<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Zero-Day on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/zero-day/</link><description>Recent content in Zero-Day on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 03 Jun 2026 14:56:46 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/zero-day/index.xml" rel="self" type="application/rss+xml"/><item><title>HD Moore Webinar: See Your Network Like an Attacker</title><link>https://zxcloudsecurity.co.uk/posts/hd-moore-webinar-network-attack-surface-visibility-zero-day/</link><pubDate>Wed, 03 Jun 2026 14:56:46 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/hd-moore-webinar-network-attack-surface-visibility-zero-day/</guid><description>HD Moore joins a webinar on moving beyond zero-day patching to network shape and blast radius reduction. Key viewing for cloud security architects.</description><content:encoded><![CDATA[<p>🟢 <strong>Low</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/beyond-zero-day-see-your-network-like.html">The Hacker News</a></p>
<hr>
<p>This is a webinar announcement featuring HD Moore, creator of Metasploit, focused on network exposure and attack surface visibility rather than reactive patching. The core argument is that with zero-days arriving faster than patches and AI accelerating exploit development, organisations must shift focus to limiting what an attacker can reach once inside. It matters because it reframes security strategy around blast radius reduction rather than the increasingly futile race to patch everything in time.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Use this as a prompt to audit your cloud network segmentation and lateral movement paths — map which workloads can reach critical data stores or control planes, and enforce least-privilege network policies (e.g. security groups, VPC firewall rules, micro-segmentation) so a compromised instance has minimal onward reach.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/beyond-zero-day-see-your-network-like.html">Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore</a></p>
]]></content:encoded></item><item><title>HD Moore Webinar: See Your Network Like an Attacker</title><link>https://zxcloudsecurity.co.uk/posts/hd-moore-webinar-network-attack-surface-zero-day-blast-radius/</link><pubDate>Wed, 03 Jun 2026 14:56:46 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/hd-moore-webinar-network-attack-surface-zero-day-blast-radius/</guid><description>HD Moore joins a webinar on why network shape and blast radius matter more than patch speed in a world of endless zero-days and AI-assisted exploits.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/beyond-zero-day-see-your-network-like.html">The Hacker News</a></p>
<hr>
<p>This is a webinar featuring HD Moore, creator of Metasploit, focused on shifting security strategy away from reactive patching and towards understanding network exposure and attack paths. The core argument is that zero-days and AI-generated exploits make &lsquo;patch everything in time&rsquo; an unrealistic goal. What matters more is controlling what an attacker can reach once they&rsquo;re inside — a principle of blast radius reduction.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Use this as a prompt to audit your network segmentation and lateral movement paths in cloud environments — map east-west traffic flows, review VPC peering and transit gateway configurations, and validate that microsegmentation or zero-trust controls are actually limiting what a compromised workload can reach.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/beyond-zero-day-see-your-network-like.html">Beyond the Zero-Day: See Your Network Like an Attacker | Webinar with HD Moore</a></p>
]]></content:encoded></item><item><title>Microsoft Exploit Leak: Researcher Bypasses Disclosure</title><link>https://zxcloudsecurity.co.uk/posts/microsoft-exploit-leak-researcher-bypasses-responsible-disclosure/</link><pubDate>Wed, 03 Jun 2026 14:30:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/microsoft-exploit-leak-researcher-bypasses-responsible-disclosure/</guid><description>A bug hunter has publicly leaked Microsoft exploits in protest at Redmond&amp;#39;s disclosure handling, raising urgent patching concerns for Azure and Windows env</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/security/2026/06/03/another-bug-hunter-leaks-microsoft-exploits-in-defiance-of-companys-handling-of-vulnerability-disclosures/5250590">The Register — Security</a></p>
<hr>
<p>A security researcher has publicly leaked Microsoft exploit code in protest at how the company handles vulnerability disclosures, following a similar incident by a researcher known as Nightmare Eclipse. The move bypasses responsible disclosure norms, meaning working exploits are now publicly available before Microsoft has necessarily issued patches. This significantly raises the risk for organisations running unpatched Microsoft and Azure environments.</p>
<blockquote>
<p><strong>Architect&rsquo;s Take:</strong> Review your Microsoft and Azure patch status immediately and prioritise any outstanding security updates — publicly available exploit code dramatically shortens the window between disclosure and active exploitation. Ensure your vulnerability management process includes alerting on zero-day and pre-patch public exploit releases, not just CVE publication.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/security/2026/06/03/another-bug-hunter-leaks-microsoft-exploits-in-defiance-of-companys-handling-of-vulnerability-disclosures/5250590">Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures</a></p>
]]></content:encoded></item></channel></rss>