CVE-2026-58012: GLib Buffer Over-Read in Azure Workloads

🟠 High | Source: Microsoft Security Response Center CVE-2026-58012 is a buffer over-read vulnerability in GLib’s regular expression handling, specifically in the g_regex_replace() function within the gregex.c component. An attacker could potentially exploit this to read data beyond allocated memory boundaries, which may lead to information disclosure or application instability. GLib is a widely used foundational library across Linux-based systems and cloud workloads, making the potential blast radius significant. Security Architect’s Take: Audit Azure Linux-based workloads and container images for GLib dependencies and prioritise patching to a remediated version; also review any custom applications that invoke GLib regex functions, as these may be directly exposed to untrusted input. ...

1 July 2025 Â· ZX Cloud Security

CVE-2026-58016: GLib Integer Underflow in Azure Workloads

🟠 High | Source: Microsoft Security Response Center CVE-2026-58016 is an integer underflow vulnerability in GLib’s D-Bus XML introspection parser, specifically in the ‘g_dbus_node_info_new_for_xml’ function. An attacker supplying maliciously crafted XML could trigger memory corruption, potentially leading to a crash or arbitrary code execution in any service that processes D-Bus introspection data. This affects workloads running on Azure that rely on GLib, a widely used C library present in many Linux environments. ...

1 July 2025 Â· ZX Cloud Security

CVE-2026-58015: GLib Path Traversal Flaw on Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-58015 is a path traversal vulnerability in GLib’s D-Bus authentication mechanism, specifically within the SHA-1 keyring handling code. An attacker exploiting this flaw could potentially access or manipulate files outside of intended directories during D-Bus authentication operations. This affects workloads and services running on Azure that depend on GLib’s GIO library, which is common in Linux-based environments. Security Architect’s Take: Audit Azure Linux VMs, containers, and managed services that use GLib — particularly those exposing D-Bus interfaces — and prioritise patching to a remediated GLib version. If immediate patching is not feasible, consider restricting D-Bus surface exposure through network segmentation and least-privilege service configurations. ...

1 July 2025 Â· ZX Cloud Security

CVE-2026-58010: GLib Buffer Over-Read in Azure Linux

🟠 High | Source: Microsoft Security Response Center CVE-2026-58010 is a buffer over-read vulnerability in GLib, a core open-source library widely used across Linux-based systems, triggered via the gvs_tuple_is_normal() function in the GVariant serialiser component. An attacker could potentially exploit this to read out-of-bounds memory, leading to information disclosure or application instability. This is particularly relevant to Azure workloads running Linux VMs or containers that depend on GLib. Security Architect’s Take: Audit Linux-based Azure workloads — including VMs, AKS nodes, and container images — for vulnerable versions of GLib and prioritise patching via your OS package manager or container base image rebuild pipeline. Ensure your vulnerability scanning tooling (e.g. Microsoft Defender for Cloud) is flagging this CVE against your inventory. ...

1 July 2025 Â· ZX Cloud Security

Azure CLI Password Spray Attack: 78 Accounts Compromised

🟠 High | Source: The Hacker News A large-scale automated password spray attack is actively targeting Microsoft Azure’s command-line interface (CLI), with over 81 million login attempts recorded between 12 and 26 June, compromising at least 78 accounts. The attack originates from an IPv6 range linked to infrastructure provider LSHIY LLC and is ongoing. This is significant because Azure CLI access can grant broad programmatic control over cloud resources, making compromised accounts a serious risk. ...

1 July 2025 Â· ZX Cloud Security

ClickFix Malware Now Uses APIs to Evade Detection

🟠 High | Source: The Hacker News ClickFix is a social engineering technique that tricks users into manually executing malware by disguising commands as CAPTCHA-style verification steps. New research analysing 3,000 live payloads reveals the operation has matured significantly, with API-driven infrastructure serving uniquely obfuscated malware variants to each visitor to evade signature-based detection. A newly discovered delivery method has also been identified that is specifically designed to bypass Windows’ built-in script scanning capabilities. ...

1 July 2025 Â· ZX Cloud Security

Citrix NetScaler Flaws CVE-2026-8451: Patch Now

🟠 High | Source: The Hacker News Citrix has released patches for six vulnerabilities in NetScaler ADC and NetScaler Gateway, the most severe of which (CVE-2026-8451, CVSS 8.8) stems from insufficient input validation and could allow attackers to read arbitrary files or crash affected systems. These products are widely deployed as network edge components, making them high-value targets. Unpatched instances exposed to the internet are at meaningful risk of exploitation. Security Architect’s Take: Prioritise patching NetScaler ADC and NetScaler Gateway instances immediately, particularly any internet-facing deployments — review Citrix’s advisory for affected version ranges and apply the latest builds. In the interim, consider restricting management interface access to trusted IP ranges and reviewing WAF rules to limit exposure. ...

1 July 2025 Â· ZX Cloud Security

Microsoft: Poisoned MCP Tools Can Make AI Agents Leak Data

🟠 High | Source: The Hacker News Microsoft researchers have demonstrated how attackers can manipulate AI agents by embedding malicious instructions inside MCP (Model Context Protocol) tool descriptions, causing the agent to silently exfiltrate sensitive company data without triggering standard security alerts. Because the agent follows its programmed logic at every step, the behaviour appears entirely routine. This highlights a significant emerging attack surface as organisations increasingly deploy AI agents with access to internal systems and data. ...

30 June 2025 Â· ZX Cloud Security

RustDuck Botnet Hijacks Routers & Servers for DDoS

🟠 High | Source: The Hacker News RustDuck is a rapidly evolving two-stage botnet, written in Rust, that compromises home routers, IP cameras, Android boxes, and exposed servers to form a DDoS-for-hire network. Tracked by QiAnXin XLab since February 2026, its most concerning trait is the speed at which it is being updated and rewritten, suggesting active, well-resourced development. The use of Rust makes detection and reverse engineering harder, raising the threat level compared to older C-based botnets. ...

30 June 2025 Â· ZX Cloud Security

Huntress Insider Threat: Employee Tipped Off Ransomware Gang

🟠 High | Source: The Register — Security A Huntress threat hunter allegedly warned a ransomware criminal that law enforcement were investigating them, prompting the company’s CEO to publicly describe the act as ‘poor judgment’. A former employee has gone further, characterising the behaviour as a textbook insider threat. The incident raises serious questions about trust, vetting, and access controls within security operations teams. Security Architect’s Take: Review your security operations team’s access to sensitive investigation data and law enforcement liaison channels — consider need-to-know access controls, audit logging on case management platforms, and clear whistleblower and escalation policies to reduce insider risk exposure. ...

30 June 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options