Cisco Unified CM CVE-2026-20230: SSRF to Root PoC

🔴 Critical | Source: The Hacker News Cisco has patched a server-side request forgery (SSRF) vulnerability in Unified Communications Manager (Unified CM) that allows an unauthenticated network attacker to write arbitrary files to the system and escalate privileges to root. The flaw is tracked as CVE-2026-20230 and public proof-of-concept exploit code is already available, significantly lowering the barrier to exploitation. Cisco’s PSIRT has not confirmed active exploitation in the wild, but the availability of working PoC code makes patching urgent. ...

4 June 2026 Â· ZX Cloud Security

Open Source AI Powers Enterprise Network Worms

🟠 High | Source: The Register — Security Researchers have demonstrated that freely available open source AI models are sufficient to build self-spreading computer worms capable of exploiting known vulnerabilities at scale across enterprise networks — no expensive or specialised AI tools required. The study shows attackers no longer need cutting-edge proprietary models to automate vulnerability exploitation, dramatically lowering the barrier to entry for large-scale attacks. This represents a meaningful shift in the threat landscape, where mass exploitation of known but unpatched vulnerabilities becomes significantly cheaper and faster to operationalise. ...

4 June 2026 Â· ZX Cloud Security

Curved Radio Beams Can Defeat Anti-Jamming Systems

🟡 Medium | Source: The Register — Security Researchers at Rice University have demonstrated that curving or bending radio beams can defeat anti-jamming systems that rely on locating the source of interference. Because the signal no longer travels in a straight line, direction-finding techniques used to identify and counter jammers become ineffective. This has implications for any wireless communication infrastructure, including those supporting cloud-connected IoT, satellite links, and enterprise wireless networks. ...

3 June 2026 Â· ZX Cloud Security

Oracle WebLogic CVE-2024-21182 Actively Exploited

🟠 High | Source: The Hacker News A high-severity vulnerability in Oracle WebLogic Server (CVE-2024-21182) has been added to CISA’s Known Exploited Vulnerabilities catalogue following confirmed active exploitation in the wild. The flaw allows an unauthenticated attacker with network access to take full control of affected servers without any credentials. Any organisation running Oracle WebLogic in cloud or on-premises environments should treat this as an urgent remediation priority. Architect’s Take: Audit your cloud environments immediately for internet-exposed or network-accessible WebLogic instances and apply Oracle’s patch from the January 2024 Critical Patch Update without delay. As an interim control, restrict network access to WebLogic admin ports using security groups or firewall rules, and consider placing instances behind a WAF or application gateway. ...

2 June 2026 Â· ZX Cloud Security