CVE-2026-54369: Linux ACL Symlink Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A symlink traversal vulnerability in the Linux ACL (Access Control List) library versions prior to 2.4.0 allows attackers to exploit libacl functions to escalate privileges on affected systems. By manipulating symbolic links, a local attacker could gain elevated permissions beyond their intended access level. This is particularly relevant to Azure workloads running Linux-based virtual machines or containers that rely on the acl package. ...

30 June 2025 · ZX Cloud Security

Apple Patches 30+ Flaws Including AI-Found WebKit Bugs

🟠 High | Source: The Hacker News Apple has released security updates for iOS, macOS, and Safari addressing over 30 vulnerabilities, including four WebKit flaws discovered using AI tools such as Anthropic Claude and OpenAI Codex Security. WebKit vulnerabilities are particularly significant as they affect the browser engine underpinning Safari and all iOS browsers, with memory corruption issues potentially enabling remote code execution. This release is notable for marking a mainstream shift towards AI-assisted vulnerability research in production security tooling. ...

30 June 2025 · ZX Cloud Security

India .bank Domain Registry API Leaked Bank Officials' Data

🟠 High | Source: The Register — Security The Reserve Bank of India mandated that banks use .bank.in domains to boost trust and reduce phishing, but the registry managing those domains exposed an open API leaking sensitive registrant data — including contact details and organisational information about bank officials. This undermines the very trust mechanism it was designed to create, giving attackers everything needed to craft convincing impersonation attacks. Security Architect’s Take: If your organisation operates in or integrates with Indian financial services, review any third-party domain registry dependencies for unauthenticated API exposure. More broadly, this is a reminder that trust infrastructure (domain registries, certificate authorities, identity providers) must itself be subjected to rigorous security assurance — treat them as critical supply chain components and assess their security posture accordingly. ...

30 June 2025 · ZX Cloud Security

LLM Prompt Injection via Role Abuse: What You Need to Know

🟠 High | Source: The Register — Security Security researchers demonstrated that large language models (LLMs) can be manipulated into producing harmful content — including drug synthesis instructions — by exploiting role-based prompt injection techniques. The attack works by assigning the LLM a persona or role that bypasses its safety guardrails. This highlights a persistent and structurally difficult class of vulnerability in AI systems deployed in enterprise and cloud environments. Security Architect’s Take: Review any LLM-powered application your organisation exposes to users and assess whether user-supplied input can influence the model’s system prompt or role context; implement strict prompt isolation, input sanitisation, and output filtering layers as defence-in-depth controls rather than relying solely on model-level safety training. ...

29 June 2025 · ZX Cloud Security

AWS WAF HTTP/2 Bypass: CVE-2026-13762 & CVE-2026-13763

🟠 High | Source: AWS Security Bulletins Two vulnerabilities (CVE-2026-13762 and CVE-2026-13763) were identified in AWS WAF’s handling of HTTP/2 multi-frame request bodies, potentially allowing crafted requests to bypass inspection. The CloudFront variant has been fully remediated server-side with no customer action needed, but the Application Load Balancer variant requires customers to explicitly configure how AWS WAF inspects HTTP/2 request bodies to ensure complete protection. Left unaddressed, the ALB issue could allow malicious payloads to pass through WAF rules undetected. ...

29 June 2025 · ZX Cloud Security

Fake Perplexity Chrome Extension Stole Search Data

🟠 High | Source: The Hacker News A malicious Chrome extension impersonating the AI search tool Perplexity was discovered by Microsoft, silently intercepting all search queries and address bar keystrokes and routing them through an attacker-controlled server. Users believed they were getting normal search results whilst their queries were being exfiltrated. Google has since removed the extension following responsible disclosure, but any users who installed it may have had sensitive searches or URLs captured. ...

29 June 2025 · ZX Cloud Security

Weak RSA Keys With Many Zeros Found in the Wild

🟠 High | Source: Schneier on Security Researchers have identified a new class of weak RSA keys characterised by an unusually high number of zero bits in the modulus, making them vulnerable to factorisation attacks. Analysis of real-world key datasets — including Certificate Transparency logs, TLS/SSH scans, and PGP keys — confirmed these vulnerable keys exist in production environments. If an attacker can factorise an RSA key, they can decrypt communications or forge signatures protected by that key. ...

29 June 2025 · ZX Cloud Security

Mustang Panda Abuses Zoho WorkDrive for C2

🟠 High | Source: The Hacker News Chinese state-aligned threat group Mustang Panda has been caught running two active espionage campaigns against Indian government and hydropower sector targets, using novel malware and abusing Zoho WorkDrive as a covert command-and-control channel. Acronis Threat Research Unit identified live compromises on machines belonging to senior Indian administrative staff. The abuse of a legitimate cloud productivity service makes detection significantly harder, as malicious traffic blends with normal business communications. ...

29 June 2025 · ZX Cloud Security

Linux Kernel Flaw, Turla Backdoor & AI Malware: Weekly Recap

🟠 High | Source: The Hacker News This weekly security recap covers several active threats including a Linux kernel vulnerability dubbed ‘DirtyClone’ that allows local privilege escalation, AI-assisted malware techniques, activity from the Turla APT group deploying backdoors, and a resurgence in infostealer campaigns. The breadth of threats underscores that attackers are exploiting both newly disclosed flaws and long-standing weaknesses. Defenders face a wide cleanup effort across patching, detection, and access control. ...

29 June 2025 · ZX Cloud Security

236,000 DCloud Uni-App Sites Used in Crypto Scams

🟠 High | Source: The Hacker News Infoblox researchers have identified over 236,000 websites built using DCloud Uni-App, a legitimate Chinese open-source development framework, that are being exploited to run cryptocurrency scams, phishing campaigns, and wallet-draining operations. These sites power pig-butchering fraud, fake exchanges, WhatsApp phishing networks, and brand impersonation at industrial scale. The abuse of a trusted, popular framework makes detection harder and lends a veneer of technical legitimacy to fraudulent infrastructure. ...

29 June 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options