Huntress Insider Threat: Analyst Alleges Ransomware Tip-Off

🟠 High | Source: The Register — Security A former Huntress analyst has publicly alleged that an insider at the cybersecurity firm passed sensitive client information to a ransomware criminal. The ex-employee further claims Huntress prioritised protecting its pending IPO over transparently disclosing the incident to affected clients. If substantiated, this raises serious concerns about insider threat management and corporate governance at a company trusted with deep visibility into customer environments. ...

25 June 2025 Â· ZX Cloud Security

Adblock for YouTube Chrome Extension: Script Injection Risk

🟠 High | Source: The Hacker News A Chrome extension called ‘Adblock for YouTube’ with over 10 million installs has been found to contain hidden functionality capable of injecting and executing arbitrary JavaScript code in users’ browsers. The extension carries a ‘Featured’ badge on the Chrome Web Store, lending it a false sense of legitimacy. This represents a significant supply-chain risk, as the dormant capability could be activated remotely to steal credentials, exfiltrate data, or compromise corporate environments. ...

25 June 2025 Â· ZX Cloud Security

CVE-2026-41086 Azure Windows Admin Center EoP Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-41086 is an elevation of privilege vulnerability affecting Windows Admin Center when accessed via the Azure Portal. If exploited, an attacker could gain elevated permissions beyond their intended access level within the management interface. This update is an acknowledgement change only and carries no new technical detail or patch. Security Architect’s Take: No immediate remediation action is required as this update is purely an acknowledgement change. However, architects should confirm that access to Windows Admin Center in the Azure Portal is restricted via Azure RBAC and that least-privilege principles are enforced, particularly for users with administrative roles. ...

25 June 2025 Â· ZX Cloud Security

CVE-2026-45637: Microsoft DWM Privilege Escalation

🟠 High | Source: Microsoft Security Response Center CVE-2026-45637 is an elevation of privilege vulnerability in the Microsoft Desktop Window Manager (DWM) Core Library, a Windows component relevant to environments running Windows-based Azure virtual machines and hybrid workloads. The vulnerability could allow a local attacker to gain elevated system privileges. This update is an informational change to acknowledgements only — no new patches or exploitability changes have been introduced. Security Architect’s Take: No immediate action is required as this is solely an acknowledgement update with no change to patch status or exploitability. However, ensure Windows-based Azure VMs and hybrid endpoints are already patched against CVE-2026-45637 as part of your standard patch management cycle, and verify that your vulnerability management tooling reflects the latest advisory metadata. ...

25 June 2025 Â· ZX Cloud Security

Prompt Injection: LLM Role Boundaries Are Broken

🟠 High | Source: Schneier on Security Researchers have demonstrated that large language models (LLMs) don’t truly separate system, user, and assistant roles internally — they recognise stylistic patterns rather than enforcing genuine trust boundaries. This makes prompt injection attacks a structural problem rather than a configuration one, as attackers can craft text that subtly shifts model behaviour without obvious malicious markers. The finding suggests that current defences based on role tags or prompt formatting are fundamentally insufficient. ...

25 June 2025 Â· ZX Cloud Security

Gaslight macOS Malware Uses Prompt Injection on AI Tools

🟠 High | Source: The Hacker News A new Rust-based macOS malware called Gaslight has been discovered that acts as an implant and information stealer, with a novel twist: it embeds prompt injection payloads designed to manipulate AI-assisted analysis tools into refusing or abandoning examination of the malware. This represents an emerging and concerning tactic where malware actively attempts to subvert the AI-powered defences and tooling used by security analysts. The technique could significantly slow incident response and threat intelligence workflows that increasingly rely on AI assistance. ...

25 June 2025 Â· ZX Cloud Security

Mistic Backdoor: KongTuke IAB Targets UK Sectors

🟠 High | Source: The Hacker News A newly identified backdoor called Mistic (also tracked as MLTBackdoor) has been used in financially motivated attacks against organisations in insurance, education, IT, and professional services since April 2026. It is linked to an initial access broker (IAB) connected to the KongTuke threat cluster, and has been deployed alongside ClickFix social engineering techniques and a remote access tool called ModeloRAT. The campaign represents a sophisticated multi-stage intrusion chain that poses a significant threat to enterprise environments across multiple sectors. ...

25 June 2025 Â· ZX Cloud Security

CVE-2026-11816 Path Traversal in Keras – Azure Risk

🟠 High | Source: Microsoft Security Response Center CVE-2026-11816 is a path traversal vulnerability identified in keras-team/keras, a widely used open-source deep learning framework. Path traversal flaws allow attackers to read or write files outside intended directories, potentially exposing sensitive data or enabling code execution. This matters because Keras is commonly used in cloud-based ML pipelines and AI workloads, including those hosted on Azure. Security Architect’s Take: Audit any Azure ML or cloud-based AI pipelines that incorporate Keras and apply vendor patches or mitigations immediately; additionally, enforce least-privilege file system access controls around any services loading or saving Keras model files to limit the blast radius of exploitation. ...

25 June 2025 Â· ZX Cloud Security

UK School Network Exposed: Password in AD Description

🟠 High | Source: The Register — Security A UK school’s network was left critically exposed after a student discovered that an administrator password had been stored in plain text within an Active Directory account description field. This elementary misconfiguration granted broad network access to anyone who found it. The incident highlights how basic security hygiene failures in on-premises and hybrid environments can undermine an entire organisation’s defences. Security Architect’s Take: Audit all Active Directory and directory service accounts immediately to ensure no credentials, hints, or sensitive data are stored in description, comment, or notes fields — this is trivially discoverable by any authenticated user. Enforce least-privilege access and implement a secrets management solution to eliminate any manual, ad-hoc credential handling. ...

25 June 2025 Â· ZX Cloud Security

Cisco SD-WAN Zero-Day CVE-2026-20245 Exploited

🟠 High | Source: The Hacker News A high-severity zero-day vulnerability in Cisco Catalyst SD-WAN (CVE-2026-20245) was actively exploited by a threat actor at least two months before Cisco publicly disclosed it, according to Mandiant. The flaw allows an authenticated local attacker to run arbitrary commands with elevated privileges, ultimately enabling root access. The pre-disclosure exploitation window significantly increases the risk for organisations that have not yet patched. Security Architect’s Take: Patch Cisco Catalyst SD-WAN devices immediately and audit recent command execution logs for anomalous activity, particularly from authenticated local sessions. Given the pre-disclosure exploitation timeline, treat any unpatched SD-WAN appliances as potentially compromised and consider isolating them pending investigation. ...

25 June 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options