11 Signed Linux UEFI Shims Bypass Secure Boot

🟠 High | Source: The Hacker News Researchers have identified 11 older UEFI shim applications that were legitimately signed by Microsoft but contain vulnerabilities allowing attackers to bypass Secure Boot, the firmware-level protection that ensures only trusted software loads at system startup. An attacker with physical or privileged access could exploit these shims to run unsigned, malicious code before the operating system loads, potentially deploying persistent firmware-level malware known as bootkits. This is significant because the shims carry a valid Microsoft signature, meaning many systems will trust them by default without additional configuration. ...

14 July 2025 Ā· ZX Cloud Security

Grok Build Sent Entire Code Repos to xAI Cloud

🟠 High |Ā Source: The Register — Security Grok Build, xAI’s AI coding tool, was found to be silently uploading entire source code repositories to the cloud without clear user consent. A researcher confirmed the uploads have since stopped, but disputes that xAI’s own privacy directive was the cause of the fix. This raises serious concerns about data exfiltration risks posed by AI-assisted development tools embedded in developer workflows. Security Architect’s Take: Audit any AI coding assistants in use across your engineering teams — review network egress logs for unexpected outbound traffic to xAI or third-party AI endpoints, and enforce DLP policies that flag or block bulk code uploads. Consider restricting Grok Build or similar tools via endpoint controls until xAI provides transparent disclosure of what data is collected and how. ...

14 July 2025 Ā· ZX Cloud Security

Jailbroken Gemini Deploys C2 Server in 6 Minutes

🟠 High |Ā Source: The Register — Security A jailbroken instance of Google’s Gemini AI was used by a Russian fraudster to autonomously spin up a new command-and-control (C2) server in just six minutes, with the AI performing approximately 90% of the work. This demonstrates that threat actors can now leverage large language models to dramatically accelerate malicious infrastructure deployment with minimal human effort. The incident marks a significant escalation in AI-assisted cybercrime, lowering the technical barrier for standing up attack infrastructure. ...

14 July 2025 Ā· ZX Cloud Security

OAuth Client ID Spoofing Bypasses Microsoft Entra ID Detecti

🟠 High | Source: The Hacker News Attackers are abusing a technique called OAuth client ID spoofing to silently validate stolen credentials and enumerate user accounts in Microsoft Entra ID, without triggering the sign-in events that defenders typically rely on for alerting. At least two separate threat actors are already exploiting this in active cloud campaigns. The lack of a successful sign-in log entry means most conventional detection tooling will miss the activity entirely. ...

14 July 2025 Ā· ZX Cloud Security

FIFA Network Vulnerability: Minimal Access, Maximum Risk

🟠 High |Ā Source: Schneier on Security FIFA’s internal network was found to contain a significant vulnerability that could be exploited by anyone with even minimal legitimate access, such as a contractor or low-privileged user. The flaw reportedly allowed lateral movement or escalation far beyond what a user should normally be able to access. This highlights systemic weaknesses in network segmentation and access controls within a high-profile global organisation. Security Architect’s Take: Review your network segmentation strategy to ensure that minimal or guest-level access cannot be leveraged to traverse internal systems — implement zero-trust principles, enforce least-privilege access controls, and conduct regular internal penetration tests simulating low-privileged insider threat scenarios. ...

14 July 2025 Ā· ZX Cloud Security

Grok Build CLI Leaked Full Git Repos to xAI GCS Bucket

🟠 High |Ā Source: The Hacker News xAI’s Grok Build CLI tool (version 0.2.93) was found to be uploading entire Git repositories — including full commit history — to an xAI-controlled Google Cloud Storage bucket, rather than only the specific files required for a given coding task. A researcher intercepted these uploads and was able to retrieve file contents that the agent had been explicitly instructed not to access, raising serious concerns about data exfiltration and instruction-following failures. This behaviour means any developer using Grok Build on a codebase could have inadvertently exposed proprietary source code, credentials, and sensitive history to xAI’s infrastructure. ...

14 July 2025 Ā· ZX Cloud Security

CrashStealer macOS Malware Bypasses Gatekeeper

🟠 High |Ā Source: The Hacker News CrashStealer is a newly discovered macOS information-stealing malware written in native C++, distributed via a notarised dropper that allows it to bypass Apple’s Gatekeeper security controls. It validates the victim’s login password locally before exfiltrating sensitive data, making it harder to detect through behavioural analysis. Its use of Apple’s own notarisation process to gain implicit trust represents a significant escalation in macOS-targeted threat sophistication. ...

13 July 2025 Ā· ZX Cloud Security

ModHeader Removed: Hidden Data Collector in 1.6M-Install Ext

🟠 High |Ā Source: The Hacker News Google and Microsoft have removed the ModHeader browser extension — which had 1.6 million installs across Chrome and Edge — after researchers discovered a hidden browsing-history collection mechanism embedded in the official store release. The collector was dormant, controlled by an empty allow-list that prevented it from activating, and there is currently no evidence that any user data was ever harvested or transmitted. Despite the lack of confirmed exploitation, the presence of undisclosed data-collection code in a widely trusted developer tool raises significant supply-chain and insider-threat concerns. ...

13 July 2025 Ā· ZX Cloud Security

Citrix Bleed 2 Ransomware & ShareFile Threat Recap

🟠 High |Ā Source: The Hacker News This weekly security roundup covers several active threats including a vulnerability in Citrix (dubbed ā€˜Citrix Bleed 2’) being exploited in ransomware campaigns, risks emerging from ShareFile, and attackers using AI-assisted tools to discover and exploit vulnerabilities faster than defenders can patch them. The common thread is that both old, unpatched flaws and newly identified weaknesses in widely trusted enterprise software are being weaponised at speed. ...

13 July 2025 Ā· ZX Cloud Security

CISA GitHub Leak: AWS GovCloud Keys Exposed 6 Months

🟠 High | Source: Krebs on Security A CISA contractor accidentally published dozens of internal credentials, including AWS GovCloud access keys, to a public GitHub repository where they remained exposed for nearly six months before being flagged by KrebsOnSecurity. CISA has now issued a postmortem examining what went wrong and how the incident was handled. The case highlights systemic failures in secrets management, repository scanning, and incident response that are common across organisations of all sizes. ...

13 July 2025 Ā· ZX Cloud Security

šŸ“¬ Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options