Miasma Malware Hits npm & GitHub Actions Supply Chain

🟠 High | Source: The Hacker News A malware family known as Miasma (also linked to Mini Shai-Hulud and Hades) has expanded its supply chain attack campaign to compromise npm packages belonging to LeoPlatform and RStreams, abuse GitHub Actions workflows, and spread into the Go ecosystem. This represents an ongoing, evolving threat targeting developer toolchains and CI/CD pipelines. The broad reach across multiple package registries and automation platforms significantly increases the potential blast radius for downstream organisations. ...

26 June 2025 Â· ZX Cloud Security

One Million Passports Leaked via ID Verification Breach

🟠 High | Source: Schneier on Security A database of nearly one million passport scans, collected by cannabis dispensaries for ID verification, was exposed online. The breach illustrates a systemic risk where high-value government-issued credentials are entrusted to low-security third-party systems. The passports themselves are not compromised at source, but the leaked data can enable identity fraud, account takeover, and document forgery at scale. Security Architect’s Take: Audit any third-party or SaaS identity verification vendors in your supply chain — demand evidence of encryption at rest, access controls, and data minimisation practices. Where possible, push for tokenised or hashed identity assertions rather than storing raw document scans, and ensure vendor contracts include breach notification SLAs and data retention limits. ...

26 June 2025 Â· ZX Cloud Security

Hotel Phishing Campaign Drops Node.js Implant via ZIP Files

🟠 High | Source: The Hacker News A phishing campaign active since April 2026 is targeting hotels and hospitality organisations across Europe and Asia, using ZIP files disguised as photo submissions to install a Node.js-based implant on front-desk systems. Microsoft has identified the campaign but has not linked it to a known threat group, and the attackers’ ultimate objective remains unclear. The technique exploits a common workflow in hotels — receiving guest or booking photos — making the lure particularly convincing for front-desk staff. ...

26 June 2025 Â· ZX Cloud Security

CVE-2026-46320: Linux TAP Driver Flaw Affects Azure VMs

🟠 High | Source: Microsoft Security Response Center CVE-2026-46320 is a memory management vulnerability in the Linux kernel’s TAP (network tap) driver, specifically in the tap_get_user_xdp() function, where a page is incorrectly freed on certain error paths. This type of use-after-free or double-free bug can potentially be exploited to corrupt kernel memory, leading to privilege escalation or system instability. The issue is relevant to Azure environments where Linux-based virtual machines or containerised workloads rely on TAP/XDP networking interfaces. ...

26 June 2025 Â· ZX Cloud Security

CVE-2026-46321: Azure Linux Kernel TUN XDP Memory Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-46321 is a kernel-level vulnerability in the Linux TUN/TAP network driver, specifically within the tun_xdp_one() function, where a memory page is not freed when a short frame is rejected during XDP (eXpress Data Path) processing. This can lead to a memory leak, and depending on the context, may be exploitable to cause denial of service or contribute to privilege escalation in virtualised or containerised Linux environments. Azure workloads running Linux VMs or containers may be affected if the underlying kernel is vulnerable. ...

26 June 2025 Â· ZX Cloud Security

CVE-2026-45850: Azure Linux IPVS IPv6 Checksum Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-45850 is a Linux kernel vulnerability in the IPVS (IP Virtual Server) subsystem, where IPv6 extension headers are not correctly skipped during checksum validation. This flaw could potentially be exploited to bypass network-level integrity checks in virtualised or containerised environments, such as those running on Azure. It matters because IPVS is commonly used in Kubernetes load balancing and cloud networking stacks. Security Architect’s Take: Review whether your Azure Kubernetes Service (AKS) or Linux-based VM workloads rely on IPVS mode for kube-proxy; prioritise applying kernel patches from Microsoft once available, and consider temporarily switching affected clusters to iptables mode as a mitigating measure. ...

26 June 2025 Â· ZX Cloud Security

CVE-2025-68736: Linux Landlock Directory Flaw on Azure

🟠 High | Source: Microsoft Security Response Center CVE-2025-68736 is a vulnerability in the Linux kernel’s Landlock security module, specifically relating to incorrect handling of disconnected directories. Landlock is a sandboxing mechanism that restricts what files and directories a process can access. A flaw in this logic could allow a process to access filesystem paths it should be denied, potentially bypassing intended access controls. Security Architect’s Take: Review Linux-based Azure workloads — particularly containerised or sandboxed environments — and ensure kernel patches addressing this CVE are applied promptly. If you rely on Landlock for process-level filesystem isolation, treat this as a priority update until patched. ...

26 June 2025 Â· ZX Cloud Security

Turla STOCKSTAY Backdoor Targets Ukraine & Italy

🟠 High | Source: The Hacker News Russian state-sponsored group Turla has deployed a previously unknown .NET backdoor, dubbed STOCKSTAY, targeting Ukrainian government and military organisations as well as entities with ties to Italian foreign policy. The malware runs on Windows and is under active development, suggesting ongoing and evolving espionage campaigns. Google’s Threat Intelligence Group has attributed the tool to Turla with high confidence. Security Architect’s Take: Review endpoint detection coverage for .NET-based backdoors and ensure Windows environments — particularly those handling sensitive government or defence-related data — have behavioural monitoring and application allowlisting in place. If your organisation has any operational links to Ukraine or Italian foreign policy stakeholders, treat this as an elevated threat and audit outbound network connections for signs of command-and-control activity. ...

26 June 2025 Â· ZX Cloud Security

Security Chief Bypassed MFA: Lessons for Cloud Teams

🟠 High | Source: The Register — Security A security leader exempted themselves from multi-factor authentication (MFA) requirements that were enforced for regular staff, creating a privileged account without MFA protection. This is a textbook example of executive exceptions undermining security policy, leaving high-value accounts — which are prime targets for attackers — exposed. It highlights how cultural and political pressures can erode even basic security controls. Security Architect’s Take: Enforce MFA unconditionally at the identity provider or cloud platform level using conditional access policies or SCPs, ensuring no role or account — including executives and security leadership — can bypass controls through policy exemptions rather than relying on manual compliance. ...

26 June 2025 Â· ZX Cloud Security

Mistic Backdoor: Access Broker Selling Footholds to Ransomwa

🟠 High | Source: The Register — Security A self-destructing backdoor called Mistic has been linked to an initial access broker (IAB) that sells compromised corporate network footholds to ransomware gangs. The malware has been observed in intrusions targeting insurance, education, IT, and professional services organisations. Its self-destruct capability makes post-incident forensic investigation significantly harder, raising the stakes for early detection. Security Architect’s Take: Prioritise robust egress filtering, endpoint detection with behavioural analytics, and network segmentation to limit lateral movement from any initial compromise. Review identity and access controls for externally exposed services, and ensure logging pipelines capture short-lived process and file activity before self-deletion can occur. ...

25 June 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options