Chinese Hackers Target University Roundcube Servers

🟠 High | Source: The Register — Security Suspected Chinese state-sponsored threat actors have been observed compromising Roundcube webmail servers at universities, exploiting vulnerabilities to conduct espionage. Proofpoint researchers estimate the campaign targeted a few dozen institutions, suggesting a focused, intelligence-gathering operation rather than opportunistic mass exploitation. The incident highlights the continued targeting of academic institutions, which often hold sensitive research and government-adjacent data. Security Architect’s Take: If your organisation runs Roundcube, patch immediately and audit server logs for indicators of compromise, particularly any unauthorised access to mailboxes or configuration files. More broadly, consider migrating legacy open-source webmail deployments to hardened, actively maintained platforms and enforce MFA across all email access points. ...

8 July 2025 Â· ZX Cloud Security

HalluSquatting: AI Coding Assistants Tricked Into Installing

🟠 High | Source: The Hacker News HalluSquatting is a novel attack technique that exploits the tendency of AI coding assistants to hallucinate package or library names. Attackers identify packages that AI tools reliably fabricate, register those names on public registries, and embed malware — including botnet payloads — that gets silently installed when a developer follows the AI’s advice. This turns a known AI reliability flaw into a practical software supply chain attack requiring no phishing or social engineering. ...

8 July 2025 Â· ZX Cloud Security

CVE-2026-42980: NT Kernel Privilege Escalation on Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-42980 is an elevation of privilege vulnerability in the Windows NT OS Kernel, meaning an attacker could potentially gain higher-level system permissions than intended. This update is purely administrative — Microsoft has amended the acknowledgements section only, with no changes to the vulnerability details, severity rating, or patch guidance. No action is required as a result of this specific update. Security Architect’s Take: No new mitigations or patches have been issued with this update; if you have already applied the relevant Windows security patch for CVE-2026-42980, no further action is required. Use this as a prompt to verify that your Azure-connected Windows workloads and VM images are patched and that kernel-level privilege escalation is covered in your threat model. ...

8 July 2025 Â· ZX Cloud Security

CVE-2026-58525: Microsoft Edge Security Bypass Fix

🟠 High | Source: Microsoft Security Response Center A security feature bypass vulnerability (CVE-2026-58525) has been identified in Microsoft Edge (Chromium-based), where improper access controls allow a remote, unauthenticated attacker to circumvent browser security protections over a network. This could enable an attacker to perform actions that would ordinarily be blocked by Edge’s built-in defences. While browser-level, this poses a meaningful risk in enterprise environments where Edge is widely deployed, particularly for users accessing cloud management portals or sensitive internal tooling. ...

8 July 2025 Â· ZX Cloud Security

GhostApproval Flaw in AI Coding Agents: Unix Security Risk

🟠 High | Source: The Register — Security A vulnerability dubbed ‘GhostApproval’ has been identified in leading AI coding agents, exploiting weaknesses in human-in-the-loop approval mechanisms — a problem rooted in decades-old Unix-era security design flaws. Attackers or malicious inputs can manipulate AI agents into executing unauthorised actions by bypassing or spoofing approval steps that users believe are protecting them. This highlights a systemic risk in agentic AI pipelines where assumed human oversight may be illusory. ...

8 July 2025 Â· ZX Cloud Security

China Warns Devs: Ditch Claude Code Over Backdoor Risk

🟠 High | Source: The Register — Security China’s national vulnerability database has flagged older versions of Anthropic’s Claude Code AI coding assistant, alleging it contains a monitoring mechanism capable of forwarding Chinese users’ data to remote servers. The advisory has prompted Chinese authorities to urge developers to stop using the affected versions. The claims introduce significant supply chain concerns around AI-assisted development tooling, particularly for organisations operating in or with Chinese entities. ...

8 July 2025 Â· ZX Cloud Security

Ghost Phishing Bypasses Email Security | EvilTokens

🟠 High | Source: The Hacker News A phishing campaign dubbed EvilTokens is using ‘ghost phishing’ to evade traditional email security tools by keeping malicious payloads encrypted until they are decrypted and rendered live inside the victim’s browser. This means standard URL reputation checks and email gateway scanners see nothing suspicious at the point of delivery. Businesses using Microsoft 365 are particularly at risk, as successful attacks can result in account compromise and sensitive data exposure. ...

8 July 2025 Â· ZX Cloud Security

SCMBANKER Malware: ClickFix Lures Target Mexican Banks

🟠 High | Source: The Hacker News A sophisticated banking malware campaign dubbed SCMBANKER (tracked as REF6045) is targeting customers of Mexican banks, fintechs, payment processors, and cryptocurrency exchanges. Attackers use fake CAPTCHA pages — a technique known as ClickFix — to trick victims into manually running a malicious PowerShell command that installs the malware. This social engineering approach is particularly effective because it bypasses many automated security controls by having the victim execute the payload themselves. ...

8 July 2025 Â· ZX Cloud Security

GitHub Verified Commits Can Be Spoofed Without Signing Key

🟠 High | Source: The Hacker News Researchers have found that GitHub’s ‘Verified’ badge on signed commits can be spoofed without access to the original signing key. An attacker can create a duplicate commit containing identical files, author details, and timestamp, complete with a valid signature, whilst producing a different commit hash. This undermines a core assumption in software supply chain security: that a verified commit is uniquely trustworthy. Security Architect’s Take: Do not rely solely on GitHub’s ‘Verified’ badge as a supply chain integrity control. Supplement commit signing policies with hash-pinning in CI/CD pipelines, enforce SLSA provenance attestations, and cross-reference commit hashes in your build manifests against expected values rather than trusting the UI indicator alone. ...

8 July 2025 Â· ZX Cloud Security

ATO in 2026: Verification Steps Are the New Attack Surface

🟠 High | Source: The Hacker News Attackers are shifting focus from credential stuffing to exploiting identity verification steps — such as MFA prompts, passkey recovery flows, and account reset mechanisms — as passkeys become mainstream and the traditional ‘front door’ gets harder to compromise. This marks a strategic pivot in account takeover (ATO) tactics where the verification layer itself becomes the primary attack surface. Cloud-hosted identity services and SaaS platforms are increasingly in scope as attackers target the weakest link in the authentication chain. ...

8 July 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options