Hijacked npm & Go Packages Deploy Python Infostealer

🟠 High |Ā Source: The Hacker News Attackers have hijacked legitimate npm and Go packages, weaponising them to deploy a Python-based infostealer across Windows, Linux, and macOS. The attack is notable for bypassing npm’s lifecycle script execution — a common detection vector — by using Visual Studio Code task configurations instead, suggesting deliberate evasion of npm v12 security controls. Any developer or CI/CD pipeline consuming these packages risks credential and secret theft from the compromised host. ...

29 June 2025 Ā· ZX Cloud Security

CVE-2023-6606: Linux Kernel SMB Out-of-Bounds Read

🟠 High |Ā Source: Microsoft Security Response Center CVE-2023-6606 is an out-of-bounds read vulnerability in the Linux kernel’s SMB client, specifically within the smbCalcSize function. It allows a local attacker to read memory beyond intended boundaries, potentially leaking sensitive kernel data. While not directly an Azure-specific flaw, it affects Linux-based workloads running on Azure VMs and other cloud environments using SMB-enabled kernels. Security Architect’s Take: Review any Azure Linux VMs or AKS node pools using SMB mounts and ensure the underlying kernel is patched to a version that addresses this CVE. Prioritise workloads where SMB shares are mounted from untrusted or externally accessible sources, as crafted SMB responses could trigger the vulnerability. ...

28 June 2025 Ā· ZX Cloud Security

CVE-2025-40158: Azure Linux Kernel IPv6 RCU Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2025-40158 is a Linux kernel vulnerability affecting IPv6 packet output handling, specifically a race condition in the ip6_output() function that lacks proper RCU (Read-Copy-Update) locking. This type of flaw can lead to use-after-free memory corruption, potentially allowing an attacker to crash the system or execute arbitrary code. It is relevant to Azure environments running Linux-based virtual machines or containerised workloads where the underlying kernel is exposed. ...

28 June 2025 Ā· ZX Cloud Security

CVE-2025-40170: Linux Kernel Net Stack Flaw in Azure

🟠 High |Ā Source: Microsoft Security Response Center CVE-2025-40170 is a Linux kernel vulnerability affecting the networking stack, specifically a race condition or improper reference in the sk_setup_caps() function where dst_dev_rcu() should be used to safely access network device references. This flaw is surfaced in the context of Azure’s Linux-based infrastructure and workloads. If exploited, it could lead to memory corruption or use-after-free conditions in the kernel’s networking path, potentially destabilising affected systems. ...

28 June 2025 Ā· ZX Cloud Security

CVE-2025-40168: Azure Linux Kernel SMC Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2025-40168 is a Linux kernel vulnerability in the SMC (Shared Memory Communications) subsystem, specifically in how destination routing cache entries are accessed without proper RCU (Read-Copy-Update) locking in the smc_clc_prfx_match() function. This can lead to a use-after-free condition, potentially allowing an attacker to cause a system crash or execute arbitrary code. It matters because Azure Linux-based virtual machines and services relying on the SMC networking stack may be exposed if the underlying kernel is unpatched. ...

28 June 2025 Ā· ZX Cloud Security

CVE-2025-40139: Linux Kernel SMC Flaw in Azure

🟠 High | Source: Microsoft Security Response Center CVE-2025-40139 is a Linux kernel vulnerability in the SMC (Shared Memory Communications) subsystem, specifically in the smc_clc_prfx_set() function, where unsafe socket destination cache access could lead to a race condition or use-after-free scenario. This type of flaw can potentially be exploited to cause system instability or, in more severe cases, arbitrary code execution within the kernel. It is relevant to Azure environments running Linux-based virtual machines or container workloads that rely on the SMC protocol. ...

28 June 2025 Ā· ZX Cloud Security

CVE-2025-21825: Azure Linux BPF Timer Kernel Flaw

🟠 High |Ā Source: Microsoft Security Response Center CVE-2025-21825 is a Linux kernel vulnerability affecting the BPF (Berkeley Packet Filter) timer subsystem, specifically in real-time kernel configurations (PREEMPT_RT). The flaw relates to improper cancellation of running BPF timers, which could lead to use-after-free conditions or system instability. This matters for Azure environments running Linux-based virtual machines or containerised workloads on real-time kernel builds. Security Architect’s Take: Review whether any Azure Linux VMs or AKS node pools are running PREEMPT_RT-enabled kernels, and prioritise applying the relevant kernel patch. If real-time kernels are not in use, exposure is minimal, but standard patching cycles should still account for this fix. ...

28 June 2025 Ā· ZX Cloud Security

Russian Intelligence Smishing Campaign Steals Messaging Cred

🟠 High |Ā Source: The Hacker News Russian intelligence services conducted a sustained campaign using fake technical support text messages to steal messaging app credentials from Ukrainian and Western government officials, military personnel, and activists. The operation was uncovered jointly by Ukraine’s Security Service (SSU) and the FBI. The campaign highlights the ongoing use of social engineering as a vector to compromise sensitive communications outside traditional IT environments. Security Architect’s Take: Ensure your organisation enforces phishing-resistant MFA (such as hardware security keys or passkeys) on all messaging and collaboration platforms, and implement policies that prohibit the use of personal or unmanaged messaging apps for sensitive communications. Review whether privileged users are adequately trained to identify smishing lures impersonating IT support. ...

27 June 2025 Ā· ZX Cloud Security

AI Uncovers Hidden Vulns: What Security Teams Must Do

🟠 High |Ā Source: The Register — Security AI-powered vulnerability research tools are uncovering large numbers of previously unknown security flaws at a pace that is outstripping the capacity of security teams to remediate them. This creates a significant risk window as defenders struggle to triage and patch vulnerabilities faster than attackers can exploit them. The trend signals a structural shift in the vulnerability landscape that will place sustained pressure on security operations throughout 2026. ...

27 June 2025 Ā· ZX Cloud Security

CVE-2026-13038: Use After Free in Edge Autofill

🟠 High |Ā Source: Microsoft Security Response Center A use-after-free vulnerability (CVE-2026-13038) has been identified in the Autofill component of Chromium, the open-source browser engine underpinning Microsoft Edge. Use-after-free flaws occur when a programme continues to reference memory after it has been freed, potentially allowing an attacker to execute arbitrary code. Microsoft Edge users are affected and should apply the latest browser update as Google Chrome’s upstream fix is being ingested into Edge. ...

27 June 2025 Ā· ZX Cloud Security

šŸ“¬ Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options