Balochistan Police Portal Exploited in Espionage Campaign

🟠 High | Source: The Hacker News Suspected China- and India-aligned threat actors conducted sustained cyber espionage campaigns against Pakistani law enforcement agencies, including the Balochistan Police, between February 2024 and April 2026. Attackers compromised web application servers hosting sensitive police and citizen data. The incident highlights how public-sector web portals managing sensitive personal and law enforcement data remain high-value espionage targets. Security Architect’s Take: Review the security posture of any internet-facing web applications that handle sensitive operational or citizen data — ensure strict network segmentation, web application firewall (WAF) coverage, and regular authenticated vulnerability scanning are in place, particularly for legacy or under-resourced government-facing systems. ...

11 July 2025 Â· ZX Cloud Security

Squidbleed: 29-Year-Old Squid Proxy HTTP Leak Flaw

🟠 High | Source: Schneier on Security A 29-year-old vulnerability in Squid proxy software, dubbed ‘Squidbleed’, has been disclosed, allowing HTTP requests to be leaked. Squid is a widely used open-source caching proxy deployed across on-premises and cloud environments. Despite its age, this flaw is significant as Squid remains prevalent in many enterprise and cloud network architectures as a forward or reverse proxy. Security Architect’s Take: Audit your environment immediately for any Squid proxy deployments — including those embedded in containerised workloads or cloud egress filtering stacks — and apply available patches or mitigations. Review network segmentation to ensure Squid instances are not exposed to untrusted networks pending remediation. ...

10 July 2025 Â· ZX Cloud Security

GigaWiper: Windows Backdoor Combines Wipers & Ransomware

🟠 High | Source: The Register — Security Microsoft has identified a sophisticated Windows backdoor called GigaWiper that combines at least three distinct malware families — including wiper and ransomware components — into a single modular tool. This makes it highly adaptable, allowing attackers to deploy destructive or extortion-based payloads from one package. The modular design significantly lowers the barrier for threat actors to cause widespread damage across targeted environments. Security Architect’s Take: Prioritise endpoint detection coverage for Windows workloads in cloud-connected environments, particularly around Azure-joined or hybrid AD machines — ensure Microsoft Defender for Endpoint is fully deployed and that wiper-class behavioural detections are enabled. Review backup immutability controls and test recovery runbooks now, before a destructive payload is triggered. ...

10 July 2025 Â· ZX Cloud Security

Injective Labs npm Supply Chain Attack Steals Crypto Keys

🟠 High | Source: The Hacker News Attackers compromised the GitHub repository of Injective Labs, a blockchain SDK project, and used it to publish a malicious npm package (@injectivelabs/sdk-ts@1.20.21) that secretly steals cryptocurrency wallet private keys and seed phrases. The package disguised its theft mechanism as routine telemetry functionality, making it difficult to detect. This is a classic software supply chain attack targeting developers who build on the Injective blockchain ecosystem. ...

10 July 2025 Â· ZX Cloud Security

Six U-Boot Flaws Enable Code Execution at Boot

🟠 High | Source: The Hacker News Researchers at Binarly have identified six vulnerabilities in U-Boot, the open-source bootloader widely used in routers, smart cameras, and server management chips. Four flaws can cause devices to crash, while two could allow an attacker who controls a malicious firmware image to execute arbitrary code before the operating system loads. Because exploitation occurs at boot time, traditional OS-level security controls offer no protection. Security Architect’s Take: Audit your supply chain for devices and server BMCs (e.g. iDRAC, iLO, BMC) that use U-Boot and track vendor patch availability immediately. Enforce secure boot and image signing policies to ensure only cryptographically verified firmware images are presented to the bootloader, mitigating the code-execution variants. ...

10 July 2025 Â· ZX Cloud Security

Laser Attack Resets Tangem Wallet Passwords Permanently

🟠 High | Source: The Hacker News Researchers from Ledger’s Donjon team have demonstrated that a precisely timed laser pulse directed at the chip inside a Tangem hardware crypto wallet card can reset the card’s password to an attacker-chosen value — with no knowledge of the original password required. Because the vulnerability exists in hardware, affected cards cannot be patched via firmware update. Any attacker who gains physical access and has the necessary equipment could take full control of the wallet and drain its funds. ...

10 July 2025 Â· ZX Cloud Security

OpenClaw AI Flaws Enable WhatsApp-to-Host Attack

🟠 High | Source: The Hacker News Three now-patched high-severity vulnerabilities in the OpenClaw AI assistant can be chained together to allow an attacker to steal credentials, escalate privileges, and execute arbitrary code on the underlying host — potentially triggered via a malicious WhatsApp message. The attack chain is particularly concerning because it crosses from a messaging interface into host-level compromise, widening the blast radius significantly. All three flaws have been patched by the vendor. ...

10 July 2025 Â· ZX Cloud Security

MODBEACON RAT: Silver Fox Uses gRPC for C2 Traffic

🟠 High | Source: The Hacker News A China-linked threat group called Silver Fox has deployed a new Rust-based remote access trojan named MODBEACON, which uses gRPC streaming to disguise its command-and-control traffic as legitimate encrypted communications. The malware is distributed via fake software installers promoted through SEO poisoning. Despite appearing unsophisticated, the group demonstrates significant operational organisation, making detection and attribution more difficult. Security Architect’s Take: Review egress controls and TLS inspection policies to ensure gRPC traffic on port 443 is inspected or allowlisted only for trusted endpoints — MODBEACON exploits the assumption that gRPC traffic is benign. Additionally, enforce software installation controls (e.g. allowlisting) on cloud-connected workstations to block counterfeit installers reaching your estate. ...

10 July 2025 Â· ZX Cloud Security

XRING: Unpatched XQUIC HTTP/3 Crash Flaw

🟠 High | Source: The Hacker News A vulnerability nicknamed XRING in Alibaba’s open-source XQUIC library allows any remote attacker to crash an HTTP/3 server using roughly 260 bytes of entirely legitimate QPACK traffic — no authentication or malformed packets required. The flaw stems from a single incorrect variable in the codebase and was publicly disclosed by FoxIO researcher SĂ©bastien FĂ©ry on 8 July. No patch is currently available, leaving all deployments of XQUIC exposed. ...

10 July 2025 Â· ZX Cloud Security

WP-SHELLSTORM: 1.4M WordPress Sites Targeted

🟠 High | Source: The Hacker News A cybercrime group accidentally left their attack infrastructure publicly accessible for three weeks, exposing their tools, logs, and a target list of over 1.4 million WordPress sites. Researchers were able to observe the full mechanics of a mass WordPress backdooring campaign, tracked as WP-SHELLSTORM. While the number of successfully compromised sites is lower than the target list, the exposure reveals the industrial scale at which these operations are conducted. ...

10 July 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options