Brazil Emergency Alert System Breached: Rogue Alert Sent

🟠 High | Source: The Register — Security Brazil’s national emergency alert system was compromised, sending a rogue message containing the word ‘misanthropy’ to mobile devices across the entire country. The platform, designed to broadcast severe weather warnings, was abused to push an unauthorised alert at national scale. Authorities have launched an investigation into how the system was accessed and by whom. Security Architect’s Take: Review access controls and authentication mechanisms on any mass-notification or emergency broadcast infrastructure you manage — ensure MFA is enforced, API keys are rotated regularly, and all administrative actions are logged and alerted on. Treat emergency alert systems as critical infrastructure with equivalent hardening to production systems, not as secondary tooling. ...

22 June 2025 · ZX Cloud Security

Legacy Infrastructure Hijacking AI Agents: What to Do

🟠 High | Source: The Hacker News Attackers are exploiting legacy infrastructure — such as unpatched on-premises systems, outdated APIs, and deprecated services — to hijack AI agents that organisations are rapidly deploying. Because security programmes have not kept pace with AI adoption, these legacy components are being used as pivot points to manipulate or subvert AI-driven workflows. With 71% of organisations piloting AI agents, the attack surface is significant and largely uncharted. ...

22 June 2025 · ZX Cloud Security

Gizmodo ClickFix Attack: Windows Users Hit by Trojan

🟠 High | Source: The Register — Security Gizmodo’s website was compromised and used to serve ClickFix social engineering prompts, tricking Windows users into running malicious commands that could install trojan malware. Mac users were largely unaffected. The incident highlights how trusted media brands can become vectors for malware distribution following an account or CMS compromise. Security Architect’s Take: Review your organisation’s acceptable use and endpoint protection policies to ensure that browser-based social engineering attacks like ClickFix — which instruct users to paste commands into PowerShell or Run dialogs — are mitigated through application control and PowerShell constrained language mode. Consider alerting your security awareness programme to this specific technique, as it bypasses many traditional content filters. ...

22 June 2025 · ZX Cloud Security

CVE-2026-4020: Gravity SMTP Plugin API Key Leak

🟠 High | Source: The Hacker News A medium-severity vulnerability in the Gravity SMTP WordPress plugin (CVE-2026-4020) is being actively exploited by attackers before many site owners have applied the patch. The flaw allows unauthenticated attackers to extract sensitive configuration data, API keys, OAuth tokens, and secrets without any login credentials. With roughly 100,000 installations affected, the potential for credential theft and downstream service compromise is significant. Security Architect’s Take: If Gravity SMTP is deployed across any WordPress instances in your environment — including headless or API-driven setups — verify the plugin is patched immediately and rotate all exposed credentials, API keys, and OAuth tokens as a precaution, since active exploitation means some keys may already be compromised. ...

20 June 2025 · ZX Cloud Security

CVE-2026-46331: Linux net/sched Pedit Page Cache Bug

🟠 High | Source: Microsoft Security Response Center CVE-2026-46331 is a Linux kernel vulnerability in the network packet scheduler (net/sched) subsystem, specifically in the ‘pedit’ action, where an incomplete copy-on-write operation can corrupt the page cache. This can lead to memory corruption affecting workloads sharing kernel resources. The issue is relevant to Azure environments where Linux-based virtual machines or container workloads run on shared kernel infrastructure. Security Architect’s Take: Ensure all Linux-based Azure VMs and AKS node pools are running patched kernel versions as soon as Microsoft and upstream distributions release fixes; prioritise workloads with network policy enforcement or traffic shaping configurations that use tc/pedit rules, as these are most directly exposed. ...

20 June 2025 · ZX Cloud Security

CVE-2026-45446: AES-GCM-SIV Empty Message Tag Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-45446 is a vulnerability affecting AES-GCM-SIV and AES-SIV encryption modes, where empty messages are processed with incorrect authentication tags. This flaw could allow an attacker to bypass integrity checks on empty ciphertexts, potentially enabling undetected data tampering or forgery in systems relying on these encryption schemes. Security Architect’s Take: Audit any Azure services or application code that uses AES-GCM-SIV or AES-SIV encryption, particularly where empty message handling is a possibility — apply Microsoft’s recommended patches or mitigations promptly and review cryptographic library dependencies for affected versions. ...

20 June 2025 · ZX Cloud Security

CVE-2026-34183: Azure QUIC Memory Vulnerability

🟠 High | Source: Microsoft Security Response Center CVE-2026-34183 is a vulnerability in the QUIC protocol’s PATH_CHALLENGE handler that allows unbounded memory growth, potentially enabling a denial-of-service condition. An attacker could exploit this by sending crafted QUIC packets that cause memory to grow without limit, eventually exhausting resources on the affected system. This is particularly significant for Azure services and any workloads relying on QUIC-based connectivity. Security Architect’s Take: Review any Azure services or self-managed workloads using QUIC (HTTP/3) and apply Microsoft’s patches promptly; consider temporarily restricting QUIC traffic at the network perimeter via firewall or load balancer rules if immediate patching is not feasible. ...

20 June 2025 · ZX Cloud Security

CVE-2025-4574: crossbeam-channel Double Free Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2025-4574 is a memory safety vulnerability in the Rust crate ‘crossbeam-channel’, a widely used concurrency library. The flaw can trigger a double-free error when a channel is dropped under certain conditions, potentially leading to memory corruption or exploitable crashes. This matters because crossbeam-channel is a common dependency in Rust-based cloud services and infrastructure tooling, including components within the Azure ecosystem. Security Architect’s Take: Audit your Rust-based services and Azure workloads for direct or transitive dependencies on crossbeam-channel and update to the patched version immediately. Pay particular attention to multi-threaded services where channel drop behaviour could be triggered under production load. ...

20 June 2025 · ZX Cloud Security

usbliter8: Unpatchable Apple A12/A13 SecureROM Exploit

🟠 High | Source: The Hacker News Security researchers have released a working exploit called ‘usbliter8’ that targets a hardware-level vulnerability in Apple’s A12 and A13 chips, achieving arbitrary code execution within the SecureROM — the foundational boot code burned permanently into the silicon. Because the flaw exists in read-only memory, Apple cannot patch it via software updates. The attack requires physical USB access to the device, but any affected device remains permanently vulnerable for its operational lifetime. ...

19 June 2025 · ZX Cloud Security

GentleKiller EDR Killer: RaaS Targets 400 Security Tools

🟠 High | Source: The Hacker News A ransomware-as-a-service group called ‘The Gentlemen’ is distributing a sophisticated toolkit called GentleKiller to its affiliates, designed to disable or kill endpoint detection and response (EDR) and security software before deploying ransomware. The framework reportedly targets around 400 security-related processes, making it capable of neutering a wide range of enterprise security tooling. This represents a mature, industrialised approach to defence evasion that significantly lowers the bar for affiliates to bypass security controls. ...

19 June 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options