FortiBleed Opsec Fail Links INC and Lynx Ransomware Gangs

🟠 High | Source: The Register — Security Security researchers analysing logs from the FortiBleed exploitation campaign have identified an operational security failure that links at least one individual to both the INC and Lynx ransomware gangs simultaneously. The discovery was made by tracing login artefacts that exposed overlapping activity between the two groups. This matters because it suggests tighter affiliations between ransomware-as-a-service operations than previously understood, with potential implications for attribution and threat intelligence. ...

2 July 2025 Â· ZX Cloud Security

CVE-2026-26145: Azure Synapse Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A vulnerability in Microsoft Azure Synapse Analytics allows an attacker who already has some level of authorised access to gain higher privileges than intended, purely over the network. This is concerning because Azure Synapse often holds sensitive data pipelines and analytics workloads, meaning privilege escalation could expose critical data assets or enable lateral movement. Microsoft has issued a patch as part of their security update guidance. ...

2 July 2025 Â· ZX Cloud Security

CVE-2026-41106: M365 Copilot Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A vulnerability in Microsoft 365 Copilot allows an attacker to perform an open redirect, sending users to a malicious external site without authentication. This can be exploited over a network to elevate privileges, potentially granting unauthorised access to sensitive resources. The flaw is particularly concerning given Copilot’s deep integration with Microsoft 365 data and services. Security Architect’s Take: Review conditional access policies and ensure Copilot access is restricted to trusted, managed devices and identities. Monitor for anomalous redirect activity in M365 audit logs and consider temporarily scoping Copilot permissions until a patch is confirmed applied to your tenant. ...

2 July 2025 Â· ZX Cloud Security

CVE-2026-45499: Azure OpenAI SSRF Privilege Escalation

🟠 High | Source: Microsoft Security Response Center CVE-2026-45499 is a server-side request forgery (SSRF) vulnerability in Azure OpenAI that allows an already-authenticated attacker to escalate their privileges over a network. SSRF flaws can be used to make the vulnerable service send requests on the attacker’s behalf, potentially accessing internal resources or metadata endpoints that should be off-limits. Because the attacker only needs existing authorised access to exploit this, the risk to organisations using Azure OpenAI in production environments is significant. ...

2 July 2025 Â· ZX Cloud Security

CVE-2026-50521: Microsoft Edge RCE Vulnerability

🟠 High | Source: Microsoft Security Response Center A remote code execution vulnerability (CVE-2026-50521) has been identified in Microsoft Edge, the Chromium-based browser. An attacker exploiting this flaw could execute arbitrary code on a victim’s machine, potentially leading to full system compromise. Microsoft has released a patched version of Edge and is urging all users on supported versions to update immediately. Security Architect’s Take: Ensure endpoint management policies (via Intune, SCCM, or equivalent) enforce the patched Edge version across all managed devices, prioritising those used to access Azure portals, cloud consoles, or sensitive SaaS applications where browser compromise could expose privileged sessions or credentials. ...

2 July 2025 Â· ZX Cloud Security

CVE-2026-54998: Exchange Online Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A flaw in Microsoft Exchange Online allows an already-authenticated attacker to gain higher privileges than they should have, potentially accessing or manipulating mailboxes and data beyond their authorised scope. The vulnerability is exploitable over the network, meaning no local access is required. Because Exchange Online is a widely used cloud email platform, the blast radius across enterprise environments could be significant. Security Architect’s Take: Review audit logs in Microsoft Purview and Exchange Online for anomalous permission changes or unusual mailbox access patterns, particularly by accounts with lower baseline privileges. Ensure you have least-privilege role assignments in place and monitor for any unexpected changes to Exchange RBAC roles while Microsoft deploys a fix — as a SaaS service, patching is handled by Microsoft, but detective controls remain your responsibility. ...

2 July 2025 Â· ZX Cloud Security

CVE-2026-57100: Microsoft Entra SSRF Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A server-side request forgery (SSRF) vulnerability in Microsoft Entra’s Provisioning Service (SyncFabric) allows an already-authenticated attacker to escalate their privileges over a network. Because the attack originates from within an authorised context, it could be exploited by a compromised account or malicious insider to gain elevated access to identity provisioning workflows. This is particularly concerning given Entra’s central role in managing user identities and access across cloud and hybrid environments. ...

2 July 2025 Â· ZX Cloud Security

ToddyCat Umbrij Malware Abuses OAuth to Read Gmail

🟠 High | Source: The Hacker News A sophisticated threat actor known as ToddyCat has deployed new malware called Umbrij that exploits OAuth tokens and the Google API to silently access victims’ Gmail inboxes, targeting corporate email communications. The malware is designed for covert espionage, allowing attackers to read sensitive business correspondence without triggering standard login alerts. This matters because it bypasses traditional credential-based detection, making it difficult to spot with conventional monitoring. ...

2 July 2025 Â· ZX Cloud Security

Medtronic Data Breach: ShinyHunters Steals Patient Health Da

🟠 High | Source: The Register — Security Medtronic, a major medical device manufacturer producing pacemakers and insulin pumps, has notified patients that their health data may have been stolen in an attack by the ShinyHunters cybercrime group. The disclosure comes months after the breach occurred, raising concerns about the delayed notification of affected individuals. The incident exposes sensitive personal and medical data, carrying significant risks for patient privacy and potential downstream fraud. ...

2 July 2025 Â· ZX Cloud Security

AI Agents Expose Gaps in Identity Lifecycle Management

🟠 High | Source: The Hacker News Traditional Identity Governance and Administration (IGA) tools were designed around human employees with defined lifecycle events such as onboarding, role changes, and offboarding. AI agents operating as autonomous principals in enterprise environments lack these attributes, creating significant governance blind spots. As AI agent adoption accelerates, organisations risk accumulating unmanaged, over-privileged non-human identities that existing IGA frameworks cannot adequately govern. Security Architect’s Take: Audit your current IGA tooling to determine whether it can model non-human identities with dynamic, task-scoped permissions and automated deprovisioning triggers — if not, begin evaluating purpose-built NHI (Non-Human Identity) governance solutions or extend your PAM tooling to cover AI agent credentials and service accounts explicitly. ...

2 July 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options