AdaptHealth Cloud Breach: Social Engineering Hits Vendor

🟠 High | Source: The Register — Security AdaptHealth, a US home healthcare equipment provider, suffered a data breach after attackers used social engineering to compromise a third-party contractor and gain access to cloud systems. The incident resulted in the theft of patient health information and insurance billing credentials. This highlights the persistent risk posed by vendor access to sensitive healthcare data held in cloud environments. Security Architect’s Take: Review and tighten third-party contractor access to cloud environments by enforcing just-in-time (JIT) privileged access, phishing-resistant MFA (e.g. FIDO2), and continuous monitoring of contractor sessions — never rely on credential-based trust alone for suppliers handling regulated data. ...

3 July 2025 Â· ZX Cloud Security

CVE-2026-14125: ANGLE Uninitialized Use in Microsoft Edge

🟠 High | Source: Microsoft Security Response Center A vulnerability involving uninitialized memory use has been identified in ANGLE, the graphics abstraction layer used by Chromium-based browsers including Microsoft Edge. Because Edge is built on Chromium, it inherits this flaw, which could potentially allow an attacker to exploit memory corruption to execute arbitrary code or leak sensitive data via a malicious web page. Google has issued a fix through Chrome, and Microsoft is tracking the update for Edge. ...

3 July 2025 Â· ZX Cloud Security

CVE-2026-13775: Use After Free in Chromium GPU – Edge

🟠 High | Source: Microsoft Security Response Center A use-after-free vulnerability in the Chromium GPU component has been assigned CVE-2026-13775 by the Chrome team. Microsoft Edge, being Chromium-based, is affected and will receive a fix via its Chromium ingestion pipeline. Use-after-free flaws in GPU processing can potentially be exploited to achieve arbitrary code execution within the browser process. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest stable release across all managed endpoints and virtual desktop environments, including Azure Virtual Desktop deployments. Prioritise updates on privileged workstations where browser compromise could lead to credential theft or lateral movement into cloud environments. ...

3 July 2025 Â· ZX Cloud Security

CVE-2026-14153: Chromium Glic Flaw Affects Microsoft Edge

🟠 High | Source: Microsoft Security Response Center A vulnerability identified as CVE-2026-14153 has been found in the Glic component of Chromium, involving an inappropriate implementation flaw. Microsoft Edge, which is built on the Chromium engine, is affected and has received a patch via the upstream Chromium project. Organisations using Edge-based browsers in their environment should apply the latest update to mitigate potential exploitation. Security Architect’s Take: Ensure Microsoft Edge is updated to the latest Chromium-based release across all managed endpoints and virtual desktop environments, particularly where users access cloud management consoles or sensitive web applications. Consider enforcing browser update policies via Intune or Group Policy to reduce the window of exposure. ...

3 July 2025 Â· ZX Cloud Security

CVE-2026-56646: Microsoft Edge Spoofing Vulnerability

🟠 High | Source: Microsoft Security Response Center A spoofing vulnerability in Microsoft Edge (Chromium-based) allows an unauthenticated attacker to expose sensitive information and impersonate content or actors over a network. The flaw stems from improper exposure of sensitive data to unauthorised parties. This is particularly relevant in enterprise environments where Edge is used to access cloud portals, internal tooling, or sensitive web applications. Security Architect’s Take: Ensure Microsoft Edge is updated to the patched version across all managed endpoints via Intune, SCCM, or equivalent MDM tooling, prioritising devices with access to Azure portals, M365, or other sensitive cloud resources. Consider monitoring for anomalous network-based spoofing activity as an interim control. ...

3 July 2025 Â· ZX Cloud Security

CVE-2026-57983: Microsoft Edge Security Bypass Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-57983 is a security feature bypass vulnerability in Microsoft Edge (Chromium-based), caused by improper authorisation checks that allow a remote, unauthenticated attacker to circumvent browser security controls over a network. This type of vulnerability can be exploited to undermine protections such as mixed content blocking, site isolation, or other trust boundaries that Edge enforces. Although it targets a browser rather than a cloud platform directly, organisations using Edge to access Azure portals, cloud consoles, and web-based tools face elevated risk. ...

3 July 2025 Â· ZX Cloud Security

CVE-2026-57985: Microsoft Edge RCE Vulnerability

🟠 High | Source: Microsoft Security Response Center A remote code execution vulnerability (CVE-2026-57985) has been identified in Microsoft Edge (Chromium-based), caused by improper input validation. An unauthenticated attacker could exploit this flaw over a network to execute arbitrary code on a victim’s machine. This poses a significant risk in enterprise environments where Edge is widely deployed, particularly for users accessing cloud management portals and internal tooling. Security Architect’s Take: Prioritise pushing the latest Edge update to all managed endpoints via Intune or your preferred patch management tooling — pay particular attention to privileged users such as cloud admins who routinely access Azure Portal, AWS Console, or GCP Console through the browser. Consider enforcing browser version compliance policies to block access from unpatched Edge versions to sensitive cloud resources. ...

3 July 2025 Â· ZX Cloud Security

CVE-2026-57987: Microsoft Edge SSRF Spoofing Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-57987 is a server-side request forgery (SSRF) vulnerability in Microsoft Edge (Chromium-based) that allows an unauthenticated attacker to perform spoofing attacks over a network. SSRF flaws can be exploited to make the victim’s browser or an associated server-side component issue requests to internal or unintended external resources on the attacker’s behalf. This is particularly concerning in enterprise environments where Edge is used to access cloud management portals or internal services. ...

3 July 2025 Â· ZX Cloud Security

CVE-2026-57993: Microsoft Edge SSRF Spoofing Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-57993 is a server-side request forgery (SSRF) vulnerability in Microsoft Edge (Chromium-based) that allows an unauthenticated attacker to conduct spoofing attacks over a network. SSRF flaws can be exploited to make the affected application issue requests on behalf of the attacker, potentially reaching internal services or cloud metadata endpoints. This is particularly relevant in enterprise environments where Edge is widely deployed and used to access cloud-hosted resources. ...

3 July 2025 Â· ZX Cloud Security

CVE-2026-58282: Microsoft Edge Spoofing Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-58282 is a spoofing vulnerability in Microsoft Edge (Chromium-based) caused by improper access controls, allowing a network-based attacker to impersonate content or UI elements without authorisation. This could be exploited to deceive users into trusting malicious content, potentially leading to credential theft or phishing attacks. While browser-focused, the risk extends to enterprise environments where Edge is the standard browser for accessing cloud services and internal tooling. ...

3 July 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options