Silent Swap Crypto Clipper: Fake Browser Extension Alert

🟠 High | Source: The Hacker News A malicious browser extension posing as Google Notes is actively stealing cryptocurrency by silently replacing wallet addresses during transactions — a technique known as ‘clipping’. Distributed via unsigned installers in both .NET and Golang variants, the campaign (dubbed Silent Swap by McAfee Labs) targets users across multiple browsers. It is particularly dangerous because victims have no visible indication that their funds are being redirected until it is too late. ...

30 June 2025 Â· ZX Cloud Security

GuardFall: AI Coding Agents Vulnerable to Shell Injection

🟠 High | Source: The Hacker News A newly disclosed bypass technique called GuardFall allows attackers to circumvent the safety guardrails built into AI coding agents using decades-old shell injection tricks. Adversa AI tested eleven popular open-source coding and computer-use agents and found ten were vulnerable, meaning malicious prompts or inputs could cause these agents to execute dangerous commands on a host system. This is significant because AI coding agents are increasingly used in development pipelines with broad access to codebases, terminals, and cloud credentials. ...

30 June 2025 Â· ZX Cloud Security

CVE-2026-42910 Windows Hotpatch EoP Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-42910 is an elevation of privilege vulnerability in the Windows Hotpatch Monitoring Service, which is used in Azure environments to apply live patches without rebooting virtual machines. An attacker exploiting this flaw could gain elevated permissions on an affected system, potentially moving laterally or escalating access within a cloud environment. This update is an acknowledgement change only and contains no new technical detail or patch. ...

30 June 2025 Â· ZX Cloud Security

282 iOS AI Apps Leak API Keys in Traffic Study

🟠 High | Source: The Hacker News A study of 444 iPhone AI chatbot apps found that 282 of them — roughly 63% — exposed paid AI API keys or unauthenticated backend proxies in their network traffic. Attackers intercepting this traffic could make model requests billed to the developer’s account at no cost to themselves. The scale of exposure suggests a systemic failure in how mobile developers handle API credential security. ...

30 June 2025 Â· ZX Cloud Security

FIFA 2026 Cyber Threats: What the Numbers Reveal

🟠 High | Source: The Hacker News Threat actors began building fraud infrastructure targeting the FIFA World Cup 2026 months before the tournament opened on 11 June, according to Check Point Research. The campaign spans at least ten languages and three sectors, indicating a highly coordinated, pre-planned operation. The scale and preparation time suggest significant risk to fans, sponsors, and organisations with any association to the event. Security Architect’s Take: Review and tighten brand protection controls and domain monitoring for any organisational assets associated with FIFA 2026 — including ticketing, hospitality, and sponsor-related services. Ensure phishing simulation and user awareness programmes account for high-profile sporting event lures, and validate that cloud-hosted web properties have WAF and bot management controls in place. ...

30 June 2025 Â· ZX Cloud Security

AirDrop & Quick Share Flaws: Crash Attacks via Wi-Fi

🟠 High | Source: The Hacker News Six security vulnerabilities have been discovered in Apple AirDrop and Google Quick Share, the wireless file-transfer features built into macOS, iOS, and Android devices. An attacker within Wi-Fi or Bluetooth range can crash the sharing service on devices configured to receive from anyone, requiring no prior pairing, authentication, or user interaction. The flaws pose a real risk in high-density environments such as offices, conferences, and public spaces where corporate devices are common. ...

30 June 2025 Â· ZX Cloud Security

BioShocking Attack: AI Browsers Tricked Into Leaking Credent

🟠 High | Source: The Hacker News Security firm LayerX has demonstrated a technique called ‘BioShocking’ that manipulates AI-powered browsers and assistants into handing over a user’s login credentials by convincing them they are participating in a game scenario. Six AI browsers were successfully exploited, including ChatGPT Atlas, Perplexity’s Comet, and Anthropic’s Claude browser extension. The attack highlights a fundamental risk in AI agents that have access to sensitive browser data and can be socially engineered through prompt manipulation. ...

30 June 2025 Â· ZX Cloud Security

CVE-2026-11979: libxml2 Buffer Overflow Hits Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-11979 is a stack-based buffer overflow vulnerability in libxml2, a widely used open-source XML parsing library. Microsoft has flagged this as affecting Azure services, meaning cloud workloads dependent on libxml2 could be exposed to potential code execution or crash-inducing exploits. Buffer overflow flaws of this nature can allow attackers to execute arbitrary code if exploited successfully. Security Architect’s Take: Audit your Azure-hosted workloads and container images for dependencies on libxml2 and apply any available patches immediately; also review your software composition analysis (SCA) tooling to ensure libxml2 vulnerabilities are flagged across your CI/CD pipelines. ...

30 June 2025 Â· ZX Cloud Security

CVE-2026-41992: GNU gzip Buffer Overflow on Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-41992 is a global buffer overflow vulnerability in GNU gzip, a widely used data compression utility. Buffer overflow flaws can allow attackers to crash applications or, in more severe cases, execute arbitrary code on affected systems. Microsoft has published this advisory via the MSRC, indicating it has relevance to Azure services or components that bundle gzip. Security Architect’s Take: Identify any Azure-hosted workloads, container images, or VM deployments that include GNU gzip and apply vendor patches promptly. Review your software composition analysis (SCA) tooling to flag gzip as a tracked dependency across your supply chain. ...

30 June 2025 Â· ZX Cloud Security

CVE-2026-54371: attr Symlink Traversal Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A symlink traversal vulnerability in the ‘attr’ package (versions below 2.6.0) allows an attacker to perform privilege escalation via the getfattr and setfattr utilities. By crafting a malicious symlink, a local attacker could read or modify extended file attributes outside their permitted scope, potentially gaining elevated privileges on affected systems. This is particularly relevant to Azure environments where Linux-based workloads or container images rely on this package. ...

30 June 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options