OpenSSL HollowByte Flaw: DoS via 11-Byte TLS Request

🟠 High | Source: The Hacker News A flaw in OpenSSL, dubbed HollowByte by Okta’s Red Team, allows an attacker to send an 11-byte TLS request that tricks an unpatched server into reserving up to 131 KB of memory for a message that never arrives. On Linux systems using glibc, that memory is not released until the process restarts, making repeated requests a viable denial-of-service attack. OpenSSL quietly shipped a fix in June 2025 with no CVE, no security advisory, and no changelog reference. ...

17 July 2025 · ZX Cloud Security

CVE-2026-15415: AWS HealthOmics MCP Path Traversal

🟠 High | Source: AWS Security Bulletins A path traversal vulnerability (CVE-2026-15415) in the AWS HealthOmics MCP Server allows an attacker who can influence the MCP agent to write arbitrary content outside the intended workflow bundle directory. The flaw exists in the linting tools of versions 0.0.35 and earlier. This is particularly concerning given HealthOmics is used in HIPAA-regulated clinical and research environments where file system integrity is critical. Security Architect’s Take: Upgrade aws-healthomics-mcp-server to version 0.0.36 or later immediately, particularly in any environment processing sensitive clinical or genomic data. Additionally, review MCP agent input handling to ensure untrusted or user-supplied workflow_files inputs are validated and sandboxed before processing. ...

17 July 2025 · ZX Cloud Security

CVE-2026-12283: AWS Athena Synapse Connector Flaw

🟠 High | Source: AWS Security Bulletins A vulnerability (CVE-2026-12283) in the AWS Athena Federated Query Synapse Connector allows a user with access to an Azure Synapse account to create a maliciously named table that, when queried through the Athena connector, could return unintended data. The flaw affects connector versions released between May 2022 and May 2026. This is a cross-cloud attack vector, as exploitation requires an adversarial foothold in Azure Synapse to affect queries executed via AWS Athena. ...

17 July 2025 · ZX Cloud Security

Malicious Vite npm Packages Deploy RAT via Blockchain C2

🟠 High | Source: The Hacker News Seven malicious npm packages impersonating the Vite frontend tooling ecosystem have been discovered deploying a Remote Access Trojan (RAT) via a sophisticated four-tier blockchain-based command-and-control infrastructure using the Tron network. Dubbed ViteVenom by Checkmarx, this campaign extends a previously identified threat actor technique called ChainVeil, which uses blockchain transactions to issue attacker commands in a way that is extremely difficult to block or take down. This is significant because blockchain-based C2 infrastructure is censorship-resistant, making traditional domain-takedown defences ineffective. ...

17 July 2025 · ZX Cloud Security

NadMesh Botnet Targets Exposed AI Services for AWS Keys

🟠 High | Source: The Hacker News A newly discovered Go-based botnet called NadMesh is actively scanning the internet for exposed AI services — including ComfyUI, Ollama, n8n, and Gradio — to harvest AWS keys and Kubernetes tokens. The botnet’s own operator dashboard reportedly counts over 3,800 unique AWS keys already compromised. This targets a common blind spot: AI tooling stood up quickly by development and ML teams without adequate network controls. ...

17 July 2025 · ZX Cloud Security

GoldenEyeDog Linked to DigiCert Code-Signing Breach

🟠 High | Source: The Hacker News A subgroup of the Chinese threat actor GoldenEyeDog (also known as APT-Q-27 and Dragon Breath), tracked as CylindricalCanine, has been attributed to a breach of certificate authority DigiCert in April 2026, resulting in the theft of code-signing certificates. This is significant because stolen code-signing certificates can be used to sign malicious software, making it appear legitimate and trusted by operating systems and security tools. The incident raises serious supply chain concerns for any organisation relying on DigiCert-issued certificates to verify software integrity. ...

17 July 2025 · ZX Cloud Security

CVE-2026-56159: DHCP Server RCE Vulnerability (Azure)

🟠 High | Source: Microsoft Security Response Center CVE-2026-56159 is a Remote Code Execution (RCE) vulnerability affecting the Windows DHCP Server Service, disclosed by Microsoft. If exploited, an attacker could execute arbitrary code on the affected server, potentially gaining significant control over network infrastructure. This update adds acknowledgements to the advisory and contains no new technical or patch information. Security Architect’s Take: Verify that any Windows DHCP Server instances running in Azure or hybrid environments have the relevant patch applied. This update is informational only, so if you have already addressed CVE-2026-56159, no further action is required — but use this as a prompt to audit DHCP server exposure and ensure the service is not reachable from untrusted network segments. ...

17 July 2025 · ZX Cloud Security

North Korea Hides Malware in SVG Files via Fake Coding Tests

🟠 High | Source: The Hacker News North Korean hackers linked to the ‘Contagious Interview’ campaign are hiding malware inside SVG image files using steganography, delivered via fake job postings and coding tests. Victims who run the project unknowingly execute a four-stage malware chain that steals browser credentials, cryptocurrency wallet data, and files — closely aligned with the known OtterCookie malware family. This campaign specifically targets developers and engineers, making it particularly relevant to technical staff in cloud and software organisations. ...

17 July 2025 · ZX Cloud Security

EU Forces Google to Open Android to Rival AI Assistants

🟠 High | Source: The Hacker News The European Commission has ordered Google to grant third-party AI assistants the same deep system access on Android that its own Gemini assistant enjoys — including the microphone, camera, on-screen content, always-on wake words, and the ability to control other apps. Google must implement these changes in Android 18 by 1 August 2027. While framed as a competition measure, the ruling significantly expands the attack surface available to third-party AI applications on billions of Android devices. ...

17 July 2025 · ZX Cloud Security

Android Lock Screen Bug Lets Gemini Send SMS Without PIN

🟠 High | Source: The Register — Security A bug in Android allows a specific multi-touch gesture to bypass the lock screen authentication prompt, enabling Google’s Gemini AI assistant to send SMS messages without requiring a PIN or biometric verification. The flaw means a physical attacker with access to a locked device could send arbitrary text messages, potentially impersonating the device owner. Google is actively working on a fix. Security Architect’s Take: Ensure Android devices in your organisation’s mobile fleet are updated promptly once Google releases the patch; in the interim, consider enforcing MDM policies that restrict AI assistant access from the lock screen, and review BYOD policies to assess exposure risk. ...

17 July 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options