WordPress RCE, SonicWall & SharePoint 0-Days: Weekly Recap

🟠 High | Source: The Hacker News This weekly roundup covers multiple active threats including a WordPress remote code execution flaw, SonicWall zero-days, SharePoint zero-day exploitation, and attacks targeting AI services. Several vulnerabilities were being exploited in the wild before patches were available, with attack paths ranging from exposed systems to malicious use of legitimate public code. Security Architect’s Take: Prioritise patching internet-facing assets immediately — SonicWall appliances, SharePoint servers, and WordPress instances should be audited for the specific flaws referenced. Review AI service API key exposure and ensure edge security appliances are not running outdated firmware, as zero-days in perimeter devices directly undermine cloud environment access controls. ...

20 July 2025 · ZX Cloud Security

Russia Hijacks IP Cameras to Spy on NATO Military Logistics

🟠 High | Source: The Hacker News Russian intelligence services are systematically compromising internet-connected IP security cameras across NATO countries and Ukraine to monitor military logistics, including weapons convoys and troop movements. The campaign was publicly disclosed in a joint advisory by Dutch civilian and military intelligence agencies (AIVD and MIVD) on 10 July. The operation represents a low-cost, high-value intelligence collection method exploiting poorly secured consumer and commercial IoT devices. ...

20 July 2025 · ZX Cloud Security

AI & Exposure Windows: Mythos Vulnerability Risk

🟠 High | Source: The Hacker News This article examines how Anthropic’s Mythos AI model, revealed in April, is reshaping vulnerability management by dramatically accelerating CVE discovery. The core concern shifts from raw volume of new vulnerabilities to the exposure window — the time between a flaw being discoverable by AI and it being remediated by defenders. Organisations that cannot shrink this window face significantly elevated risk, regardless of whether their overall security programme is mature. ...

20 July 2025 · ZX Cloud Security

CVE-2026-14266: 7-Zip XZ Archive RCE Flaw

🟠 High | Source: The Hacker News A heap-based buffer overflow in 7-Zip (CVE-2026-14266) allows an attacker to execute arbitrary code on a victim’s machine simply by getting them to open a specially crafted XZ archive. The flaw affects how 7-Zip processes XZ chunked data and was publicly detailed by Trend Micro’s Zero Day Initiative on 15 July 2026. A patched version, 7-Zip 26.02, was released on 25 June 2026. Security Architect’s Take: Ensure 7-Zip is updated to version 26.02 or later across all endpoints, build pipelines, and cloud-hosted systems — particularly CI/CD runners and file-processing workloads that may handle untrusted archives. Consider blocking or sandboxing extraction of XZ archives at the perimeter until patching is confirmed complete. ...

20 July 2025 · ZX Cloud Security

CVE-2026-63815: Azure Linux f2fs Kernel Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-63815 is a Linux kernel vulnerability in the f2fs (Flash-Friendly File System) driver, where the inline xattr size field for certain inodes is not properly bounded. This can lead to out-of-bounds memory access, potentially enabling privilege escalation or system instability. It affects Azure Linux-based virtual machines and container workloads running kernels with the vulnerable f2fs implementation. Security Architect’s Take: Review whether your Azure Linux VMs or AKS node pools use kernels with f2fs support enabled, and apply Microsoft’s patched kernel updates promptly. If f2fs is not required in your environment, consider disabling the module as a defence-in-depth measure. ...

20 July 2025 · ZX Cloud Security

Hugging Face Breached by Autonomous AI Agent

🟠 High | Source: The Hacker News Hugging Face, the world’s largest AI model repository, suffered a breach carried out by an autonomous AI agent system, resulting in unauthorised access to internal datasets and credentials. The incident is notable both for the sensitivity of the platform — which hosts models used across countless production AI pipelines — and for the method of attack, marking one of the first publicly confirmed cases of an AI agent being used offensively at scale. Credential exposure and potential dataset tampering represent significant downstream supply chain risks for organisations that consume models or datasets from the platform. ...

20 July 2025 · ZX Cloud Security

SleeperGem: Malicious RubyGems Supply Chain Attack

🟠 High | Source: The Hacker News Three malicious RubyGems packages, part of a campaign dubbed SleeperGem, were published to the RubyGems registry with the intent to compromise developer machines and deliver additional malicious payloads. The packages impersonate legitimate tools — including a convincing clone of the popular Git Credential Manager — making them likely to be installed by unsuspecting Ruby developers. Supply chain attacks targeting package registries pose a broad risk as a single compromised dependency can affect many downstream projects and CI/CD pipelines. ...

20 July 2025 · ZX Cloud Security

AI Agent Integrations: Expanding Cloud Attack Surface

🟠 High | Source: The Register — Security Connecting AI agents to external services — APIs, databases, SaaS tools — dramatically expands the attack surface, as each integration becomes a potential entry point for prompt injection, data exfiltration, or lateral movement. Unlike traditional software integrations, AI agents can interpret and act on malicious instructions embedded in external content, making the consequences harder to predict and contain. This represents a structural shift in risk that most organisations have not yet accounted for in their threat models. ...

19 July 2025 · ZX Cloud Security

UAC-0145 ClickFix CAPTCHA Malware Targets Ukraine

🟠 High | Source: The Hacker News Russian state-sponsored group UAC-0145, a sub-cluster of the GRU-linked Sandworm unit, is using fake CAPTCHA prompts (the ‘ClickFix’ technique) to trick Ukrainian users into manually executing malware on their own machines. The attack results in data-stealing malware being installed without requiring any traditional exploit. This matters because the social engineering approach bypasses many technical controls by making the victim an unwitting participant in their own compromise. ...

19 July 2025 · ZX Cloud Security

CVE-2026-50012: Squid Memory Corruption Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50012 is a memory corruption vulnerability in Squid, a widely used open-source web proxy cache, specifically affecting how it processes cache digest replies. Memory corruption flaws of this nature can potentially be exploited to crash the service or, in more severe cases, execute arbitrary code. This advisory has been published by Microsoft, suggesting relevance to Azure environments where Squid may be deployed as part of network or proxy infrastructure. ...

18 July 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options