<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Data-Exfiltration on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/data-exfiltration/</link><description>Recent content in Data-Exfiltration on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 04 Jun 2026 09:33:57 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/data-exfiltration/index.xml" rel="self" type="application/rss+xml"/><item><title>Executive Outlook Mailbox Spied on via OneDrive &amp; Dropbox</title><link>https://zxcloudsecurity.co.uk/posts/stock-exchange-executive-outlook-mailbox-espionage-onedrive-dropbox/</link><pubDate>Thu, 04 Jun 2026 09:33:57 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/stock-exchange-executive-outlook-mailbox-espionage-onedrive-dropbox/</guid><description>Attackers silently exfiltrated a stock exchange executive&amp;#39;s Outlook email for five months, hiding data theft behind Dropbox and OneDrive traffic.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/hackers-spied-on-stock-exchange.html">The Hacker News</a></p>
<hr>
<p>Unknown threat actors maintained covert access to a senior stock exchange executive&rsquo;s Outlook mailbox for at least five months, quietly exfiltrating email data in small batches to evade detection. The stolen data was routed through legitimate cloud storage services — Dropbox and OneDrive — to blend with normal business traffic. Symantec and Carbon Black attribute the campaign to espionage, suggesting a nation-state or sophisticated threat actor targeting financial sector intelligence.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review Microsoft 365 audit logs and Conditional Access policies for unusual mailbox delegation, mail forwarding rules, or OAuth app consents — particularly any third-party app with access to Mail.Read scopes. Implement Cloud App Security (Defender for Cloud Apps) policies to alert on bulk email access or large data transfers to consumer cloud storage services such as Dropbox and OneDrive.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/hackers-spied-on-stock-exchange.html">Hackers Spied on a Stock Exchange Executive&rsquo;s Outlook Mailbox for Five Months</a></p>
]]></content:encoded></item><item><title>Stock Exchange Exec Outlook Hacked via OneDrive Exfil</title><link>https://zxcloudsecurity.co.uk/posts/stock-exchange-executive-outlook-mailbox-espionage-onedrive-dropbox-exfiltration/</link><pubDate>Thu, 04 Jun 2026 09:33:57 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/stock-exchange-executive-outlook-mailbox-espionage-onedrive-dropbox-exfiltration/</guid><description>Attackers spent five months silently exfiltrating a stock exchange executive&amp;#39;s Outlook mailbox via OneDrive and Dropbox. Here&amp;#39;s what cloud architects need</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/hackers-spied-on-stock-exchange.html">The Hacker News</a></p>
<hr>
<p>Unknown threat actors maintained covert access to a senior stock exchange executive&rsquo;s Microsoft Outlook mailbox for at least five months, systematically exfiltrating email data in small batches to avoid detection. The stolen data was routed through Dropbox and OneDrive to blend with legitimate cloud traffic, making it harder for security tools to flag the activity. The campaign bears the hallmarks of a state-sponsored or sophisticated espionage operation targeting high-value financial intelligence.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review Microsoft 365 audit logs and Defender for Cloud Apps policies for anomalous mail export activity, particularly incremental inbox syncs or delegated access from unfamiliar locations — and enforce conditional access policies that restrict OAuth app permissions for third-party cloud storage providers such as Dropbox and OneDrive to prevent data staging and exfiltration via trusted cloud channels.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/hackers-spied-on-stock-exchange.html">Hackers Spied on a Stock Exchange Executive&rsquo;s Outlook Mailbox for Five Months</a></p>
]]></content:encoded></item><item><title>Gamaredon Exploits WinRAR CVE-2025-8088 Malware</title><link>https://zxcloudsecurity.co.uk/posts/gamaredon-winrar-cve-2025-8088-gammaworm-gammasteel-ukraine/</link><pubDate>Tue, 02 Jun 2026 18:21:49 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/gamaredon-winrar-cve-2025-8088-gammaworm-gammasteel-ukraine/</guid><description>Russian APT Gamaredon exploits WinRAR path traversal flaw CVE-2025-8088 to deploy GammaWorm and GammaSteel malware against Ukrainian targets.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html">The Hacker News</a></p>
<hr>
<p>Russian state-linked threat group Gamaredon is actively exploiting CVE-2025-8088, a path traversal vulnerability in WinRAR, to deploy a chain of malware against Ukrainian targets. The attack begins with an HTML Application payload (GammaPhish) which then downloads further malware including GammaWorm and GammaSteel, designed for data theft and lateral propagation. This is a targeted, state-sponsored campaign with significant implications for organisations operating in or with Ukraine.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Ensure WinRAR is patched to a version addressing CVE-2025-8088 across all endpoints, and consider blocking HTA file execution via AppLocker or Windows Defender Application Control policies. Cloud-connected environments should review egress controls and data exfiltration detection rules, particularly for workloads with access to sensitive data stores.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/gamaredon-exploits-winrar-to-deliver.html">Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine</a></p>
]]></content:encoded></item></channel></rss>