CVE-2026-13021: Chromium Edge DeviceBoundSession Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-13021 is a vulnerability in Chromium’s DeviceBoundSessionCredentials feature, involving an inappropriate implementation that could be exploited via a malicious website. Because Microsoft Edge is built on Chromium, it inherits this flaw and requires patching through a Chromium update. Google has addressed this in Chrome, and Microsoft Edge users should ensure they are running the latest version. Security Architect’s Take: Ensure all managed endpoints running Microsoft Edge (or Chrome) are updated to the latest Chromium-based release via your endpoint management tooling (e.g. Intune, WSUS, or your browser deployment pipeline). Pay particular attention to enterprise environments where DeviceBoundSessionCredentials may be in use for workload or user authentication flows. ...

27 June 2025 Â· ZX Cloud Security

Secret Service Mobile Security Failures Exposed

🟠 High | Source: The Register — Security A report has revealed that US Secret Service agents are using personal mobile phones rather than government-issued devices during protective operations, with no threat detection tooling deployed on official handsets. This represents a significant operational security failure, as unmanaged personal devices are far harder to audit, control, or protect against compromise. The findings highlight systemic mobile device management failures within a high-value government security operation. ...

26 June 2025 Â· ZX Cloud Security

FBI: Russian Hackers Steal Signal Backup Recovery Keys

🟠 High | Source: The Hacker News Russian intelligence operatives have evolved their Signal phishing campaign to specifically target users’ Backup Recovery Keys — a static credential that grants full access to message history and account control. Unlike a password reset, the key remains valid indefinitely once compromised, giving attackers persistent, silent access. The FBI and CISA have updated their advisory to reflect this escalated tactic. Security Architect’s Take: Advise staff and privileged users to treat Signal Backup Recovery Keys with the same sensitivity as MFA seed phrases — never share them and store them offline in a secrets manager or physical safe. Consider issuing guidance that no legitimate service or authority will ever request this key, and review whether Signal is approved for handling sensitive organisational communications given this persistent credential risk. ...

26 June 2025 Â· ZX Cloud Security

SharkLoader Malware Deploys Cobalt Strike in StrikeShark Att

🟠 High | Source: The Hacker News A newly identified malware loader called SharkLoader is being used in targeted cyberattacks, dubbed StrikeShark by Kaspersky, to deploy Cobalt Strike Beacon on compromised systems. The campaign has focused on diplomatic and government organisations in Indonesia and Taiwan, suggesting nation-state or espionage-related motivations. Cobalt Strike is a well-established post-exploitation framework frequently abused by threat actors to maintain persistent access and move laterally across networks. ...

26 June 2025 Â· ZX Cloud Security

Chinese APT CL-STA-1062 Deploys TinyRCT Backdoor

🟠 High | Source: The Hacker News A Chinese-speaking APT group tracked as CL-STA-1062 has deployed a previously unknown backdoor called TinyRCT against government entities and state-owned enterprises in the energy sector across Southeast Asia. The campaign represents a targeted espionage operation against critical national infrastructure. Palo Alto Networks attributed the activity, suggesting sophisticated, well-resourced threat actors with strategic regional interests. Security Architect’s Take: Review your organisation’s east-west network segmentation and egress controls, particularly for systems handling OT/ICS or government data — TinyRCT-style backdoors rely on persistent outbound command-and-control channels that robust egress filtering and DNS monitoring can help detect and disrupt. Ensure threat intelligence feeds include CL-STA-1062 indicators of compromise and validate that EDR tooling covers any cloud-hosted workloads or hybrid infrastructure in the region. ...

26 June 2025 Â· ZX Cloud Security

Amazon Q Flaw: Git Repos Could Steal AWS Cloud Creds

🟠 High | Source: The Register — Security A vulnerability in Amazon Q, AWS’s AI coding assistant, allowed malicious Git repositories to execute arbitrary code and steal cloud credentials on a developer’s machine. Attackers could craft a booby-trapped repository that, when opened with Amazon Q, would trigger commands from project configuration files without explicit user consent. Researchers highlight this as a broader pattern affecting many AI coding assistants that blindly execute instructions from project-level config files. ...

26 June 2025 Â· ZX Cloud Security

CVE-2026-12957: Amazon Q Developer MCP Flaw

🟠 High | Source: The Hacker News A high-severity vulnerability (CVE-2026-12957, CVSS 8.5) in Amazon Q Developer allowed a malicious code repository to execute arbitrary commands and steal AWS cloud credentials simply by being opened in the IDE. The flaw stemmed from how Amazon Q handled Model Context Protocol (MCP) server configurations, meaning a developer trusting a workspace was sufficient to trigger the attack. Amazon has issued a patch. Security Architect’s Take: Ensure all developers update Amazon Q Developer to the latest patched version immediately, and review internal guidance on trusting third-party repositories in AI-assisted development environments. Consider auditing MCP server configurations across your development fleet and restrict automatic trust of workspaces in IDE security policies. ...

26 June 2025 Â· ZX Cloud Security

Miasma Campaign Poisons 20+ npm Packages for Creds

🟠 High | Source: The Register — Security A threat campaign dubbed ‘Miasma’ has compromised over 20 npm packages — including those associated with the Leo Platform and RStreams ecosystems — by injecting malicious code designed to harvest developer credentials. Microsoft identified the campaign, which appears to target package maintainers to gain further footholds and spread the compromise across the npm supply chain. The attack is particularly dangerous because developers who install or update affected packages may unknowingly expose secrets stored in their local environments or CI/CD pipelines. ...

26 June 2025 Â· ZX Cloud Security

CVE-2026-43503 DirtyClone Linux Kernel Root Flaw

🟠 High | Source: The Hacker News A newly disclosed Linux kernel vulnerability, CVE-2026-43503 (dubbed DirtyClone), allows a local user to corrupt file-backed memory via a cloned network packet and escalate privileges to root. It belongs to the DirtyFrag family of kernel flaws and carries a CVSS score of 8.8. JFrog Security Research published a working exploit walkthrough on 25 June 2026, making this immediately actionable for defenders. Security Architect’s Take: Prioritise patching Linux kernel versions affected by CVE-2026-43503 across all cloud VM fleets and container hosts — pay particular attention to multi-tenant environments where local access by unprivileged users is possible, as a container escape or compromised pod could lead to host root. Verify your cloud provider’s managed node images (EKS, GKE, AKS) have applied the upstream patch and enforce kernel update policies via your IaC or node auto-upgrade mechanisms. ...

26 June 2025 Â· ZX Cloud Security

AI Agent Identity Governance: Closing the IAM Gap

🟠 High | Source: The Hacker News AI agents operating within enterprise environments are inheriting and exercising permissions at machine speed, but existing identity governance frameworks were designed for human users and cannot adequately control autonomous actors. This creates a growing blind spot where AI agents may accumulate excessive privileges, traverse systems laterally, and take consequential actions with little oversight. The gap between AI deployment velocity and governance programme maturity represents a significant and expanding attack surface. ...

26 June 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options