FakeGit: 7,600 GitHub Repos Spread SmartLoader Malware

🟠 High | Source: The Hacker News Attackers have seeded nearly 7,600 malicious GitHub repositories — over 800 of which impersonate AI tools or Model Context Protocol (MCP) servers — to distribute a malware loader called SmartLoader. The campaign, dubbed FakeGit, uses cloned legitimate projects, convincing READMEs, and fake developer profiles to lure developers into downloading malicious ZIP archives. The scale and focus on AI-themed lures makes this a significant supply chain risk for development teams actively adopting AI tooling. ...

20 July 2025 Â· ZX Cloud Security

HOLLOWGRAPH: M365 Calendars Used as C2 Drop Boxes

🟠 High | Source: The Register — Security A threat campaign dubbed HOLLOWGRAPH is abusing Microsoft 365 calendar invitations to deliver and relay malware commands, with attackers embedding instructions inside appointments dated as far ahead as 2050 to evade detection. The malware uses Microsoft’s own cloud infrastructure as its command-and-control channel, making malicious traffic extremely difficult to distinguish from legitimate Microsoft 365 communications. This living-off-the-land approach significantly reduces the effectiveness of traditional network-based detection controls. ...

20 July 2025 Â· ZX Cloud Security

HollowGraph Malware Abuses Microsoft 365 Calendar C2

🟠 High | Source: The Hacker News HollowGraph is an espionage implant that abuses Microsoft 365 calendar events — dated to 2050 to avoid attention — to receive operator commands and exfiltrate stolen files as attachments. It communicates exclusively via the legitimate Microsoft Graph API, making malicious traffic extremely difficult to distinguish from normal Microsoft 365 activity. The technique was uncovered by Group-IB and represents a sophisticated living-off-the-land approach that sidesteps many traditional network-based detections. ...

20 July 2025 Â· ZX Cloud Security

CVE-2024-35248 Dynamics 365 Business Central EoP

🟠 High | Source: Microsoft Security Response Center CVE-2024-35248 is an elevation of privilege vulnerability in Microsoft Dynamics 365 Business Central, a cloud-based ERP platform. If exploited, it could allow an attacker to gain higher-level permissions than intended within the application. Microsoft has issued an informational update revising the affected build numbers, with no change to the underlying guidance. Security Architect’s Take: Verify that your Dynamics 365 Business Central environments are running patched build versions as listed in the updated advisory, and confirm your software update policies are pulling the latest release. No additional remediation steps are indicated beyond applying the previously released fix. ...

20 July 2025 Â· ZX Cloud Security

CVE-2026-47304: .NET Security Feature Bypass Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-47304 is a security feature bypass vulnerability in Microsoft .NET, which could allow an attacker to circumvent built-in security controls within .NET applications. Microsoft has issued an updated advisory with revised product information in the Software Update table, though the vulnerability details themselves remain unchanged. Organisations running .NET workloads, including those hosted on Azure, should review the updated guidance to ensure the correct patches are applied. ...

20 July 2025 Â· ZX Cloud Security

CVE-2026-50525: .NET Denial of Service Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50525 is a Denial of Service vulnerability affecting .NET, which is widely used across Azure-hosted applications and services. An attacker exploiting this flaw could cause affected .NET applications to become unresponsive or crash, disrupting availability. Microsoft has issued an informational update to the affected software table, indicating no change to the underlying vulnerability details or patch status. Security Architect’s Take: Review your Azure and on-premises workloads for exposure to the affected .NET versions and ensure patching is applied promptly; pay particular attention to internet-facing services or APIs built on .NET, as these present the highest availability risk if exploited. ...

20 July 2025 Â· ZX Cloud Security

CVE-2026-50646: .NET Framework RCE Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50646 is a Remote Code Execution vulnerability affecting .NET Framework, with Microsoft issuing an informational update to product details in the Software Update table. No new patches or exploitability changes have been announced at this time. Despite the update being administrative in nature, RCE vulnerabilities in .NET Framework carry significant risk given the framework’s widespread use across Windows-based Azure workloads. Security Architect’s Take: Verify that all .NET Framework versions deployed across your Azure-hosted Windows VMs and App Services are covered by the latest patching cycle, and monitor the MSRC advisory page for any escalation beyond this informational update. ...

20 July 2025 Â· ZX Cloud Security

CVE-2026-50648: .NET Framework DoS Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50648 is a Denial of Service vulnerability affecting the .NET Framework, with Microsoft issuing an updated advisory to reflect revised product information in the Software Update table. The change is informational only and does not alter the vulnerability’s technical details or severity rating. Organisations running .NET Framework workloads on Azure or on-premises should ensure they have applied the relevant patches from the original advisory. ...

20 July 2025 Â· ZX Cloud Security

CVE-2026-50649: .NET Remote Code Execution Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-50649 is a remote code execution vulnerability affecting .NET, Microsoft’s widely used development framework. If exploited, an attacker could execute arbitrary code on a vulnerable system, potentially gaining full control. This update is an informational revision to the Software Update table and does not introduce new patches or change severity ratings. Security Architect’s Take: Verify that all .NET runtimes and SDKs across your Azure-hosted workloads, CI/CD pipelines, and containerised environments are patched to the versions listed in the updated Software Update table. Prioritise internet-facing services and those processing untrusted input. ...

20 July 2025 Â· ZX Cloud Security

CVE-2026-50650 .NET Framework Privilege Escalation

🟠 High | Source: Microsoft Security Response Center CVE-2026-50650 is an elevation of privilege vulnerability affecting the .NET Framework, meaning an attacker could potentially gain higher-level permissions than intended on a vulnerable system. Microsoft has issued an update to the Software Update table, described as an informational change with no new technical findings. Organisations running .NET Framework workloads — including those hosted on Azure — should ensure applicable patches are applied. ...

20 July 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options