CVE-2026-54130: M365 Copilot Info Disclosure Flaw

🟠 High | Source: Microsoft Security Response Center A missing authentication flaw in Microsoft 365 Copilot (CVE-2026-54130) allows an unauthenticated attacker to access sensitive information over a network without any credentials. Because Copilot integrates deeply with organisational data sources such as emails, documents, and Teams conversations, the potential exposure of confidential business data is significant. Microsoft has disclosed this as a high-priority vulnerability requiring attention from organisations using M365 Copilot. Security Architect’s Take: Review your M365 Copilot deployment and apply any available Microsoft patches or mitigations immediately; in the interim, consider restricting Copilot access to trusted network segments or enforcing Conditional Access policies to reduce the attack surface until a fix is confirmed in place. ...

18 June 2025 · ZX Cloud Security

DragonForce Abuses Microsoft Teams C2 Traffic

🟠 High | Source: The Hacker News The DragonForce ransomware group has deployed a custom Go-based backdoor, Backdoor.Turn, that tunnels command-and-control traffic through Microsoft Teams relay infrastructure to evade detection. By blending malicious traffic with legitimate Teams communications, the group makes it significantly harder for defenders to identify or block C2 activity. The technique was observed in an attack against a major US services organisation, flagged by Symantec and Carbon Black. ...

18 June 2025 · ZX Cloud Security

Orphaned AI Agents: Hidden Access Risks in Your Network

🟠 High | Source: The Hacker News Organisations rapidly adopting internal AI agents are accumulating significant access control debt, with autonomous tools continuing to hold active credentials and permissions long after the employees who created them have left. These ‘orphaned’ agents often retain standing privileges to sensitive systems, including core intellectual property, with no clear ownership or oversight. Without visibility into who authorised each agent, security teams cannot effectively audit, revoke, or govern their access. ...

18 June 2025 · ZX Cloud Security

PCI DSS v4 & Third-Party Scripts: Checkout Page Risk

🟠 High | Source: The Hacker News PCI DSS v4.0 now explicitly requires merchants to control and monitor third-party scripts running on payment pages, closing a long-standing blind spot where analytics, tag managers, and support widgets could exfiltrate card data without detection. A QSA assessment of the Reflectiz platform evaluated how well it addresses these new requirements. Any organisation taking card payments online needs to demonstrate they have visibility and control over client-side scripts or risk failing their next PCI audit. ...

18 June 2025 · ZX Cloud Security

CVE-2026-46274: Linux io-wq Kernel Flaw Affects Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-46274 is a Linux kernel vulnerability affecting the io-wq (io_uring work queue) subsystem, specifically a missing hash check in the io_wq_remove_pending() function. This flaw can lead to incorrect handling of predecessor nodes, potentially causing memory corruption or undefined behaviour. It is relevant to Azure environments where Linux-based virtual machines or container workloads rely on the affected kernel component. Security Architect’s Take: Ensure Azure Linux VMs and AKS node pools are running patched kernel versions that include this fix; review your OS image update cadence and consider enabling automatic kernel updates for workloads exposed to untrusted or multi-tenant I/O operations. ...

18 June 2025 · ZX Cloud Security

CVE-2026-28387: Azure DANE Client Use-After-Free Flaw

🟠 High | Source: Microsoft Security Response Center CVE-2026-28387 is a use-after-free vulnerability identified in DANE (DNS-based Authentication of Named Entities) client code, which could allow an attacker to execute arbitrary code or cause a crash by exploiting improper memory management. DANE is used to validate TLS certificates via DNSSEC, meaning this flaw sits within a trust and authentication mechanism. If exploited, the impact could range from denial of service to remote code execution depending on the context in which the vulnerable code runs. ...

18 June 2025 · ZX Cloud Security

CVE-2026-9076: CMS Decryption Out-of-Bounds Read | Azure

🟠 High | Source: Microsoft Security Response Center CVE-2026-9076 is an out-of-bounds read vulnerability in CMS (Cryptographic Message Syntax) password-based decryption, disclosed via Microsoft’s Security Response Center. This type of flaw can allow an attacker to read memory beyond its intended boundary during decryption operations, potentially leaking sensitive data such as cryptographic keys or plaintext content. Depending on where this component is used in Azure services or client tooling, the exposure could be significant for workloads relying on CMS-based encryption. ...

18 June 2025 · ZX Cloud Security

CVE-2026-34180: Azure ASN.1 Heap Buffer Over-read

🟠 High | Source: Microsoft Security Response Center CVE-2026-34180 is a heap buffer over-read vulnerability in ASN.1 content parsing, affecting Microsoft Azure services. This type of flaw allows an attacker to read data beyond the intended memory boundary, potentially exposing sensitive information held in memory. While typically not directly exploitable for remote code execution, information disclosure vulnerabilities of this nature can aid further attacks by leaking cryptographic material or internal state. ...

18 June 2025 · ZX Cloud Security

CVE-2026-42767: Azure CRMF NULL Pointer Dereference

🟠 High | Source: Microsoft Security Response Center CVE-2026-42767 is a NULL pointer dereference vulnerability in the CRMF (Certificate Request Message Format) EncryptedValue decryption process, affecting an Azure-related component. This class of vulnerability can cause application crashes or potentially be leveraged to execute arbitrary code, depending on how the affected component handles malformed input. If exploited, it could disrupt certificate management operations or be used as part of a broader attack chain targeting cryptographic infrastructure. ...

18 June 2025 · ZX Cloud Security

CVE-2026-7383: Azure ASN.1 Heap Buffer Overflow

🟠 High | Source: Microsoft Security Response Center CVE-2026-7383 is a possible heap buffer overflow vulnerability in ASN.1 multibyte string conversion, affecting Microsoft Azure services or components that rely on this cryptographic encoding standard. Heap buffer overflows can allow attackers to corrupt memory, potentially leading to remote code execution or denial of service. The impact depends on where the vulnerable component is deployed and whether it is reachable by untrusted input. ...

18 June 2025 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options