Welcome to ZX Cloud Security โ€” a daily intelligence feed for cloud security architects and engineers. We track the latest CVEs, advisories and threats across AWS, Azure and GCP, each enriched with a practical architect's take so you know what actually matters and what to do about it.

New here? Explore our in-depth cloud security guides covering Zero Trust, CSPM, IAM, Kubernetes security and cross-cloud service comparisons.

Updated 13 Jun 2026 06:03 UTC Pipeline runs daily at 06:00 UTC
Critical
10
High
54
Medium
22
Total
107
AWS: 19 Azure: 20 GCP: 0 General: 68
Critical advisory
Velvet Ant Backdoors Linux PAM & OpenSSH for 10 Years
A China-linked threat actor tracked as Velvet Ant spent nearly a decade maintaining persistent access to a targeted network by backdooring PAM (Pluggable Authentication Modules) and OpenSSH โ€” the core
Security Architect's Take: Audit the integrity of PAM configuration files and OpenSSH binaries across all Linux hosts using file integrity monitoring or a trusted read-only baseline โ€” pay particular attention to shared services and jump hosts where a single compromise yields the broadest access. Consider deploying centralised SSH certificate authorities (e.g. HashiCorp Vault SSH, AWS EC2 Instance Connect) to reduce reliance on static authorised_keys files and make backdoored local auth paths easier to detect.

CVE-2026-12043: AWS SDK HTTP/2 RCE Vulnerability

CVE-2026-12043 is a heap double-free in AWS Common Runtime aws-c-http that could allow a malicious server to achieve remote code execution on SDK clients.

๐Ÿ”ด Critical  |  AWS Security Bulletins  |  12 Jun 2026

Velvet Ant Backdoors Linux PAM & OpenSSH for 10 Years

China-linked Velvet Ant compromised PAM and OpenSSH to maintain stealthy Linux access for nearly a decade. Here's what cloud architects must do now.

๐Ÿ”ด Critical  |  The Hacker News  |  12 Jun 2026

LangGraph RCE Flaw Chain: SQL Injection Risk for AI Agents

Three patched LangGraph vulnerabilities, including a critical SQL injection chain, expose self-hosted AI agent deployments to remote code execution. Patch

๐Ÿ”ด Critical  |  The Hacker News  |  12 Jun 2026

CVE-2026-35273: Oracle PeopleSoft Auth Bypass Flaw

CVE-2026-35273 is a critical Oracle PeopleSoft PeopleTools missing authentication flaw enabling full system takeover. Patch by 15 June 2026.

๐Ÿ”ด Critical  |  CISA Known Exploited Vulnerabilities  |  12 Jun 2026

Cisco Unified CM CVE-2026-20230: SSRF to Root PoC

Cisco patches CVE-2026-20230 in Unified CM โ€” an SSRF flaw allowing unauthenticated attackers to write files and escalate to root. Public PoC now available.

๐Ÿ”ด Critical  |  The Hacker News  |  4 Jun 2026

Claude Code GitHub Action Flaw Enabled Repo Hijack

A flaw in Anthropic's Claude Code GitHub Action let attackers hijack public repos via a single issue, risking supply chain compromise across downstream pro

๐Ÿ”ด Critical  |  The Hacker News  |  4 Jun 2026

CVE-2026-45247: Magento RCE Flaw Added to CISA KEV

CISA adds CVE-2026-45247, a CVSS 9.8 RCE flaw in the Mirasvit Cache Warmer Magento extension, to its KEV catalogue amid active exploitation.

๐Ÿ”ด Critical  |  The Hacker News  |  3 Jun 2026

Microsoft 365 Android Debug Flag Exposes Account Tokens

A leftover debug flag in Microsoft 365 Android apps let any installed app steal account tokens silently, exposing email, files and calendar data.

๐Ÿ”ด Critical  |  The Hacker News  |  3 Jun 2026

Microsoft 365 Android Token Theft via Debug Flag Flaw

A leftover debug flag in Microsoft 365 Android apps let any installed app steal account tokens silently, exposing email, files and calendar data.

