Qantas Data Breach: Tech Support Scam Hits 5.7M Customers

🟠 High | Source: The Register — Security A tech support scam targeting a Qantas employee led to a data breach exposing the personal information of 5.7 million customers, making it one of Australia’s largest airline data incidents. The breach highlights how social engineering — rather than sophisticated technical exploits — remains a highly effective attack vector. Notably, despite the scale, Qantas reportedly did not breach Australian privacy rules, raising questions about the adequacy of existing data protection legislation. ...

16 July 2025 Â· ZX Cloud Security

CVE-2026-15746: SSRF & Credential Leak in AWS Strands Agents

🟠 High | Source: AWS Security Bulletins A server-side request forgery (SSRF) vulnerability in the Strands Agents Tools package allows a crafted prompt to trick the elasticsearch_memory tool into sending an operator’s Elasticsearch API key to an attacker-controlled server. The flaw exists because the tool exposes connection parameters — including the target host — to the large language model, and falls back to environment variable credentials when none are explicitly provided. Any deployment using strands-agents-tools below version 0.7.0 with the elasticsearch_memory tool is at risk of credential theft. ...

15 July 2025 Â· ZX Cloud Security

OkoBot Malware Phishes Ledger & Trezor Seed Phrases

🟠 High | Source: The Hacker News OkoBot is a Windows malware framework active since April 2025 that targets hardware cryptocurrency wallet users by injecting phishing overlays into legitimate Ledger and Trezor desktop applications. When a hardware wallet is connected, the malware displays a convincing prompt within the genuine wallet software requesting the user’s seed phrase — the master recovery key that grants full access to all funds. Because the surrounding application is real and trusted, victims have little visual reason to suspect the request is fraudulent. ...

15 July 2025 Â· ZX Cloud Security

CVE-2026-50375: DirectX Graphics Kernel EoP Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-50375 is an elevation of privilege vulnerability in the DirectX Graphics Kernel component on Windows, which could allow an attacker to gain higher system privileges than intended. This update from Microsoft is an informational change only, revising the acknowledgment section with no changes to severity, patch status, or exploitability. No immediate action beyond previously issued guidance is required as a result of this update. ...

15 July 2025 Â· ZX Cloud Security

CVE-2026-56182 Windows NTFS Privilege Escalation

🟠 High | Source: Microsoft Security Response Center CVE-2026-56182 is an elevation of privilege vulnerability affecting Windows NTFS, the file system used across Windows environments including Azure virtual machines and hybrid workloads. An attacker exploiting this flaw could gain higher-level permissions on an affected system without authorisation. This update is an acknowledgment change only — no new patches or exploitation details have been released at this time. Security Architect’s Take: No immediate patching action is triggered by this update, as it is an informational acknowledgment change only; however, ensure CVE-2026-56182 is tracked in your vulnerability management backlog and that Azure VMs and Windows-based workloads have the original remediation applied. Validate that your Windows Server images used in Azure are built from patched baselines. ...

15 July 2025 Â· ZX Cloud Security

CVE-2026-58644 SharePoint RCE Advisory Corrected

🟠 High | Source: Microsoft Security Response Center Microsoft has issued a correction to the advisory for CVE-2026-58644, a Remote Code Execution vulnerability in Microsoft SharePoint. The update revises the Exploitability Index, the ‘Exploited’ flag, and the CVSS vector, all of which were inaccurate at initial publication on 14 July 2026. This is a metadata correction only — no new patch or change to the underlying vulnerability is introduced. Security Architect’s Take: Review the corrected CVSS vector and updated Exploitability Index to reassess your patching priority for SharePoint environments. If the revised ‘Exploited’ flag now indicates active exploitation, treat this as urgent and accelerate remediation timelines accordingly. ...

15 July 2025 Â· ZX Cloud Security

Windows Zero-Day PoC: ProfSvc Privilege Escalation

🟠 High | Source: The Hacker News A security researcher has publicly released a proof-of-concept exploit called LegacyHive targeting a previously undisclosed vulnerability in the Windows User Profile Service (ProfSvc), allowing local privilege escalation. The PoC was dropped shortly after Microsoft’s July 2026 Patch Tuesday cycle, meaning it may not yet be patched. This is particularly concerning as elevation of privilege vulnerabilities are commonly used as a second stage in broader attack chains. ...

15 July 2025 Â· ZX Cloud Security

Closing the Approval Gap in AI-Era Ad Tech Security

🟠 High | Source: The Hacker News Marketing tags approved by security teams can silently load unauthorised fourth-party JavaScript, exposing customer forms, checkout pages, and sensitive data to unknown third parties. This ‘Approval Gap’ exists because the initial tag review rarely covers the downstream scripts those tags subsequently load. An on-demand webinar outlines how this attack surface forms and how teams can close it before regulators or attackers exploit it. Security Architect’s Take: Implement a Content Security Policy (CSP) with a strict allowlist and deploy client-side JavaScript monitoring or a tag governance tool (e.g. SourcePoint, Feroot) to inventory and alert on fourth-party script execution in real time — approval of a tag must not imply trust in everything it loads. ...

15 July 2025 Â· ZX Cloud Security

Cursor Editor Flaw: Malicious git.exe Runs on Open

🟠 High | Source: The Hacker News A vulnerability in the Cursor AI code editor on Windows allows a malicious file named git.exe placed in a project root to execute automatically when the repository is opened, with no user prompt or warning. The binary runs with the victim’s full privileges, giving an attacker access to source code, SSH keys, and cloud credentials. The execution persists for as long as the project remains open. ...

15 July 2025 Â· ZX Cloud Security

AsyncAPI npm Packages Hijacked to Spread Botnet

🟠 High | Source: The Hacker News Four npm packages within the @asyncapi namespace were compromised and used to distribute a multi-stage botnet loader, meaning any project installing these packages during the affected window may have executed malicious code. The attack targets the software supply chain by hijacking trusted, widely-used open-source tooling. This is particularly concerning given AsyncAPI’s popularity in API-driven and event-driven architecture projects. Security Architect’s Take: Audit your CI/CD pipelines and developer environments for installations of the four affected @asyncapi packages and treat any affected systems as potentially compromised. Implement or review npm package integrity controls — including lockfile enforcement, private registry mirroring, and automated supply chain scanning tools such as Socket or Sigstore — to detect future namespace-level compromises before they reach production. ...

15 July 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options