Enterprise AI Security Incidents: The Cost of Moving Fast

🟠 High | Source: The Register — Security A majority of enterprises report having experienced AI-related security incidents or vulnerabilities, reflecting the industry-wide trend of deploying AI tools rapidly without adequate security controls in place. Organisations rushed to adopt AI capabilities to remain competitive, often bypassing standard security review processes. This pattern of ’leap before you look’ adoption is now resulting in measurable security consequences across enterprise environments. Security Architect’s Take: Conduct an immediate audit of all AI services and integrations in your environment, cataloguing data access permissions, API exposure, and any third-party model dependencies — then enforce AI-specific security policies including prompt injection controls, data loss prevention guardrails, and model supply chain validation before any further deployments are approved. ...

7 July 2025 · ZX Cloud Security

Fake IT Helpdesk on Microsoft Teams Drops EtherRAT

🟠 High | Source: The Register — Security Attackers are impersonating IT helpdesk staff on Microsoft Teams to trick employees into granting remote access to their machines, then deploying the EtherRAT remote access trojan. The campaign, uncovered by Palo Alto’s Unit 42, exploits the inherent trust workers place in internal IT channels. This is a significant social engineering threat that bypasses technical controls by targeting human behaviour directly. Security Architect’s Take: Restrict who can initiate external or guest Teams calls with employees, and enforce a policy requiring remote support sessions to be initiated only through your official ITSM platform — not ad-hoc Teams requests. Ensure EDR solutions are tuned to alert on remote access tool installation triggered via Teams processes, and consider disabling Teams guest and federated access if not operationally required. ...

7 July 2025 · ZX Cloud Security

China-Linked Hackers Exploit Roundcube CVE-2024-42009

🟠 High | Source: The Hacker News A suspected China-aligned threat group is actively exploiting a critical, now-patched vulnerability (CVE-2024-42009, CVSS 9.3) in Roundcube webmail to steal credentials from physics and engineering departments at US and Canadian universities. The campaign highlights the ongoing targeting of academic institutions, likely for intellectual property theft. Roundcube’s widespread use in academia and self-hosted environments makes this a significant concern for organisations that have not yet applied available patches. ...

7 July 2025 · ZX Cloud Security

CVE-2026-9080: Azure UAF Socket Callback Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-9080 is a Use-After-Free (UAF) vulnerability triggered during a pause in a socket callback, which can allow an attacker to execute arbitrary code or cause a system crash by exploiting memory that has already been freed. UAF vulnerabilities are particularly dangerous because they can be leveraged to corrupt memory and potentially escalate privileges or achieve remote code execution. This vulnerability affects Azure-hosted workloads and warrants prompt attention from teams running network-facing services. ...

7 July 2025 · ZX Cloud Security

CVE-2026-8926: Azure Password Leak via netrc & URL

🟠 High | Source: Microsoft Security Response Center CVE-2026-8926 is a vulnerability in which passwords can be inadvertently exposed when a URL contains both user credentials and a .netrc file reference, potentially allowing an attacker to harvest plaintext credentials. This affects Azure-related tooling or SDKs that process such URLs. The risk is significant because credential leakage can lead to unauthorised access to cloud resources and sensitive data. Security Architect’s Take: Audit any automation pipelines, scripts, or CI/CD workflows that construct URLs with embedded credentials or rely on .netrc files for authentication — migrate to token-based or managed identity authentication immediately, and rotate any credentials that may have been exposed. ...

7 July 2025 · ZX Cloud Security

CVE-2026-8286: Azure STARTTLS Connection Reuse Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-8286 is a vulnerability related to incorrect reuse of STARTTLS connections, which is a mechanism used to upgrade plain-text connections to encrypted ones. When connections are improperly reused after the STARTTLS handshake, sensitive data or credentials may be exposed to a third party or subjected to a man-in-the-middle attack. This affects Azure-based services or components relying on the flawed STARTTLS implementation. Security Architect’s Take: Review any Azure services or workloads that rely on STARTTLS for securing communications (e.g. SMTP, IMAP, or LDAP over TLS) and apply Microsoft’s patch promptly. Additionally, consider enforcing explicit TLS rather than STARTTLS opportunistic encryption where possible to reduce the attack surface. ...

7 July 2025 · ZX Cloud Security

CVE-2026-8458: Azure Credential Reuse Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-8458 is a vulnerability in Microsoft Azure involving the incorrect reuse of credentials or tokens across different services, which can lead to unintended cross-service access. This type of flaw can allow an attacker — or a misconfigured service — to leverage authentication material intended for one service to access another, potentially exposing sensitive resources. The issue is significant in cloud environments where service-to-service authentication is widespread. ...

7 July 2025 · ZX Cloud Security

CVE-2026-8924: Azure Trailing Dot Domain Super Cookie Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-8924 describes a vulnerability involving trailing dot domains being used to set ‘super cookies’ that can bypass normal cookie scoping boundaries. This can allow an attacker to set cookies that are unexpectedly shared across subdomains or services, potentially leading to session hijacking or cross-site data leakage. The issue is particularly concerning in multi-tenant cloud environments where domain boundaries are relied upon for isolation. ...

7 July 2025 · ZX Cloud Security

CVE-2026-8932: Azure mTLS Connection Reuse Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-8932 is a vulnerability in Azure involving incomplete mutual TLS (mTLS) configuration matching during connection reuse. When connections are reused, the system may fail to correctly validate mTLS settings, potentially allowing a connection authenticated under one certificate policy to be reused in a context where a different, stricter policy should apply. This could result in unintended access or information disclosure between workloads that rely on mTLS for mutual authentication. ...

7 July 2025 · ZX Cloud Security

CVE-2026-9545: Azure HTTP/3 Early Data Exposure

🟠 High | Source: Microsoft Security Response Center CVE-2026-9545 is a vulnerability in HTTP/3 early data (also known as 0-RTT data) handling within Microsoft Azure, which could expose sensitive request data to attackers. Early data in HTTP/3 is replayed before a full TLS handshake is complete, making it susceptible to replay attacks and potential information disclosure. This matters because Azure-hosted applications using HTTP/3 could inadvertently leak user data or session information without any direct user interaction. ...

7 July 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options