Amadey & StealC Takedown: 27M Credentials Recovered

🟠 High | Source: The Hacker News A joint law enforcement and private sector operation coordinated by Europol has dismantled the infrastructure behind Amadey and StealC, two prolific malware families used to steal credentials and enable ransomware and financial fraud. The operation recovered approximately 27 million stolen credentials. Partners including Bitdefender, Bitsight, ESET, and Microsoft contributed to taking down the criminal ‘assembly lines’ that fed downstream attacks. Security Architect’s Take: Review your threat intelligence feeds and identity monitoring for any credentials associated with your organisation in the recovered dataset — contact your CIEM or SIEM vendor about ingesting indicators from this operation. Additionally, audit cloud workloads and endpoints for StealC or Amadey indicators of compromise, as stolen credentials from these campaigns are frequently used to pivot into cloud environments via valid account abuse. ...

24 June 2025 Â· ZX Cloud Security

AI Agentic Adversaries: The End of Human-Speed Threats

🟠 High | Source: The Hacker News A new class of AI-driven adversary is emerging that operates at machine speed, compressing the traditional vulnerability-to-exploit timeline from weeks to near-instantaneous. This ‘apex agentic adversary’ uses autonomous AI agents to discover, exploit, and pivot through environments faster than human defenders can respond. The shift fundamentally breaks patch-cycle-based security models that the industry has relied on for decades. Security Architect’s Take: Prioritise autonomous, real-time detection and response controls — relying on human-reviewed patch cycles is no longer sufficient. Invest in AI-assisted threat detection, enforce least-privilege and zero-trust segmentation to limit blast radius, and run tabletop exercises simulating machine-speed attack chains across your cloud environments. ...

24 June 2025 Â· ZX Cloud Security

KDDI Data Breach: 14.2M Email Credentials Exposed

🟠 High | Source: The Register — Security Japanese telecoms giant KDDI has exposed the email credentials of approximately 14.2 million users across five ISPs it manages, in what appears to be a significant data breach. The incident affects managed email account details, meaning affected users face risks including account takeover, phishing, and downstream compromise of services tied to those email addresses. The scale of exposure and the number of ISPs involved amplifies the potential blast radius considerably. ...

24 June 2025 Â· ZX Cloud Security

Squidbleed: 1990s Memory Leak Found in Squid Proxy

🟠 High | Source: The Register — Security Security research firm Mythos has uncovered ‘Squidbleed’, a memory leak vulnerability in Squid proxy software that has apparently existed undetected since the mid-1990s. The finding is part of a broader investigation surfacing long-standing security flaws in legacy protocols and software including NetWare, FTP, and HTTP. Memory leaks of this nature can expose sensitive data in process memory, potentially including credentials, session tokens, or cryptographic material. ...

23 June 2025 Â· ZX Cloud Security

Scattered Spider Members Plead Guilty Over TfL Attack

🟠 High | Source: Krebs on Security Two members of the cybercrime group Scattered Spider pleaded guilty in a UK court on the first day of their trial, in connection with a major cyberattack against Transport for London in August 2024. The attack caused significant disruption to London’s public transport network and its associated IT systems. The case is a rare example of successful prosecution of a sophisticated, socially engineered cybercrime gang. ...

23 June 2025 Â· ZX Cloud Security

CVE-2026-12957 & 12958: Amazon Q Developer Flaws

🟠 High | Source: AWS Security Bulletins Two vulnerabilities have been identified in Language Servers for AWS, the runtime underpinning Amazon Q Developer’s IDE plugins for VS Code, JetBrains, Eclipse, and Visual Studio. CVE-2026-12957 allows arbitrary command execution when a user opens and trusts a maliciously crafted workspace, whilst CVE-2026-12958 enables path traversal outside the workspace boundary via a crafted symlink. Both issues are patched in Language Servers for AWS version 1.69.0 and corresponding plugin updates. ...

23 June 2025 Â· ZX Cloud Security

Fake AI Agent Skill Bypasses All Scanners, Hits 26K Agents

🟠 High | Source: The Hacker News Security firm AIR created a deliberately benign fake skill for AI agent platforms, distributed it via a skill marketplace and Instagram advertising, and observed it being installed by approximately 26,000 agents — including those on corporate accounts. Critically, every security scanner tested against the skill returned a clean verdict, demonstrating a significant blind spot in current AI agent supply chain security tooling. The research highlights how malicious actors could exploit the same distribution channels to deploy genuinely harmful payloads at scale. ...

23 June 2025 Â· ZX Cloud Security

GitHub Blocks Pwn Request Attacks in actions/checkout

🟠 High | Source: The Hacker News GitHub is updating its widely-used ‘actions/checkout’ action to block ‘pwn request’ attacks, where malicious code in pull requests gains full workflow privileges via the ‘pull_request_target’ trigger. Effective 18 June 2026, the new version introduces safeguards to prevent untrusted code from executing in privileged workflow contexts. This matters because successful exploitation allows attackers to exfiltrate secrets, tamper with pipelines, or compromise downstream software supply chains. ...

23 June 2025 Â· ZX Cloud Security

CVE-2026-33840 Win32k Privilege Escalation – Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-33840 is a Windows Win32k elevation of privilege vulnerability that could allow an attacker to gain higher-level permissions on an affected system. This update from Microsoft is an acknowledgement change only — no new patches or technical details have been issued. Although the advisory originates from MSRC, Win32k vulnerabilities are relevant to Azure environments where Windows-based virtual machines and hybrid workloads are common. ...

23 June 2025 Â· ZX Cloud Security

CVE-2026-45504 Exchange Server Privilege Escalation

🟠 High | Source: Microsoft Security Response Center CVE-2026-45504 is an Elevation of Privilege vulnerability affecting Microsoft Exchange Server, meaning an attacker could potentially gain higher-level permissions than intended on an affected system. This update is an acknowledgement addition and carries no change to the technical details or patch guidance. Organisations running Exchange Server on-premises or in hybrid configurations should remain aware of the underlying vulnerability. Security Architect’s Take: No immediate action is required as this is an informational update only; however, architects should confirm that patches addressing CVE-2026-45504 have already been applied across all Exchange Server instances, particularly in hybrid Azure/on-premises deployments where Exchange is a common lateral movement target. ...

23 June 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options