Operation Endgame Disrupts SocGholish Malware Network

🟠 High | Source: The Hacker News A multinational law enforcement operation (Operation Endgame) has disrupted the infrastructure behind SocGholish, a widely-used malware loader that spreads via compromised websites. Nearly 15,000 infected WordPress sites have been cleaned as part of the action, coordinated by Dutch, Canadian, German, and US authorities. SocGholish is frequently used as an initial access broker, making this takedown significant for reducing downstream ransomware and data theft campaigns. ...

19 June 2025 Â· ZX Cloud Security

CVE-2026-44817 Microsoft Excel RCE for Mac

🟠 High | Source: Microsoft Security Response Center CVE-2026-44817 is a remote code execution vulnerability in Microsoft Excel affecting Microsoft Office for Mac. An attacker exploiting this flaw could execute arbitrary code on a victim’s machine, potentially leading to full system compromise. Microsoft has released security updates and only Mac users running affected Office software need to act. Security Architect’s Take: Ensure macOS endpoints across your organisation have the latest Microsoft Office for Mac updates deployed promptly — prioritise this via your MDM solution (e.g. Intune or Jamf) and verify compliance through your endpoint management tooling. Confirm that Windows and cloud-hosted Office users are unaffected and no additional action is required for those workloads. ...

19 June 2025 Â· ZX Cloud Security

CVE-2026-44818: Excel for Mac RCE Vulnerability

🟠 High | Source: Microsoft Security Response Center A remote code execution vulnerability (CVE-2026-44818) has been identified in Microsoft Excel for Mac. An attacker who successfully exploits this flaw could execute arbitrary code on a victim’s machine, typically by convincing a user to open a malicious Excel file. Only users running Microsoft Office for Mac are affected; other Office platforms do not require action. Security Architect’s Take: Ensure all macOS endpoints running Microsoft Office are patched immediately via the update released by Microsoft. If you manage a fleet of Macs through Intune or a third-party MDM solution, prioritise deploying this update and validate compliance reporting to confirm coverage before threat actors can weaponise a public proof-of-concept. ...

19 June 2025 Â· ZX Cloud Security

CVE-2026-44819: Microsoft Office for Mac RCE Vulnerability

🟠 High | Source: Microsoft Security Response Center A remote code execution vulnerability (CVE-2026-44819) has been identified in Microsoft Office for Mac, allowing attackers to potentially execute arbitrary code on affected systems. Microsoft has released security updates to address the flaw, and only Mac users running affected Office software need to act. Users on other platforms are not impacted. Security Architect’s Take: Ensure all macOS endpoints running Microsoft Office are patched immediately via your MDM or endpoint management tooling; prioritise any devices with access to cloud environments or sensitive data, and verify compliance through your endpoint detection inventory. ...

19 June 2025 Â· ZX Cloud Security

CVE-2026-44820 Microsoft Excel RCE for Mac Patched

🟠 High | Source: Microsoft Security Response Center A remote code execution vulnerability (CVE-2026-44820) has been identified in Microsoft Excel for Mac. An attacker exploiting this flaw could execute arbitrary code on an affected machine, potentially leading to full system compromise. Microsoft has released a security update and Mac users running affected versions of Microsoft Office should apply the patch immediately. Security Architect’s Take: Ensure endpoint management policies enforce prompt installation of the latest Microsoft Office for Mac updates across your organisation — verify compliance via Intune or your MDM solution. If your environment includes Mac-based developer or analyst workstations with access to cloud environments, treat this as elevated priority given the potential for lateral movement post-exploitation. ...

19 June 2025 Â· ZX Cloud Security

CVE-2026-44823: Microsoft Excel RCE Flaw for Mac

🟠 High | Source: Microsoft Security Response Center A remote code execution vulnerability (CVE-2026-44823) has been identified in Microsoft Excel for Mac. An attacker exploiting this flaw could execute arbitrary code on an affected system, potentially gaining full control. Only users running Microsoft Office on macOS are affected; other Office platforms do not require action. Security Architect’s Take: Ensure all macOS endpoints in your organisation running Microsoft Office are patched immediately via your MDM or patch management tooling. Verify compliance through your endpoint management platform and confirm no exemptions exist for privileged users or developer machines running Office for Mac. ...

19 June 2025 Â· ZX Cloud Security

CVE-2026-44824: Microsoft Office for Mac RCE Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-44824 is a remote code execution vulnerability affecting Microsoft Office for Mac. An attacker exploiting this flaw could potentially execute arbitrary code on a victim’s machine, likely by convincing a user to open a malicious Office document. Microsoft has released security updates and advises affected Mac users to apply the patch immediately. Security Architect’s Take: Ensure endpoint management policies (e.g. via Intune or Jamf) enforce automatic updates for Microsoft Office on macOS devices across your estate. Verify compliance dashboards confirm patched versions are deployed, particularly for privileged users or those handling sensitive data. ...

19 June 2025 Â· ZX Cloud Security

CVE-2026-45456: Microsoft Outlook & Word RCE on macOS

🟠 High | Source: Microsoft Security Response Center Microsoft has released security updates addressing a remote code execution vulnerability (CVE-2026-45456) affecting Microsoft Outlook and Word on macOS. Attackers exploiting this flaw could potentially execute arbitrary code on affected Mac systems running vulnerable versions of Microsoft Office. Only Mac users are affected; users of other Office platforms do not need to take action. Security Architect’s Take: Ensure any macOS endpoints in your organisation running Microsoft Outlook or Word are patched immediately via Microsoft AutoUpdate or your MDM solution. Validate patch compliance through your endpoint management tooling, particularly for remote or BYOD Mac users who may not receive updates promptly. ...

19 June 2025 Â· ZX Cloud Security

CVE-2026-45458: Microsoft Outlook & Word RCE Fix

🟠 High | Source: Microsoft Security Response Center A remote code execution vulnerability (CVE-2026-45458) has been identified in Microsoft Outlook and Word for Mac. Microsoft has released security updates to address the flaw, and Mac users running affected versions of these Office applications should apply the patch immediately. Users on other platforms are not affected and no further action is required from them. Security Architect’s Take: Ensure any Mac endpoints in your organisation running Microsoft Outlook or Word are updated promptly via your MDM solution or patch management tooling — prioritise devices with access to sensitive cloud environments or corporate email, as RCE vulnerabilities in mail and document clients present a significant initial-access risk. ...

19 June 2025 Â· ZX Cloud Security

CVE-2026-45460: Microsoft Office Android Info Disclosure

🟠 High | Source: Microsoft Security Response Center CVE-2026-45460 is an information disclosure vulnerability affecting Microsoft Office for Android. Exploitation could allow an attacker to access sensitive data that should otherwise be protected within the application. Microsoft has released a security update and users of the affected Android app should apply it promptly. Security Architect’s Take: Ensure your mobile device management (MDM) or MAM policy enforces automatic app updates for Microsoft Office on Android, and verify that managed devices are running the patched version. Consider reviewing data classification policies to limit the sensitivity of data accessible via mobile Office clients until patching is confirmed. ...

19 June 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options