TELEPUZ Malware Spreads via ClickFix Lures (2026)

🟠 High | Source: The Hacker News TELEPUZ is a newly identified modular malware spreading through ClickFix-laced websites since late April 2026, capable of stealing data and executing remote commands via command-and-control infrastructure. Its lightweight, modular design makes it adaptable and harder to detect. The campaign is still in relatively early stages, but its versatility poses a meaningful threat to organisations whose users browse the web from corporate or cloud-connected endpoints. ...

16 July 2025 · ZX Cloud Security

Scattered Spider Members Jailed for TfL Ransomware Attack

🟠 High | Source: The Register — Security Two British members of the Scattered Spider cybercrime group have been sentenced to prison for their roles in the 2023 ransomware attack on Transport for London (TfL), which caused widespread disruption and exposed sensitive customer data. The conviction marks the largest cybercrime prosecution in UK legal history. Scattered Spider is a loosely organised, English-speaking threat group known for sophisticated social engineering and identity-based attacks targeting major organisations. ...

16 July 2025 · ZX Cloud Security

ClickLock macOS Stealer: App-Kill Password Theft

🟠 High | Source: The Hacker News ClickLock is a newly discovered macOS infostealer that coerces victims into handing over their login password by repeatedly killing core system applications every 210 milliseconds until they comply. It is delivered via a Terminal command — likely through social engineering — and persists across reboots using macOS LaunchAgents, even if the victim initially refuses the fake system password prompt. The technique is notable for its aggressive, user-harassment-based approach to credential theft rather than silent exploitation. ...

16 July 2025 · ZX Cloud Security

20+ Gov Websites Hijacked in PhantomEnigma Attack

🟠 High | Source: The Hacker News Over 20 Brazilian government websites were compromised and weaponised as malware distribution points as part of an active campaign dubbed PhantomEnigma. Researchers at ANY.RUN uncovered previously unknown backdoor behaviour, hidden infrastructure, and multiple attack vectors tied to the campaign. The incident highlights the risk of trusted government domains being abused to bypass reputation-based security controls. Security Architect’s Take: Review your organisation’s web filtering and threat intelligence feeds to ensure that government-domain URLs are not unconditionally trusted — apply the same inspection rigour to all traffic regardless of source domain reputation. Additionally, validate that your egress controls and DNS monitoring would detect beaconing to newly identified PhantomEnigma infrastructure. ...

16 July 2025 · ZX Cloud Security

Agent Data Injection: AI Agents Hijacked via Poisoned Data

🟠 High | Source: The Hacker News A newly documented attack technique called ‘Agent Data Injection’ allows adversaries to manipulate AI agents by poisoning the data sources they consume — such as product reviews or code repository comments — causing the agent to execute attacker-controlled actions rather than the user’s intended task. Unlike prompt injection, this attack does not directly target the agent’s instructions; it corrupts the environmental data the agent trusts, making detection significantly harder. The technique has broad implications for any agentic AI workflow that reads from untrusted external sources, including web browsing, code assistance, and automated purchasing. ...

16 July 2025 · ZX Cloud Security

Windows 10 End of Support: Cloud Security Risk Grows

🟠 High | Source: The Register — Security Approximately one in six Windows machines globally still runs Windows 10, despite Microsoft’s end-of-support deadline of October 2025 drawing ever closer. Once support ends, these machines will stop receiving security patches, leaving a vast attack surface exposed to unmitigated vulnerabilities. For organisations with unmanaged or legacy endpoints connecting to cloud environments, this represents a growing and tangible risk. Security Architect’s Take: Audit your estate now for Windows 10 endpoints with access to cloud resources — particularly those using federated identity, VPN, or direct cloud API access — and prioritise either forced migration to Windows 11 or isolation via network segmentation and conditional access policies that block non-compliant devices from reaching sensitive cloud workloads. ...

16 July 2025 · ZX Cloud Security

Daxin Rootkit & Stupig Backdoor Target Taiwan Firms

🟠 High | Source: The Hacker News Daxin, a sophisticated kernel-mode rootkit previously linked to Chinese state-sponsored threat actors, has reappeared at a Taiwanese manufacturing firm over four years after its initial public disclosure. Alongside it, researchers discovered a previously undocumented backdoor called Stupig, capable of operating before user login at SYSTEM-level privileges. The combination represents a highly capable, stealthy intrusion toolkit likely used for long-term espionage within critical industrial environments. ...

16 July 2025 · ZX Cloud Security

Shark Vacuum Flaw Enables Region-Wide AWS Device Takeover

🟠 High | Source: The Hacker News A security researcher has discovered an unpatched flaw in the Shark RV2320EDUS robot vacuum that allows an attacker who physically extracts a device certificate from the vacuum’s flash storage to issue root-level commands to any other Shark vacuum in the same AWS region. This grants access to the live camera feed, remote driving control, household floor plan data, and Wi-Fi credentials stored in plaintext. The vendor has not yet issued a patch, meaning all affected devices remain exposed. ...

16 July 2025 · ZX Cloud Security

CVE-2026-59831: GitHub CLI Codespace RCE Flaw

🟠 High | Source: Microsoft Security Response Center A vulnerability in GitHub CLI’s gh codespace jupyter command could allow an attacker to execute arbitrary code on a developer’s machine by tricking them into connecting to a maliciously crafted Codespace. The flaw sits in the JupyterLab integration within GitHub Codespaces, meaning any developer using this workflow could be at risk without realising the Codespace they are connecting to has been compromised. Given the prevalence of Codespaces in modern development pipelines, the potential for lateral movement into build systems or source code repositories is significant. ...

16 July 2025 · ZX Cloud Security

Law Firm Single Shared Password Security Breach

🟠 High | Source: The Register — Security A law firm was found to be using a single shared administrator password across its systems, meaning anyone with that credential could access all client data and impersonate any user. This represents a fundamental failure of identity and access management, exposing highly sensitive legal and client information to insider threats and external attackers alike. The incident highlights how credential hygiene failures can render all other security controls ineffective. ...

16 July 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options