<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Access-Control on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/access-control/</link><description>Recent content in Access-Control on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 04 Jun 2026 15:10:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/access-control/index.xml" rel="self" type="application/rss+xml"/><item><title>Agentic AI in Defence: Secure Your Infrastructure First</title><link>https://zxcloudsecurity.co.uk/posts/agentic-ai-defence-secure-infrastructure-anthropic-claude-mythos/</link><pubDate>Thu, 04 Jun 2026 15:10:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/agentic-ai-defence-secure-infrastructure-anthropic-claude-mythos/</guid><description>Agentic AI boosts defence capabilities but creates new attack surfaces. Learn why secure cloud infrastructure is critical before deployment.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/agentic-ai-is-transforming-defense-but.html">The Hacker News</a></p>
<hr>
<p>Agentic AI systems are increasingly being deployed in defence and security networks, but this introduces new attack surfaces — illustrated by reports that an unauthorised group claimed access to Anthropic&rsquo;s Claude Mythos model within hours of a limited technical preview. The incident highlights that AI capabilities in high-stakes environments are only as secure as the infrastructure underpinning them. Without robust access controls, segmentation, and identity governance, agentic AI deployments can become a significant liability rather than a force multiplier.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Before onboarding any agentic AI model into sensitive or defence-adjacent environments, conduct a thorough access control review: enforce least-privilege API access, implement strict identity verification for model endpoints, and ensure AI workloads are isolated within dedicated network segments with full audit logging enabled.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/agentic-ai-is-transforming-defense-but.html">Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It</a></p>
]]></content:encoded></item><item><title>CVE-2026-35414: OpenSSH Principals Auth Bypass</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-35414-openssh-authorized-keys-principals-bypass-azure/</link><pubDate>Thu, 04 Jun 2026 08:40:55 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-35414-openssh-authorized-keys-principals-bypass-azure/</guid><description>CVE-2026-35414 affects OpenSSH before 10.3, mishandling authorised_keys principals with CA comma characters — risking unauthorised SSH access on Azure VMs.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35414">Microsoft Security Response Center</a></p>
<hr>
<p>A vulnerability in OpenSSH versions before 10.3 (CVE-2026-35414) means the authorised_keys principals option is not handled correctly in certain edge cases where a principals list is combined with a Certificate Authority that uses comma characters in specific ways. This could allow unintended principals to authenticate, potentially granting unauthorised SSH access to affected systems. The issue is particularly relevant to cloud environments where certificate-based SSH authentication is used at scale.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Audit your SSH certificate infrastructure to identify any Certificate Authorities or authorised_keys configurations that use comma characters within principals lists, and prioritise upgrading OpenSSH to 10.3 or later across all Azure VMs and jump hosts. Consider enforcing certificate-based SSH access policies via Azure Policy to ensure patched versions are consistently deployed.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-35414">CVE-2026-35414 OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.</a></p>
]]></content:encoded></item><item><title>AWS IoT Device Management: MQTT Session Data in API</title><link>https://zxcloudsecurity.co.uk/posts/aws-iot-device-management-mqtt-session-data-connectivity-status-api/</link><pubDate>Wed, 03 Jun 2026 21:15:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/aws-iot-device-management-mqtt-session-data-connectivity-status-api/</guid><description>AWS IoT Device Management adds MQTT session data to its connectivity status API, with indefinite retention and IAM-controlled socket-level access for IoT f</description><content:encoded><![CDATA[<p>🟢 <strong>Low</strong>  |  <strong>Source:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-iot-device-management-mqtt/">AWS What&rsquo;s New</a></p>
<hr>
<p>AWS IoT Device Management has enhanced its connectivity status API to include detailed MQTT session data, such as session timeout and expiry values, plus optional socket-level details including IP addresses, ports, and VPC endpoint IDs. Unlike the AWS IoT Core GetConnection API, which only retains data for 30 minutes post-disconnect, this API stores connection history indefinitely, improving long-term auditability. Access to sensitive socket-level information is controlled via IAM policies, allowing organisations to limit visibility to authorised teams.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review and tighten IAM policies governing access to the connectivity status API, particularly the socket-level data permissions, to ensure only operations and security teams have visibility into source/destination IPs and VPC endpoint IDs. Additionally, consider integrating the indefinite data retention capability into your IoT incident response and audit workflows to leverage historical disconnect data for forensic investigations.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://aws.amazon.com/about-aws/whats-new/2026/05/aws-iot-device-management-mqtt/">AWS IoT Device Management adds MQTT session data to connectivity status API</a></p>
]]></content:encoded></item></channel></rss>