Free Android VPN Apps: Traffic Leaks & No Encryption

🟠 High | Source: The Hacker News A study of 281 popular free Android VPN apps found that many fail at their core purpose: keeping user traffic private. Problems include traffic leaks outside the VPN tunnel, unencrypted data transmission, and embedded tracking. Apps with at least one identified flaw have been collectively installed over 2.4 billion times, making this a widespread consumer and enterprise risk. Security Architect’s Take: Prohibit or formally assess the use of free consumer VPN apps on any device that accesses corporate resources — this research confirms they frequently lack basic security controls. If employees use personal Android devices under a BYOD policy, update your acceptable use policy and mobile device management (MDM) controls to block or flag unapproved VPN applications. ...

10 July 2025 · ZX Cloud Security

Fake Entra Passkey Enrolment Used to Hijack M365

🟠 High | Source: The Hacker News A threat actor tracked as O-UNC-066 is using vishing (voice phishing) calls to trick Microsoft 365 users into enrolling an attacker-controlled passkey in Microsoft Entra, effectively handing over persistent account access. Once enrolled, the attacker can authenticate as the victim without needing a password or MFA, enabling data extortion. The attack uses a panel-controlled phishing kit specifically designed to abuse the passkey registration flow. ...

10 July 2025 · ZX Cloud Security

CVE-2026-56288: GNU patch Flaw Affects Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-56288 is a NULL pointer dereference vulnerability in GNU patch, a widely used utility for applying code changes to files. Microsoft has published an advisory indicating this affects Azure environments, likely through Linux-based compute resources or container images that ship GNU patch. NULL pointer dereference flaws can cause application crashes or, in certain conditions, be exploited to execute arbitrary code. Security Architect’s Take: Audit Azure Linux VMs, container base images, and Azure Kubernetes Service node pools for versions of GNU patch that are unpatched against CVE-2026-56288, and prioritise updating affected OS packages via your standard patching pipeline or golden image rebuild process. ...

10 July 2025 · ZX Cloud Security

CVE-2026-59818: etcd CRL Revocation Bypass in Azure

🟠 High | Source: Microsoft Security Response Center A vulnerability in etcd’s gRPC client listener means that certificate revocation lists (CRLs) specified via the --client-crl-file flag are not enforced, allowing clients with revoked certificates to continue authenticating successfully. This undermines a key control used to invalidate compromised or expired credentials in etcd clusters, which are commonly used as the backing store for Kubernetes control planes. In Azure environments where etcd is a component of managed or self-managed Kubernetes clusters, this could allow an attacker holding a revoked certificate to maintain unauthorised access. ...

10 July 2025 · ZX Cloud Security

US County Pays $1M Ransomware Extortion Demand

🟠 High | Source: The Register — Security An unnamed US county, believed to be in Ohio, paid a $1 million extortion demand to cybercriminals following what appears to be a ransomware or data extortion attack. Details have emerged through leaked negotiation transcripts, shedding light on how local government entities handle such incidents. The case highlights the continued targeting of under-resourced public sector organisations and the real-world financial impact of extortion-driven attacks. ...

9 July 2025 · ZX Cloud Security

GigaWiper Backdoor: Wiper, Spyware & Fake Ransomware

🟠 High | Source: The Hacker News Microsoft has analysed a new Windows backdoor called GigaWiper that combines three destructive capabilities — full disk wiping, Windows drive overwriting, and fake ransomware that encrypts files without saving the decryption key — into a single operator-controlled toolkit. Because the encryption key is discarded, victims cannot recover files even if they pay a ransom, making it a pure destructive tool masquerading as financially motivated malware. The modular design lowers the bar for threat actors to cause irreversible damage to targeted systems. ...

9 July 2025 · ZX Cloud Security

EU Chat Control Returns: What It Means for Cloud Security

🟠 High | Source: The Register — Security The European Parliament failed to secure the 360-vote majority needed to block an interim rule that would require messaging and cloud platforms to scan for child sexual abuse material (CSAM), effectively keeping ‘Chat Control’ legislation alive. Opponents won a simple majority but fell short of the procedural threshold required to kill the proposal. This matters because the rule could compel cloud and communications providers to implement client-side scanning or backdoors, fundamentally undermining end-to-end encryption. ...

9 July 2025 · ZX Cloud Security

Microsoft Patches Defender RoguePlanet Zero-Day

🟠 High | Source: The Register — Security Microsoft has released a patch for a zero-day vulnerability in Microsoft Defender, dubbed RoguePlanet by the threat group Nightmare Eclipse, weeks after working exploit code was publicly available. The delay between exploit publication and patch release meant organisations running Defender were exposed for an extended period. This is notable because Defender is a core security control in many Windows and Azure environments, meaning a compromise could undermine broader endpoint and cloud defences. ...

9 July 2025 · ZX Cloud Security

GodDamn Ransomware: PoisonX Driver Disables EDR

🟠 High | Source: The Hacker News A new ransomware strain called GodDamn, believed to be a rebrand of the Beast ransomware family, uses a malicious kernel driver called PoisonX to disable endpoint security tools before encrypting systems. First observed in the wild in May 2026, it employs a Bring Your Own Vulnerable Driver (BYOVD)-style technique to operate at the kernel level, bypassing traditional defences. This approach makes it particularly dangerous as it can neutralise EDR and antivirus solutions before the payload deploys. ...

9 July 2025 · ZX Cloud Security

CVE-2026-53359: KVM Shadow Paging Use-After-Free on Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-53359 is a use-after-free vulnerability in the Linux KVM hypervisor’s x86 shadow paging implementation, affecting virtualised environments hosted on Azure. Use-after-free flaws occur when software continues to reference memory after it has been freed, potentially allowing an attacker to execute arbitrary code or escalate privileges within the hypervisor layer. This is particularly significant in cloud environments where KVM underpins virtual machine isolation. Security Architect’s Take: Review your Azure VM configurations and ensure all host OS and hypervisor patches are applied promptly once Microsoft releases fixes; if you operate self-managed KVM-based infrastructure on Azure (e.g. nested virtualisation scenarios), prioritise patching the kernel and assess whether any untrusted workloads could exploit the shadow paging path. ...

9 July 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options