<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Network-Security on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/network-security/</link><description>Recent content in Network-Security on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 04 Jun 2026 16:55:51 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/network-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Cisco Unified CM CVE-2026-20230: SSRF to Root PoC</title><link>https://zxcloudsecurity.co.uk/posts/cisco-unified-cm-ssrf-privilege-escalation-cve-2026-20230/</link><pubDate>Thu, 04 Jun 2026 16:55:51 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cisco-unified-cm-ssrf-privilege-escalation-cve-2026-20230/</guid><description>Cisco patches CVE-2026-20230 in Unified CM — an SSRF flaw allowing unauthenticated attackers to write files and escalate to root. Public PoC now available.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/cisco-patches-cve-2026-20230-in-unified.html">The Hacker News</a></p>
<hr>
<p>Cisco has patched a server-side request forgery (SSRF) vulnerability in Unified Communications Manager (Unified CM) that allows an unauthenticated network attacker to write arbitrary files to the system and escalate privileges to root. The flaw is tracked as CVE-2026-20230 and public proof-of-concept exploit code is already available, significantly lowering the barrier to exploitation. Cisco&rsquo;s PSIRT has not confirmed active exploitation in the wild, but the availability of working PoC code makes patching urgent.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Apply Cisco&rsquo;s patch immediately and treat any internet- or untrusted-network-exposed Unified CM instances as highest priority. As an interim control, restrict network access to Unified CM admin interfaces to trusted management VLANs only, and review ingress firewall rules to limit the blast radius while patching is under way.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/cisco-patches-cve-2026-20230-in-unified.html">Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public</a></p>
]]></content:encoded></item><item><title>Open Source AI Powers Enterprise Network Worms</title><link>https://zxcloudsecurity.co.uk/posts/open-source-ai-self-spreading-worm-enterprise-vulnerability-exploitation/</link><pubDate>Thu, 04 Jun 2026 07:09:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/open-source-ai-self-spreading-worm-enterprise-vulnerability-exploitation/</guid><description>Researchers prove free open source AI models can build self-spreading worms that exploit known vulnerabilities at scale — no advanced tools needed.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/research/2026/06/04/free-ai-model-powers-self-spreading-worm-in-enterprise-test-network/5250918">The Register — Security</a></p>
<hr>
<p>Researchers have demonstrated that freely available open source AI models are sufficient to build self-spreading computer worms capable of exploiting known vulnerabilities at scale across enterprise networks — no expensive or specialised AI tools required. The study shows attackers no longer need cutting-edge proprietary models to automate vulnerability exploitation, dramatically lowering the barrier to entry for large-scale attacks. This represents a meaningful shift in the threat landscape, where mass exploitation of known but unpatched vulnerabilities becomes significantly cheaper and faster to operationalise.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Prioritise rapid patching cadence and automated vulnerability remediation pipelines — the research confirms that the window between public vulnerability disclosure and weaponised exploitation is shrinking fast. Review your network segmentation controls and lateral movement detection capabilities to limit the blast radius of any self-propagating worm that gains an initial foothold.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/research/2026/06/04/free-ai-model-powers-self-spreading-worm-in-enterprise-test-network/5250918">Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine</a></p>
]]></content:encoded></item><item><title>Curved Radio Beams Can Defeat Anti-Jamming Systems</title><link>https://zxcloudsecurity.co.uk/posts/curved-radio-beams-defeat-anti-jamming-technology-wireless-security/</link><pubDate>Wed, 03 Jun 2026 20:57:39 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/curved-radio-beams-defeat-anti-jamming-technology-wireless-security/</guid><description>Rice University researchers show that bending radio signals defeats direction-finding anti-jamming tech, posing risks to wireless and IoT infrastructure.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/networks/2026/06/03/curving-beams-could-fool-anti-jamming-tech/5250872">The Register — Security</a></p>
<hr>
<p>Researchers at Rice University have demonstrated that curving or bending radio beams can defeat anti-jamming systems that rely on locating the source of interference. Because the signal no longer travels in a straight line, direction-finding techniques used to identify and counter jammers become ineffective. This has implications for any wireless communication infrastructure, including those supporting cloud-connected IoT, satellite links, and enterprise wireless networks.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Cloud architects relying on wireless backhaul, satellite connectivity, or IoT sensor networks should review their signal resilience strategy — consider whether your anti-jamming or interference-detection controls assume line-of-sight propagation, and engage your network security team to assess whether alternative detection methods (e.g. signal fingerprinting or multi-point triangulation) are in scope.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/networks/2026/06/03/curving-beams-could-fool-anti-jamming-tech/5250872">Bend the beam like Beckham to defeat anti-jamming tech</a></p>
]]></content:encoded></item><item><title>Oracle WebLogic CVE-2024-21182 Actively Exploited</title><link>https://zxcloudsecurity.co.uk/posts/oracle-weblogic-cve-2024-21182-kev-active-exploitation/</link><pubDate>Tue, 02 Jun 2026 18:14:42 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/oracle-weblogic-cve-2024-21182-kev-active-exploitation/</guid><description>CISA adds CVE-2024-21182 to KEV catalogue after active exploitation. The CVSS 7.5 flaw lets unauthenticated attackers take control of Oracle WebLogic serve</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/oracle-weblogic-cve-2024-21182-added-to.html">The Hacker News</a></p>
<hr>
<p>A high-severity vulnerability in Oracle WebLogic Server (CVE-2024-21182) has been added to CISA&rsquo;s Known Exploited Vulnerabilities catalogue following confirmed active exploitation in the wild. The flaw allows an unauthenticated attacker with network access to take full control of affected servers without any credentials. Any organisation running Oracle WebLogic in cloud or on-premises environments should treat this as an urgent remediation priority.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Audit your cloud environments immediately for internet-exposed or network-accessible WebLogic instances and apply Oracle&rsquo;s patch from the January 2024 Critical Patch Update without delay. As an interim control, restrict network access to WebLogic admin ports using security groups or firewall rules, and consider placing instances behind a WAF or application gateway.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/oracle-weblogic-cve-2024-21182-added-to.html">Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation</a></p>
]]></content:encoded></item></channel></rss>