CVE-2026-10275: OpenSC pkcs11-tool Buffer Overflow

🟠 High | Source: Microsoft Security Response Center CVE-2026-10275 is a buffer overflow vulnerability in OpenSC’s pkcs11-tool, specifically within the key generation and certificate writing functionality in pkcs11-tool.c. The flaw could allow an attacker to corrupt memory during PKCS#11 cryptographic operations, potentially leading to arbitrary code execution or service crashes. This matters because OpenSC is widely used to interact with hardware security modules (HSMs) and smart cards, including in Azure and hybrid environments. ...

19 June 2025 Â· ZX Cloud Security

CVE-2026-8376: Perl Heap Buffer Overflow on Azure

🟠 High | Source: Microsoft Security Response Center A heap buffer overflow vulnerability exists in Perl versions up to and including 5.43.10, triggered when the interpreter compiles regular expressions containing repeated fixed strings on 32-bit builds. This type of memory corruption flaw can potentially be exploited to crash applications or, in worst-case scenarios, execute arbitrary code. Any Azure workloads or services running 32-bit Perl environments are potentially at risk. Security Architect’s Take: Audit your Azure workloads and container images for 32-bit Perl installations at version 5.43.10 or below, and prioritise patching or rebuilding on 64-bit runtimes where possible. If immediate patching isn’t feasible, consider restricting untrusted regex input paths and applying network-level controls to limit exposure. ...

19 June 2025 Â· ZX Cloud Security

CVE-2026-43966: HTTP Response Splitting Azure Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-43966 is an HTTP Response Splitting vulnerability in the cow_http_struct_hd:escape_string/2 function, caused by insufficient filtering of non-printable, non-VCHAR bytes in HTTP headers. An attacker able to influence header values could inject crafted responses, potentially leading to cache poisoning, cross-site scripting, or session hijacking. This affects Azure-hosted workloads or services relying on the vulnerable HTTP parsing component. Security Architect’s Take: Review any Azure services or containerised workloads that use the affected HTTP library and apply the vendor patch promptly. In the interim, enforce strict input validation and header sanitisation at your API gateway or WAF layer to block non-VCHAR characters in HTTP header values. ...

19 June 2025 Â· ZX Cloud Security

CVE-2026-9669: Azure Python bz2 Stack Buffer Overflow

🟠 High | Source: Microsoft Security Response Center CVE-2026-9669 is a stack buffer overflow vulnerability in Python’s bz2.BZ2Decompressor, triggered when the decompressor object is reused after encountering an error state. This can lead to memory corruption, and in a cloud context, could be exploited by an attacker supplying crafted compressed data to a vulnerable application running on Azure. The risk is elevated wherever Python workloads process untrusted bz2-compressed input. Security Architect’s Take: Audit Azure-hosted Python workloads that use the bz2 module — particularly any that reuse BZ2Decompressor instances across multiple decompression operations or after error conditions — and apply available patches or restrict input sources. Consider enforcing input validation and sandboxing for services that decompress user-supplied data. ...

19 June 2025 Â· ZX Cloud Security

CVE-2026-53689: Azure Security Vulnerability Advisory

🟠 High | Source: Microsoft Security Response Center CVE-2026-53689 is a security vulnerability affecting Microsoft Azure, published by the Microsoft Security Response Center. Details remain limited at this stage, but the advisory has been flagged as high priority, indicating a meaningful risk to Azure environments. Organisations using Azure should monitor this CVE closely as further technical details are expected to follow. Security Architect’s Take: Review the MSRC advisory page directly for updates and assess whether any Azure services in your environment are in scope; consider enabling relevant Azure Defender or Microsoft Defender for Cloud alerts to detect potential exploitation attempts while full details emerge. ...

19 June 2025 Â· ZX Cloud Security

CVE-2026-42014: GnuTLS Use-After-Free on Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-42014 is a use-after-free vulnerability in GnuTLS, a widely used cryptographic library, specifically in the function responsible for setting PKCS#11 token PINs. Use-after-free flaws occur when a programme continues to use memory after it has been freed, potentially allowing attackers to execute arbitrary code or cause a crash. This matters because GnuTLS underpins TLS/SSL operations in many Linux-based workloads, including those running on Azure. ...

19 June 2025 Â· ZX Cloud Security

CVE-2025-20701: Apple Beats Bluetooth Spy Flaw Patched

🟠 High | Source: The Hacker News A high-severity vulnerability (CVE-2025-20701) in the Airoha Bluetooth audio SDK allowed nearby attackers to pair with Beats Studio Buds without the owner’s knowledge or consent, potentially enabling real-time microphone eavesdropping. The flaw stems from incorrect authorisation logic in the Bluetooth pairing process. Apple has issued a firmware update to address the issue. Security Architect’s Take: While this is a consumer device vulnerability rather than a cloud infrastructure issue, architects should consider updating their organisation’s mobile device and peripheral management policies to mandate firmware updates for Bluetooth audio devices used in sensitive environments — particularly where staff work remotely or in shared spaces where conversations about confidential matters may be overheard. ...

19 June 2025 Â· ZX Cloud Security

Popa Botnet Tied to Israeli Firm Alarum Technologies

🟠 High | Source: Krebs on Security A large Android botnet called Popa has been operating for four years, silently turning millions of consumer TV boxes into proxies used for ad fraud, account takeovers, and data scraping. Security researchers have now linked the botnet to NetNut, a residential proxy service run by Alarum Technologies, a publicly-traded Israeli company on NASDAQ. The findings raise serious questions about the legitimacy of the residential proxy industry and how such services may be built on compromised consumer devices. ...

18 June 2025 Â· ZX Cloud Security

Weekly Threat Bulletin: Claude Abuse, npm C2 & Phishing

🟠 High | Source: The Hacker News This weekly bulletin covers a broad range of active threats including abuse of Claude AI chat links for malware delivery, malicious npm packages acting as C2 infrastructure, device-code phishing campaigns, and fileless macOS attacks. Attackers are increasingly exploiting legitimate platforms and trusted tooling — AI assistants, package registries, and cloud agent frameworks — as delivery and persistence mechanisms. The breadth of this bulletin reflects a threat landscape where well-understood, intentional system behaviours are being weaponised rather than bypassed. ...

18 June 2025 Â· ZX Cloud Security

Windows Clipper Malware: USB LNK Worm & Tor C2

🟠 High | Source: The Hacker News Microsoft has identified an ongoing malware campaign targeting Windows users with a cryptocurrency clipper that silently replaces copied wallet addresses with attacker-controlled ones. The malware, active since February 2026, uses Windows Script Host and ActiveX to launch a bundled Tor proxy, communicating with a dark web command-and-control server to evade detection. The use of USB LNK worm propagation significantly widens the potential blast radius, including air-gapped or enterprise environments where USB devices are in common use. ...

18 June 2025 Â· ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options