding IDE, allowed a malicious web page to manipulate the tool into rewriting its own configuration file and executing arbitrary code on a developer’s machine. The attack required no user interaction beyond asking Kiro to summarise a page, and existing approval mechanisms provided no protection. AWS has patched the flaw, though no CVE has been assigned. ...

21 July 2025 · ZX Cloud Security

CVE-2026-50462 WinSock EoP Vulnerability | Azure Windows

🟠 High | Source: Microsoft Security Response Center CVE-2026-50462 is an elevation of privilege vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys), a core Windows networking component. If exploited, an attacker with local access could gain SYSTEM-level privileges on an affected machine. This update is an acknowledgement change only and carries no new technical details or patch changes. Security Architect’s Take: No immediate action is required as this update is purely administrative. However, cloud security architects running Windows-based workloads on Azure VMs or hybrid environments should confirm that the original patch for CVE-2026-50462 has been applied across all Windows endpoints and server fleets via Azure Update Manager or equivalent patch management tooling. ...

21 July 2025 · ZX Cloud Security

CVE-2026-58640 Windows NTFS RCE Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-58640 is a Remote Code Execution vulnerability affecting Windows NTFS, the default file system used across Windows Server environments including those underpinning Azure infrastructure. This update is administrative only — an acknowledgement credit has been amended — and introduces no new technical or patch information. No immediate action is required as a result of this specific update. Security Architect’s Take: No new mitigations or patches accompany this update, so no immediate action is required. However, if CVE-2026-58640 is not already on your radar, validate that affected Windows Server instances — including Azure VMs and any hybrid on-premises hosts — have had the original patch applied and are reflected in your vulnerability management tooling. ...

21 July 2025 · ZX Cloud Security

Suno AI Music Platform Breach: 55M Users Exposed

🟠 High | Source: The Register — Security AI music generation platform Suno has suffered a data breach affecting approximately 55 million user accounts, with Have I Been Pwned confirming the scale for the first time. The incident exposes the risks inherent in rapidly scaling consumer AI platforms that may prioritise growth over robust security controls. The breach highlights ongoing concerns about third-party SaaS platforms handling large volumes of personal data without adequate protections. ...

21 July 2025 · ZX Cloud Security

Android AI Agents Vulnerable to Invisible Prompt Injection

🟠 High | Source: The Hacker News Researchers have demonstrated that malicious Android apps can embed invisible text instructions into the screen to manipulate AI agents controlling a mobile device — a technique known as indirect prompt injection. By exploiting common Android permissions such as drawing over windows and accessing shared storage, an attacker can chain these injections to execute arbitrary commands on the host PC driving the agent. The attack was validated across five open-source mobile agent frameworks, highlighting a systemic vulnerability in how AI agents process untrusted on-screen content. ...

21 July 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options