<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Spoofing on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/spoofing/</link><description>Recent content in Spoofing on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 18 Jun 2025 14:00:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/spoofing/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-32208: Microsoft Edge XSS Spoofing Flaw</title><link>https://zxcloudsecurity.co.uk/posts/microsoft-edge-xss-spoofing-vulnerability-cve-2026-32208/</link><pubDate>Thu, 18 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/microsoft-edge-xss-spoofing-vulnerability-cve-2026-32208/</guid><description>CVE-2026-32208 is an XSS spoofing vulnerability in Microsoft Edge (Chromium-based). Learn the security impact and remediation steps for cloud environments.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32208">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-32208 is a cross-site scripting (XSS) vulnerability in Microsoft Edge (Chromium-based) that allows an authenticated attacker to perform spoofing attacks over a network. The flaw stems from improper handling of user input during web page generation, meaning malicious content could be injected and rendered in a victim&rsquo;s browser session. This is particularly relevant in enterprise environments where Edge is widely deployed for accessing cloud portals and internal web applications.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Ensure Microsoft Edge is updated to the patched version across all managed endpoints, prioritising devices used to access Azure Portal, M365, and other sensitive web applications. Verify your endpoint management tooling (e.g. Intune or WSUS) has deployed the fix, and consider reviewing Content Security Policy configurations on internally hosted web apps to reduce XSS exposure as a defence-in-depth measure.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32208">CVE-2026-32208 Microsoft Edge (Chromium-based) Spoofing Vulnerability</a></p>
]]></content:encoded></item><item><title>CVE-2026-47646: Dynamics 365 Customer Voice XSS Flaw</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-47646-dynamics-365-customer-voice-xss-spoofing/</link><pubDate>Thu, 18 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-47646-dynamics-365-customer-voice-xss-spoofing/</guid><description>CVE-2026-47646 is an XSS spoofing vulnerability in Microsoft Dynamics 365 Customer Voice exploitable by unauthenticated attackers over a network.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47646">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-47646 is a cross-site scripting (XSS) vulnerability in Microsoft Dynamics 365 Customer Voice that allows an unauthenticated attacker to perform spoofing attacks over a network. The flaw stems from improper handling of user-supplied input during web page generation, meaning malicious content could be injected and rendered in a victim&rsquo;s browser. Because no authentication is required to exploit this, the potential reach is broad for any organisation using Customer Voice externally.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review your Dynamics 365 Customer Voice deployments and ensure Microsoft&rsquo;s patch is applied promptly; additionally, assess whether any customer-facing survey links or embedded forms could be weaponised to deliver spoofed content to end users, and consider adding Content Security Policy (CSP) headers as a compensating control where supported.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47646">CVE-2026-47646 Dynamics 365 Customer Voice Spoofing Vulnerability</a></p>
]]></content:encoded></item><item><title>CVE-2026-47636 SharePoint Server Spoofing Flaw</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-47636-microsoft-sharepoint-server-spoofing-vulnerability/</link><pubDate>Wed, 17 Jun 2026 14:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-47636-microsoft-sharepoint-server-spoofing-vulnerability/</guid><description>CVE-2026-47636 is a spoofing vulnerability in Microsoft SharePoint Server. Learn what it means for your environment and what action to take.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47636">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-47636 is a spoofing vulnerability affecting Microsoft SharePoint Server, which could allow an attacker to impersonate another user or system within the platform. Spoofing vulnerabilities can undermine trust and authentication controls, potentially enabling further attacks such as phishing, data exfiltration, or lateral movement. This update is an acknowledgement change only and carries no new technical detail or patch.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Verify that the latest SharePoint Server cumulative updates are applied across your estate, and review audit logs for any anomalous authentication or identity-related activity. No immediate action is required in response to this specific advisory update, but treat the underlying CVE as a prompt to confirm patch compliance.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47636">CVE-2026-47636 Microsoft SharePoint Server Spoofing Vulnerability</a></p>
]]></content:encoded></item></channel></rss>