Five Eyes AI Cyber Warning: Skill vs Ability Gap

🟠 High | Source: Schneier on Security The Five Eyes intelligence alliance has issued a joint advisory warning that AI models are increasingly capable of autonomously conducting cyberattacks, lowering the skill barrier for threat actors. The statement highlights a growing gap between the technical knowledge required to understand an attack and the practical ability to execute one, as AI tools handle complexity on behalf of less-skilled adversaries. This represents a structural shift in the threat landscape rather than a temporary spike in risk. ...

8 July 2025 · ZX Cloud Security

UAT-7810 Expands ORB Network With LONGLEASH Malware

🟠 High | Source: The Hacker News A Chinese state-linked threat actor, UAT-7810, is actively developing new malware called LONGLEASH to expand its ‘LapDogs’ Operational Relay Box (ORB) network — a system of compromised networking devices used to relay and obscure malicious traffic. The group targets internet-facing network devices, making detection and attribution significantly harder. ORB networks are increasingly favoured by Chinese APTs to evade geolocation-based blocking and complicate incident response. ...

8 July 2025 · ZX Cloud Security

GitHub AI Agent Leaks Private Repos: GitLost Flaw

🟠 High | Source: The Register — Security A vulnerability in GitHub’s AI agent allows private repository contents to be exposed when users issue simple natural language prompts, effectively bypassing access controls through the AI layer. The issue, dubbed ‘GitLost’, has no available patch or vendor documentation at time of reporting. This is particularly concerning given the widespread enterprise adoption of AI coding assistants and the sensitivity of source code repositories. ...

7 July 2025 · ZX Cloud Security

CAI Cloud Worm Steals Credentials & Mines Crypto

🟠 High | Source: The Register — Security A cloud-targeting worm dubbed CAI has been observed actively evicting competing malware from compromised cloud environments before stealing credentials and deploying cryptomining software. The worm’s ability to identify and remove rival malicious tools suggests a sophisticated, resource-competitive threat actor focused on maximising persistent access. This matters because it indicates an increasingly cutthroat and automated attacker ecosystem targeting cloud infrastructure at scale. Security Architect’s Take: Audit cloud workloads for unexpected process terminations, unusual IAM credential usage, and cryptomining indicators — the worm’s clean-up behaviour may mask its presence by removing other known malware signatures your tooling would otherwise detect. Ensure runtime threat detection covers behavioural anomalies, not just known malware hashes. ...

7 July 2025 · ZX Cloud Security

RedWing Android MaaS: Bank Fraud Sold on Telegram

🟠 High | Source: The Hacker News RedWing is a new Android malware-as-a-service (MaaS) operation sold via Telegram that enables low-skilled attackers to conduct banking fraud, including credential theft and one-time passcode interception. Researchers at Zimperium’s zLabs have identified it as likely a variant of the Oblivion rental toolkit, previously available for around $300 per month. Its low barrier to entry significantly broadens the pool of potential threat actors, increasing the likelihood of widespread consumer and corporate banking compromise. ...

7 July 2025 · ZX Cloud Security

Google Dialogflow CX Flaw Let Attackers Hijack Chatbots

🟠 High | Source: The Hacker News A flaw in Google’s Dialogflow CX allowed an attacker with edit access to one chatbot agent to compromise other agents within the same Google Cloud project that had Code Blocks enabled. Exploitation could enable attackers to intercept live conversations, exfiltrate user-submitted data, and inject malicious messages — including fake password prompts. The vulnerability was discovered by Varonis and has since been patched by Google. ...

7 July 2025 · ZX Cloud Security

Predatorgate Victims Sue Spyware Maker for €8M

🟠 High | Source: The Register — Security Victims of the Predatorgate surveillance scandal have filed an €8 million lawsuit in Greece against the maker of Predator spyware, which was used to covertly monitor journalists, politicians, and activists. The case coincides with increased pressure from civil rights groups on the EU to tighten regulation of commercial spyware vendors. This is a significant legal milestone in efforts to hold spyware companies accountable for enabling state-sponsored surveillance abuses. ...

7 July 2025 · ZX Cloud Security

DEBULL: Microsoft 365 Device Code Phishing Attack

🟠 High | Source: The Hacker News A phishing campaign dubbed DEBULL is exploiting Microsoft’s legitimate device code authentication flow to hijack Microsoft 365 accounts, without requiring a fake login page. Attackers use collaboration-themed lures to trick users into entering a device code on Microsoft’s own login portal, granting the attacker a valid access token. This technique is particularly dangerous because it bypasses traditional phishing indicators and can circumvent MFA. Security Architect’s Take: Review and restrict device code flow (OAuth 2.0 device authorisation grant) in your Microsoft Entra ID Conditional Access policies — block or limit it to trusted, managed devices where possible. Additionally, enable sign-in risk policies and monitor for device code authentication events in your Entra ID sign-in logs, particularly from unfamiliar locations or user agents. ...

7 July 2025 · ZX Cloud Security

GitHub Agentic Workflows Vulnerable to Prompt Injection

🟠 High | Source: The Hacker News Researchers at Noma Security have demonstrated that a malicious actor can craft a seemingly innocent issue on a public GitHub repository to manipulate GitHub Agentic Workflows into exfiltrating data from an organisation’s private repositories. The attack requires no credentials, no insider access, and no code changes — just a public issue post. If an AI agent has been granted broad read access across repositories, it can be prompted indirectly to leak sensitive private content, a classic prompt injection scenario applied to agentic AI pipelines. ...

7 July 2025 · ZX Cloud Security

CVE-2026-45638 WinSock EoP Vulnerability – Azure Impact

🟠 High | Source: Microsoft Security Response Center CVE-2026-45638 is an elevation of privilege vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys), a core Windows networking component. If exploited, an attacker with local access could gain SYSTEM-level privileges on affected Windows machines, including those running as Azure VMs or hybrid-connected servers. This update is an acknowledgement change only and carries no new technical details or patches. Security Architect’s Take: No immediate remediation action is required as this is an informational acknowledgement update — ensure the original patch for CVE-2026-45638 has been applied across all Windows-based Azure VMs, Azure Virtual Desktop hosts, and hybrid Arc-connected servers via your patch management tooling. ...

7 July 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options