Gamaredon APT Abuses Cloud Services in Ukraine Attacks

🟠 High | Source: The Hacker News Russian APT group Gamaredon has significantly expanded its cyberattacks against Ukrainian targets throughout 2025, deploying new malware variants and abusing legitimate cloud services as part of 35 distinct spear-phishing campaigns observed by ESET. The group’s continued evolution of its toolset demonstrates a sustained and adaptive threat posture against Ukrainian organisations. Cloud service abuse is particularly notable as it allows malicious traffic to blend with legitimate activity, complicating detection. ...

29 June 2025 Â· ZX Cloud Security

Nissan Oracle PeopleSoft Breach: SSNs & Payroll Exposed

🟠 High | Source: The Register — Security Nissan has disclosed a breach of its Oracle PeopleSoft HR and payroll systems, potentially exposing employee Social Security Numbers and payroll records. The intrusion exploited an as-yet-unidentified vulnerability in the PeopleSoft platform. This is a significant incident given the sensitivity of the data involved and the scale of Nissan’s workforce. Security Architect’s Take: Audit all internet-facing PeopleSoft instances immediately — review patch levels, check for unauthenticated access paths, and validate network segmentation between PeopleSoft and core HR/payroll data stores. If PeopleSoft is hosted on-premises or via Oracle Cloud, ensure privileged access logging and anomaly detection are active and alerts are being reviewed. ...

29 June 2025 Â· ZX Cloud Security

Microsoft StegoAd: 119 Malicious Edge Extensions Removed

🟠 High | Source: The Hacker News Microsoft removed 119 malicious extensions from its Edge Add-ons store that used steganography to hide malware payloads inside image and font files, evading detection until days after installation. Dubbed StegoAd, the campaign combined credential theft with ad fraud and is attributed to a single threat actor active since at least 2021. The delayed activation technique was specifically designed to bypass automated security scanning at the point of submission. ...

29 June 2025 Â· ZX Cloud Security

CVE-2026-58058: Nmap IPv6 Integer Underflow Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-58058 is an integer underflow vulnerability in Nmap’s IPv6 extension header parsing logic. An attacker could potentially craft a malicious IPv6 packet or response that triggers unexpected behaviour during a network scan, possibly leading to a crash or code execution within the scanning process. This matters because Nmap is widely used by security and operations teams to discover and audit cloud and on-premises infrastructure. ...

29 June 2025 Â· ZX Cloud Security

CVE-2026-58055: nghttp2 nghttpx HTTP Smuggling Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-58055 is an HTTP request/response smuggling vulnerability in nghttp2’s nghttpx reverse proxy component, triggered via HTTP Upgrade requests that include a Content-Length header. This class of vulnerability can allow attackers to poison shared connection caches, bypass security controls, or hijack requests between clients and backend services. It is particularly relevant to Azure-hosted workloads that use nghttp2-based proxies or HTTP/2 gateway components. Security Architect’s Take: Review any Azure workloads or container images using nghttpx as a reverse proxy or HTTP/2 front-end and prioritise patching to a fixed version of nghttp2. Additionally, audit WAF and API gateway configurations to ensure HTTP Upgrade requests with Content-Length headers are validated or blocked at the perimeter until patching is complete. ...

29 June 2025 Â· ZX Cloud Security

CVE-2026-58051: libssh2 Uninitialised Pointer Flaw on Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-58051 is a memory corruption vulnerability in libssh2, an open-source SSH library, involving the improper freeing of an uninitialised pointer during public key list cleanup. This type of flaw can potentially be exploited to crash an application or, in more severe cases, execute arbitrary code. The vulnerability is relevant to Azure environments and any services or workloads that depend on libssh2 for SSH connectivity. ...

29 June 2025 Â· ZX Cloud Security

CVE-2026-58050: libssh2 Integer Overflow in Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-58050 is an integer overflow vulnerability in the publickey subsystem of libssh2, an open-source SSH library used across many platforms and cloud environments, including Azure. Integer overflows in memory allocation routines can lead to heap corruption, potentially allowing an attacker to execute arbitrary code or crash affected services. This is particularly concerning because libssh2 is widely embedded in tooling, SDKs, and managed services. ...

29 June 2025 Â· ZX Cloud Security

CVE-2026-52908: Azure RDMA Memory Re-reg Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-52908 is a vulnerability in the Linux kernel’s RDMA (Remote Direct Memory Access) subsystem, specifically in the memory region re-registration process where access flags are not properly validated. This can allow incompatible access permissions to be set during a re-registration operation, potentially leading to unauthorised memory access or privilege escalation in environments using RDMA-capable hardware. Azure workloads leveraging high-performance networking or HPC (High Performance Computing) configurations may be exposed if the underlying host kernel is affected. ...

29 June 2025 Â· ZX Cloud Security

CVE-2026-52909 Azure Linux Kernel ip6_vti Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-52909 is a Linux kernel vulnerability affecting the IPv6 VTI (Virtual Tunnel Interface) subsystem, where the fallback device does not have the netns_immutable flag set. This can allow incorrect namespace handling, potentially leading to privilege escalation or unauthorised access across network namespaces in containerised or virtualised environments. Azure workloads running Linux-based virtual machines or container hosts may be exposed if unpatched kernel versions are in use. ...

29 June 2025 Â· ZX Cloud Security

CVE-2026-52910: Azure Linux Kernel BPF Use-After-Free

🟠 High | Source: Microsoft Security Response Center CVE-2026-52910 is a Linux kernel vulnerability affecting the Berkeley Packet Filter (BPF) subsystem, specifically how reuseport cBPF programmes are freed before an RCU (Read-Copy-Update) grace period completes. This can lead to use-after-free conditions, which may be exploitable to cause system instability or, in a worst case, allow privilege escalation within affected environments. Azure workloads running on Linux-based virtual machines or containers may be affected if the underlying kernel is unpatched. ...

29 June 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options