Moody Bible Institute Breach: 2.3M Records Leaked

🟠 High | Source: The Register — Security Moody Bible Institute has suffered a data breach affecting approximately 2.3 million accounts, with the ShinyHunters threat group leaking stolen records including names, addresses, and dates of birth. The incident highlights the ongoing risk posed by ShinyHunters, a prolific group responsible for numerous high-profile breaches. Educational and non-profit organisations with large user databases remain attractive targets due to historically weaker security postures. Security Architect’s Take: Review your data minimisation and retention policies immediately — storing DOBs and addresses at scale creates significant breach liability. Ensure sensitive PII is encrypted at rest with customer-managed keys, and validate that your threat detection tooling covers exfiltration patterns consistent with ShinyHunters TTPs. ...

6 July 2025 · ZX Cloud Security

QuimaRAT MaaS RAT Targets Windows, Linux & macOS

🟠 High | Source: The Hacker News QuimaRAT is a new Java-based remote access trojan sold as a subscription service, capable of compromising Windows, Linux, and macOS systems. Its cross-platform design makes it particularly dangerous in cloud and hybrid environments where mixed operating systems are common. Priced from £150/month, its low barrier to entry means a wide range of threat actors can deploy it. Security Architect’s Take: Audit your cloud workloads for unauthorised Java runtimes and ensure EDR coverage extends to Linux-based instances and containers, as these are frequently under-monitored. Block outbound connections from compute instances to known MaaS infrastructure using egress filtering and enforce application allowlisting where feasible. ...

6 July 2025 · ZX Cloud Security

Opera GX Flaw: Malicious Sites Auto-Install Data-Stealing Mo

🟠 High | Source: The Hacker News A vulnerability in Opera GX allowed malicious websites to silently install browser extensions without user interaction, which could then extract data from pages the victim visited. Researchers demonstrated the flaw by reconstructing a user’s full Gmail address from a single page visit with no clicks required. Opera has since patched the issue and reports no evidence of active exploitation. Security Architect’s Take: Organisations permitting Opera GX on managed endpoints should verify the patched version is deployed via endpoint management tooling. More broadly, review browser extension governance policies — consider blocking unapproved extension installs via browser enterprise policy or EDR controls, particularly for browsers used in cloud console access. ...

6 July 2025 · ZX Cloud Security

SkillCloak: Malicious AI Agent Skills Evade Scanners

🟠 High | Source: The Hacker News Researchers at Hong Kong University of Science and Technology have demonstrated a technique called SkillCloak that uses self-extracting packing to disguise malicious add-on ‘skills’ for AI coding agents, bypassing static security scanners over 90% of the time. This is significant because AI coding agents such as GitHub Copilot and Cursor increasingly rely on third-party skills or plugins, creating a new supply chain attack surface. The same research team also developed a runtime detection tool that catches the majority of evasion attempts. ...

6 July 2025 · ZX Cloud Security

MFA-Optional Banks Risk Customer Accounts

🟠 High | Source: The Register — Security A number of banks are offering multi-factor authentication (MFA) as an optional rather than mandatory control, leaving customer accounts vulnerable to credential-based attacks. This practice prioritises user convenience over security, creating an easily exploitable gap that threat actors can abuse through phishing, credential stuffing, or brute force. Given the sensitivity of financial data and the regulatory environment in the UK, this represents a significant risk to both consumers and institutions. ...

5 July 2025 · ZX Cloud Security

Kairos Data Extortion: US Gov Pays $1M Ransom

🟠 High | Source: The Hacker News A US government entity paid approximately $1 million to a threat actor group called Kairos to prevent stolen files being publicly leaked. Unusually, Kairos appears to operate purely as a data extortion group with no evidence of ransomware or file encryption — making this a pure exfiltration-and-extort model. The case is notable because it demonstrates that organisations are willing to pay significant sums even without the additional pressure of encrypted systems. ...

4 July 2025 · ZX Cloud Security

North Korean PolinRider: 108 Malicious npm & Chrome Packages

🟠 High | Source: The Hacker News North Korean threat actors behind the Contagious Interview campaign have published 108 malicious packages and browser extensions across npm, Packagist, Go, and Chrome in an active campaign dubbed PolinRider. The attackers are compromising legitimate maintainer accounts to distribute malware through trusted package repositories. This is a supply chain attack targeting developers who install seemingly legitimate dependencies. Security Architect’s Take: Audit your CI/CD pipelines and developer workstations for recently installed npm, Go, or Packagist packages, and enforce allowlisting of approved dependencies via a private registry or lock file integrity checks. Implement runtime behavioural monitoring on build agents and restrict outbound network access from CI environments to limit the blast radius of any compromise. ...

4 July 2025 · ZX Cloud Security

FatFs Flaws Expose Millions of Embedded Devices

🟠 High | Source: The Hacker News Security researchers at runZero have disclosed seven unpatched vulnerabilities in FatFs, a widely embedded filesystem library used to handle FAT and exFAT storage formats. The library ships inside firmware for security cameras, drones, industrial controllers, and hardware crypto wallets, meaning the attack surface spans millions of physical devices globally. Because the flaws remain unpatched, any device processing untrusted storage media such as USB drives or SD cards could be at risk. ...

3 July 2025 · ZX Cloud Security

Avalon Malware Framework: CrownX Ransomware Threat

🟠 High | Source: The Hacker News A newly discovered malware framework called Avalon bundles ransomware, credential theft, lateral movement, and remote access capabilities into a single modular toolkit, delivered via a multi-stage phishing campaign designed to evade conventional security tools. The integrated CrownX ransomware component adds data encryption and recovery disruption to an already broad attack surface. Its modular design means threat actors can tailor attacks to specific environments, increasing the risk to enterprise and cloud workloads alike. ...

3 July 2025 · ZX Cloud Security

North Korea npm Supply Chain Attack Targets Devs

🟠 High | Source: The Hacker News North Korea-linked threat actors have published malicious npm packages that impersonate legitimate Rollup polyfill tooling, enabling remote access and credential theft from developer machines. The packages closely mimic the real ‘rollup-plugin-polyfill-node’ project, including metadata and repository details, making them difficult to spot. This is a software supply chain attack targeting developers who may unknowingly install the counterfeit packages. Security Architect’s Take: Audit your CI/CD pipelines and developer workstations for the packages ‘rollup-packages-polyfill-core’ and ‘rollup-runtime-polyfill-core’, and remove them immediately. Enforce package allowlists or integrity checks (e.g. via npm audit, Artifactory Xray, or Socket.dev) to prevent unapproved packages entering your build environments. ...

3 July 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options