INC Ransomware: 830+ Victims and Growing RaaS Threat

🟠 High | Source: The Hacker News INC ransomware has grown from a newcomer in August 2023 to one of the most active ransomware-as-a-service (RaaS) groups, amassing over 830 victims by 2026. Its rise was accelerated by the law enforcement disruption of LockBit and the shutdown of BlackCat, which pushed experienced affiliates to seek alternative platforms. The group now represents a significant and prolific threat across multiple sectors. Security Architect’s Take: Review your ransomware resilience posture immediately: ensure immutable, air-gapped backups are in place and tested, enforce least-privilege access across cloud workloads, and validate that endpoint detection and response (EDR) tooling covers all cloud-connected assets. Consider threat intelligence feeds that track INC TTPs to enable proactive detection rule updates. ...

18 June 2025 · ZX Cloud Security

CVE-2026-32174: Azure Bot Service Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A vulnerability in Azure Bot Service allows an already-authenticated attacker to elevate their privileges over a network, potentially gaining access beyond their intended permission level. The flaw stems from improper authentication handling within the service. This is significant because bot services often have integrations with sensitive backend systems, meaning privilege escalation could have a wide downstream impact. Security Architect’s Take: Review service principals and managed identities associated with Azure Bot Service deployments and apply the principle of least privilege immediately. Monitor for any anomalous permission changes or unexpected API calls originating from bot service identities while awaiting or applying Microsoft’s patch. ...

18 June 2025 · ZX Cloud Security

CVE-2026-32208: Microsoft Edge XSS Spoofing Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-32208 is a cross-site scripting (XSS) vulnerability in Microsoft Edge (Chromium-based) that allows an authenticated attacker to perform spoofing attacks over a network. The flaw stems from improper handling of user input during web page generation, meaning malicious content could be injected and rendered in a victim’s browser session. This is particularly relevant in enterprise environments where Edge is widely deployed for accessing cloud portals and internal web applications. ...

18 June 2025 · ZX Cloud Security

CVE-2026-42895: Microsoft Copilot Command Injection Flaw

🟠 High | Source: Microsoft Security Response Center A command injection vulnerability in Microsoft Copilot allows an unauthenticated attacker to tamper with the service over a network, without requiring any user interaction or elevated privileges. The flaw stems from improper handling of special characters within commands, a class of vulnerability that can enable attackers to manipulate application behaviour or underlying systems. Given Copilot’s integration across Microsoft 365 and Azure services, the potential blast radius for affected organisations is significant. ...

18 June 2025 · ZX Cloud Security

CVE-2026-47633: Azure Cost Management Info Disclosure

🟠 High | Source: Microsoft Security Response Center A vulnerability in Microsoft Azure Cost Management allows an unauthenticated attacker to access sensitive financial or usage information over a network. The flaw exists within the Cost Management Interactive Experiences component and requires no user interaction or prior authentication to exploit. This is concerning as billing and cost data can expose details about an organisation’s cloud resource footprint, spending patterns, and potentially sensitive infrastructure configurations. ...

18 June 2025 · ZX Cloud Security

CVE-2026-47645: M365 Copilot Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A vulnerability in Microsoft 365 Copilot’s Business Chat allows attackers to exploit an open redirect flaw, redirecting users to malicious sites without authentication. This can be leveraged to elevate privileges over a network, potentially enabling account takeover or credential theft. The risk is heightened given the widespread enterprise adoption of Microsoft 365 Copilot. Security Architect’s Take: Review and restrict access to Microsoft 365 Copilot’s Business Chat where not business-critical, and ensure conditional access policies and phishing-resistant MFA are enforced. Monitor Microsoft’s update guidance and apply any available patches or mitigations promptly, particularly in environments where Copilot has broad data access. ...

18 June 2025 · ZX Cloud Security

CVE-2026-47646: Dynamics 365 Customer Voice XSS Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-47646 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Customer Voice that allows an unauthenticated attacker to perform spoofing attacks over a network. The flaw stems from improper handling of user-supplied input during web page generation, meaning malicious content could be injected and rendered in a victim’s browser. Because no authentication is required to exploit this, the potential reach is broad for any organisation using Customer Voice externally. ...

18 June 2025 · ZX Cloud Security

CVE-2026-47647: Dynamics 365 Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A flaw in Microsoft Dynamics 365 allows an already-authenticated attacker to gain higher privileges than they should have, purely over the network — no physical access required. This means a low-privileged user or compromised account could be leveraged to access sensitive business data or administrative functions within Dynamics 365. Given how widely Dynamics 365 is used for CRM and ERP workflows, the potential business impact is significant. ...

18 June 2025 · ZX Cloud Security

CVE-2026-48582: Exchange Online Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A vulnerability in Microsoft Exchange Online allows an already-authenticated attacker to elevate their privileges beyond what they should have access to. Because Exchange Online is a widely used cloud email platform, a successful exploit could give an attacker significantly greater control over mailboxes, organisational data, or administrative functions. Microsoft has classified this as a network-exploitable issue, meaning no physical access is required. Security Architect’s Take: Review audit logs in Exchange Online for any anomalous privilege changes or unexpected admin role assignments, and ensure least-privilege principles are enforced across all Exchange Online accounts. Monitor the MSRC advisory for patch availability or mitigations and prioritise remediation given the broad blast radius of a compromised email platform. ...

18 June 2025 · ZX Cloud Security

CVE-2026-48584: Azure Synapse Privilege Escalation

🟠 High | Source: Microsoft Security Response Center A vulnerability in Microsoft Azure Synapse Analytics allows an authenticated attacker to elevate their privileges over a network by exploiting unnecessarily broad execution permissions within the service. This means a user with standard access could potentially gain higher-level control than intended, putting sensitive data workloads and analytics environments at risk. The attack requires no physical access and can be carried out remotely, increasing its practical threat level. ...

18 June 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options