CVE-2026-15711: libsoup WebSocket DoS on Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-15711 is a denial-of-service vulnerability in libsoup, an HTTP client/server library used in Linux-based environments, affecting its WebSocket implementation. An attacker can send an oversized WebSocket control frame that violates protocol rules, causing the connection to crash or become unresponsive. This matters because libsoup is widely used in applications running on Azure and Linux-based cloud workloads, meaning exposed services could be taken offline without authentication. ...

17 July 2025 Â· ZX Cloud Security

CVE-2026-53366: Azure Linux Kernel IPv4 Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-53366 addresses a flaw in the Linux kernel’s IPv4 networking stack, specifically in how memory fragmentation gaps (fraggap) are handled during paged memory allocation for network packets. This vulnerability affects Azure infrastructure running Linux-based workloads and could potentially be exploited to cause instability or memory corruption. Microsoft has published this advisory through the MSRC, indicating it warrants attention for Azure-hosted Linux environments. Security Architect’s Take: Review your Azure Linux VM and container workloads and ensure OS and kernel patches are applied promptly once available from your distribution vendor; prioritise internet-facing or multi-tenant workloads where network packet handling vulnerabilities carry the highest risk. ...

17 July 2025 Â· ZX Cloud Security

CVE-2026-48863: Libsolv Buffer Overflow on Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-48863 is a stack-based buffer overflow vulnerability in libsolv, an open-source library used for package dependency resolution. The flaw exists in the EdDSA PGP signature verification routine and can be exploited to cause a denial of service. This matters because libsolv is widely used across Linux-based environments, including containerised workloads and Azure services that rely on package management. Security Architect’s Take: Identify any Azure-hosted workloads, containers, or pipelines that use libsolv for package resolution and ensure the patched version is deployed promptly; also review container base images in your registries for the vulnerable library and trigger rebuilds as part of your standard vulnerability management process. ...

17 July 2025 Â· ZX Cloud Security

Open-Weight AI Model Poisoning for Under $100

🟠 High | Source: The Register — Security A researcher has demonstrated that open-weight AI models can be poisoned — subtly manipulated to produce malicious or misleading outputs — for less than $100. Unlike closed models hosted by major providers, open-weight models are distributed as downloadable weights with no central verification mechanism, meaning users have no reliable way to confirm a model hasn’t been tampered with. This highlights a growing supply chain risk for organisations deploying open-weight models in production environments. ...

16 July 2025 Â· ZX Cloud Security

CVE-2026-15895: AWS jsii-diff Command Injection Flaw

🟠 High | Source: AWS Security Bulletins A command injection vulnerability (CVE-2026-15895) has been identified in jsii-diff, a CLI tool used to compare API differences between AWS jsii assemblies. Specially crafted command line arguments can be used to execute arbitrary shell commands on the host system. All versions prior to 1.131.0 are affected. Security Architect’s Take: Audit your CI/CD pipelines and developer toolchains for use of jsii-diff and upgrade to version 1.131.0 or later immediately. Pay particular attention to any automated workflows where jsii-diff processes externally supplied or untrusted input, as these present the highest exploitation risk. ...

16 July 2025 Â· ZX Cloud Security

Scattered Spider Hackers Jailed for ÂŁ29M TfL Hack

🟠 High | Source: The Hacker News Two members of the Scattered Spider cybercriminal group, Owen Flowers (18) and Thalha Jubair (20), have each been sentenced to five and a half years in prison for the 2024 hack of Transport for London. The attack took 148 TfL systems offline and forced all 27,000 staff to reset passwords in person, costing the organisation an estimated £29 million. The convictions represent a notable enforcement success against a group known for sophisticated social engineering and identity-based attacks. ...

16 July 2025 Â· ZX Cloud Security

CVE-2026-15737: AWS Bedrock AgentCore SDK Data Leak

🟠 High | Source: AWS Security Bulletins A vulnerability in the Bedrock AgentCore Python SDK (versions 1.4.8 and 1.5.0) causes raw user prompts and full agent responses to be written unfiltered into OpenTelemetry span attributes on every invocation. These spans are stored in the customer’s CloudWatch Logs group, where any locally authenticated user with read access to CloudWatch Logs could retrieve potentially sensitive AI conversation data. The issue stems from a lack of filtering or masking in the SDK’s OpenTelemetry instrumentation layer. ...

16 July 2025 Â· ZX Cloud Security

ThreatsDay: Ransomware, Chrome Sync Stalking & Spyware Round

🟠 High | Source: The Hacker News This weekly threat roundup covers a broad range of active attack techniques, including spyware bundled with game cheats, ransomware that deploys and encrypts within 24 hours, and Chrome Sync being abused for stalkerware-style tracking. The common thread is attackers exploiting trust — in familiar tools, default configurations, and legitimate platform features — to move quickly and avoid detection. Security Architect’s Take: Review your egress filtering and endpoint detection rules for abuse of legitimate browser sync features, and audit third-party or developer tooling in your environment for supply-chain risk. Prioritise rapid containment playbooks given the 24-hour ransomware deployment window highlighted here. ...

16 July 2025 Â· ZX Cloud Security

CVE-2026-50304: AD FS Denial of Service Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50304 is a Denial of Service vulnerability affecting Windows Active Directory Federation Services (AD FS), a widely used identity federation technology often integrated with Azure and hybrid cloud environments. An attacker exploiting this flaw could disrupt authentication services, potentially locking users out of applications and cloud resources. Microsoft has issued an informational update to the affected software table, but the underlying vulnerability warrants attention from teams running AD FS. ...

16 July 2025 Â· ZX Cloud Security

CVE-2026-50324: AD FS Denial of Service Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50324 is a Denial of Service vulnerability affecting Windows Active Directory Federation Services (AD FS), a critical authentication component widely used in hybrid and cloud-connected Microsoft environments. An attacker exploiting this flaw could disrupt federation services, potentially preventing users from authenticating to Azure AD and connected applications. Microsoft has issued an informational update to the affected software listing, with no change to the underlying vulnerability details. ...

16 July 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options