CVE-2026-58283: Microsoft Edge Spoofing Vulnerability

🟠 High | Source: Microsoft Security Response Center A type confusion vulnerability in Microsoft Edge (Chromium-based) allows an attacker over a network to perform spoofing attacks without requiring authentication. Type confusion flaws occur when software processes data as the wrong type, potentially leading to unexpected and dangerous behaviour. This matters because Edge is widely deployed in enterprise environments, meaning a successful exploit could be used to impersonate trusted content or intercept user interactions. ...

3 July 2025 Â· ZX Cloud Security

CVE-2026-58287: Microsoft Edge RCE Vulnerability

🟠 High | Source: Microsoft Security Response Center A use-after-free memory vulnerability in Microsoft Edge (Chromium-based) allows a remote, unauthenticated attacker to execute arbitrary code on a victim’s machine over a network. Use-after-free flaws occur when a programme continues to use memory after it has been freed, which attackers can manipulate to gain code execution. This is particularly concerning as exploitation requires no prior authentication and can be triggered remotely. Security Architect’s Take: Ensure Edge is updated to the patched version immediately across all managed endpoints, prioritising internet-facing workstations and those used to access cloud management consoles such as the Azure Portal, as a compromised browser session could expose credentials or tokens with elevated cloud permissions. ...

3 July 2025 Â· ZX Cloud Security

CVE-2026-58299: Microsoft Edge Android RCE Flaw

🟠 High | Source: Microsoft Security Response Center A race condition vulnerability in Microsoft Edge for Android allows an attacker to remotely execute arbitrary code on affected devices over a network, without requiring any user authentication. The flaw stems from a time-of-check time-of-use (TOCTOU) weakness, where the timing gap between a security check and its corresponding action can be exploited. This is particularly concerning for organisations where employees use Android devices to access cloud resources or corporate data through Edge. ...

3 July 2025 Â· ZX Cloud Security

Armored Likho BusySnake Stealer Targets Gov & Energy

🟠 High | Source: The Hacker News A newly identified threat group called Armored Likho is conducting cyber attacks against government agencies and energy sector organisations in Russia, Brazil, and Kazakhstan using a malware strain dubbed BusySnake. The group is unusual in that it blends financially motivated attacks on individuals with targeted espionage campaigns against critical infrastructure. The combination of espionage and financial crime makes attribution and defence more complex. Security Architect’s Take: Review your organisation’s email gateway and endpoint controls for stealer malware indicators, particularly if you operate in government or energy sectors. Ensure cloud-hosted workloads and identity stores are monitored for credential harvesting activity, as stealers frequently exfiltrate cloud access tokens and session cookies. ...

3 July 2025 Â· ZX Cloud Security

NetNut Botnet Cracked: FBI & Google Hit 2M-Device Network

🟠 High | Source: The Register — Security Google and the FBI have taken action against a botnet of approximately 2 million compromised devices linked to the residential proxy service NetNut. Residential proxy networks of this scale are frequently abused to route malicious traffic — including credential stuffing, scraping, and fraud — through legitimate-looking IP addresses. The operation raises concerns that other residential proxy brands may be drawing on the same underlying compromised infrastructure. ...

3 July 2025 Â· ZX Cloud Security

EU Parliament Member Hacked with Pegasus Spyware

🟠 High | Source: The Hacker News Citizen Lab has confirmed that Stelios Kouloglou, a former Member of the European Parliament serving on the committee investigating spyware abuse, had his mobile device repeatedly compromised using NSO Group’s Pegasus spyware. The attack is particularly significant given that the target was actively scrutinising the misuse of commercial surveillance tools within the EU. This underscores the brazen use of state-grade spyware against democratic oversight mechanisms. ...

3 July 2025 Â· ZX Cloud Security

PamStealer macOS Malware Steals Login Passwords

🟠 High | Source: The Hacker News A new macOS information stealer called PamStealer is being distributed via fake websites impersonating Maccy, a popular open-source clipboard manager, using a compiled AppleScript file to compromise systems. Once installed, it abuses macOS’s Pluggable Authentication Module (PAM) framework to harvest login passwords and exfiltrate sensitive data. The threat is notable for its use of a trusted open-source tool as a lure and its exploitation of a legitimate OS authentication mechanism. ...

3 July 2025 Â· ZX Cloud Security

Google Warned Dev of Hijack – Then Billed $11k Anyway

🟠 High | Source: The Register — Security A developer reports that Google detected and warned him about an account hijack on his Google Cloud account, yet still processed approximately $11,000 in fraudulent charges run up by the attacker. The incident highlights a disconnect between Google’s threat detection and billing protection mechanisms, leaving the victim liable despite the provider being aware of the compromise. This is a cautionary tale about assuming cloud provider warnings automatically trigger financial safeguards. ...

2 July 2025 Â· ZX Cloud Security

FBI Seizes NetNut Proxy & Popa Botnet Domains

🟠 High | Source: Krebs on Security The FBI has seized hundreds of domains linked to NetNut, a residential proxy service run by Nasdaq-listed Israeli firm Alarum Technologies, following revelations that it was connected to the Popa botnet — a network of over two million compromised devices enrolled without meaningful user consent. Residential proxy networks like this are routinely abused to anonymise malicious traffic, making them a significant threat to cloud-based fraud detection, rate limiting, and access controls. The seizure follows investigative reporting by KrebsOnSecurity and coordinated action with industry partners. ...

2 July 2025 Â· ZX Cloud Security

Agentic AI Ransomware: First End-to-End Attack Demonstrated

🟠 High | Source: The Register — Security Researchers have demonstrated what is being described as the first fully autonomous, end-to-end ransomware attack driven by an AI agent, capable of executing the entire attack lifecycle without human involvement. The system leverages large language model (LLM) reasoning to make decisions, adapt to defences, and manage victim negotiations — raising the concern that paying a ransom may not result in data recovery if the AI mismanages decryption keys. This marks a significant escalation in the threat landscape, lowering the skill barrier for ransomware operators whilst increasing attack speed and scale. ...

2 July 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options