ChocoPoC RAT Targets Security Researchers via Fake GitHub Po

🟠 High | Source: The Hacker News A new remote access trojan called ChocoPoC is being distributed through fake proof-of-concept exploit repositories on GitHub, specifically targeting vulnerability researchers and bug hunters. When executed, the malware silently steals saved passwords, browser cookies, and files, whilst granting the attacker a persistent shell on the victim’s machine. The campaign is notable because it weaponises the trusted practice of sharing PoC code, turning researchers’ own workflows against them. ...

2 July 2025 Â· ZX Cloud Security

Snow Shovelling Red Team Gets Network Admin Access

🟠 High | Source: The Register — Security A red team exercise demonstrated how physical social engineering — in this case, helping a company by shovelling snow — led to attackers being granted network administrator access as a goodwill gesture. The engagement highlighted how human trust and informal helpfulness can completely bypass technical security controls. While this was a controlled test, the scenario reflects realistic attack vectors used by malicious actors. ...

2 July 2025 Â· ZX Cloud Security

EvilTokens BEC Kit: Device-Code Phishing Threat

🟠 High | Source: The Register — Security EvilTokens is a device-code phishing kit that has been revealed to be far more capable than initially understood, functioning as a full business email compromise (BEC) operations platform according to Cisco Talos researchers. It exploits the OAuth device authorisation flow to steal authentication tokens from victims without requiring them to enter credentials on a fake login page. This makes it particularly dangerous as it bypasses multi-factor authentication and can grant persistent access to Microsoft 365 and other cloud services. ...

1 July 2025 Â· ZX Cloud Security

DeepSeek Generates In-Browser Ransomware on Request

🟠 High | Source: The Register — Security Check Point researchers demonstrated that DeepSeek, a Chinese AI model, can be prompted with minimal effort to generate functional in-browser ransomware code, despite ostensibly having safety guardrails. The AI produced attack code that could be refined into a fully working ransomware payload, highlighting serious jailbreak risks in large language models used by developers. This matters because organisations increasingly rely on AI coding assistants, and if those tools can be trivially weaponised, they become a direct enabler of cyber attacks. ...

1 July 2025 Â· ZX Cloud Security

CVE-2026-14265: AWS JDBC Wrapper RCE via Cache

🟠 High | Source: AWS Security Bulletins A deserialization vulnerability (CVE-2026-14265) has been identified in the AWS Advanced JDBC Wrapper’s RemoteQueryCachePlugin, affecting versions 3.3.0 through 4.0.0. When the plugin is enabled, query results retrieved from a shared Redis or Valkey cache are deserialized without any class filtering, meaning an attacker with write access to that cache could plant a malicious serialized object and achieve remote code execution on the application server. The blast radius is significant for any application using this plugin with a shared, multi-tenant or externally accessible cache. ...

1 July 2025 Â· ZX Cloud Security

Scattered Spider Member Extradited to Face US Charges

🟠 High | Source: The Hacker News Peter Stokes, a 19-year-old dual US-Estonian national, has been extradited from Finland to the United States to face federal charges linked to his alleged membership of Scattered Spider, a notorious cybercriminal group. Scattered Spider is responsible for high-profile attacks on major cloud and technology firms, typically using social engineering and SIM-swapping to bypass security controls. The extradition signals continued international law enforcement pressure on the group following earlier arrests. ...

1 July 2025 Â· ZX Cloud Security

CVE-2026-13760: AWS CDK NodejsFunction Command Injection

🟠 High | Source: AWS Security Bulletins A command injection vulnerability (CVE-2026-13760) in AWS CDK’s NodejsFunction Docker bundling pipeline allows an attacker who can control dependency version strings in a project’s package.json to execute arbitrary commands on the machine running the CDK toolchain. The flaw exists in versions of aws-cdk-lib prior to 2.260.0 and is exploited via shell metacharacters in the OsCommand helper during Docker-based bundling. While exploitation requires influence over the package.json contents, the impact on developer workstations and CI/CD pipelines could be severe. ...

1 July 2025 Â· ZX Cloud Security

CVE-2026-13769: AWS CLI World-Readable Credentials

🟠 High | Source: AWS Security Bulletins A vulnerability in the AWS CLI for Unix-like systems allowed credential and configuration files to be written with world-readable permissions, meaning any local user on the same host could read another user’s AWS credentials. This affects all AWS CLI v1 versions up to and including 1.44.77 and v2 versions up to and including 2.34.28. On multi-user systems, this could lead to credential theft and unauthorised access to AWS environments. ...

1 July 2025 Â· ZX Cloud Security

SEO Poisoning Campaign Deploys AsyncRAT via ScreenConnect

🟠 High | Source: The Hacker News Attackers are using SEO poisoning to push fake software download sites that serve malicious installers disguised as legitimate tools such as OBS Studio and Bandicam. Once a victim runs the installer, ScreenConnect is used to establish remote access before deploying AsyncRAT, a remote access trojan capable of data theft and persistent control. The campaign is described as large-scale and multilingual, significantly widening the potential victim pool. ...

1 July 2025 Â· ZX Cloud Security

Claude Desktop Hijacked via Prompt Injection Attack

🟠 High | Source: The Register — Security Security researchers successfully manipulated Claude Desktop, Anthropic’s AI assistant application, into acting as a covert agent by exploiting the inherent trust users place in AI tools. The attack demonstrates how AI assistants can be weaponised through prompt injection or similar techniques to perform malicious actions on behalf of an attacker without the user’s awareness. This matters because AI assistants are increasingly integrated into enterprise workflows, expanding the attack surface significantly. ...

1 July 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options