๐Ÿ”ด Critical  |  The Hacker News  |  3 Jun 2026

CVE-2026-45247: Mirasvit Cache Warmer RCE Flaw

CVE-2026-45247 allows unauthenticated RCE via PHP deserialisation in Mirasvit Full Page Cache Warmer. Actively exploited โ€” patch immediately.

๐Ÿ”ด Critical  |  CISA Known Exploited Vulnerabilities  |  3 Jun 2026

400+ AUR Packages Hijacked to Drop Infostealer & eBPF Rootki

Over 400 Arch Linux AUR packages were compromised to deliver a Rust credential stealer and eBPF rootkit, posing a serious supply chain risk to developers a

๐ŸŸ  High  |  The Hacker News  |  12 Jun 2025

IT Worker Jailed for Sabotaging School District Systems

An Iowa IT worker received 21 months in prison for sabotaging his former school district. Learn what this means for offboarding and insider threat controls

๐ŸŸ  High  |  The Register โ€” Security  |  12 Jun 2025

Novo Nordisk Cyberattack: Clinical Trial Data Stolen

Novo Nordisk confirms hackers stole pseudonymised clinical trial participant data. Here's what cloud security teams should consider in response.

๐ŸŸ  High  |  The Register โ€” Security  |  12 Jun 2025

Microsoft Surface Brick Flaw: Single Packet DoS Patched

A critical Surface firmware flaw allowed devices to be permanently bricked with one network packet. Microsoft has mostly patched the issue โ€” here's what to

๐ŸŸ  High  |  The Register โ€” Security  |  12 Jun 2025

Microsoft Surface Brick Vulnerability Patched | AI Leak

A single packet could brick unprotected Microsoft Surface devices. Microsoft has mostly patched the flaw, which was accidentally exposed via Microsoft Copi

๐ŸŸ  High  |  The Register โ€” Security  |  12 Jun 2025

Agentjacking: AI Coding Agents Tricked Into Running Maliciou

Agentjacking exploits AI coding agents via fake Sentry error reports, tricking them into executing arbitrary code on developer machines.

๐ŸŸ  High  |  The Hacker News  |  12 Jun 2025

OpenAI Codex Chains HTTP/2 DoS Attacks Autonomously

OpenAI's Codex AI agent autonomously chained decade-old HTTP/2 DoS techniques to crash web servers in seconds โ€” here's what architects need to know.

๐ŸŸ  High  |  The Register โ€” Security  |  4 Jun 2026

Agentic AI in Defence: Secure Your Infrastructure First

Agentic AI boosts defence capabilities but creates new attack surfaces. Learn why secure cloud infrastructure is critical before deployment.

๐ŸŸ  High  |  The Hacker News  |  4 Jun 2026

TA4922 China Phishing Threat Hits UK & Europe

China-linked TA4922 expands phishing attacks to the UK, Germany, Italy and South Africa using ValleyRAT and Atlas RAT malware families.

๐ŸŸ  High  |  The Hacker News  |  4 Jun 2026

TA4922 Phishing Targets UK, Germany & Italy

China-linked TA4922 expands phishing attacks to UK, Germany, Italy and South Africa, deploying ValleyRAT and Atlas RAT. What cloud security teams need to k

๐ŸŸ  High  |  The Hacker News  |  4 Jun 2026

Five Eyes Warns of China LinkedIn Spy Recruitment

Five Eyes agencies warn China is targeting government staff via LinkedIn to recruit paid informants. Here's what security teams need to know.

๐ŸŸ  High  |  The Register โ€” Security  |  4 Jun 2026

FlutterShell macOS Backdoor via Malicious Google Ads

Operation FlutterBridge spreads the FlutterShell macOS backdoor via malicious Google and YouTube ads. Learn the risks and mitigations for cloud teams.

๐ŸŸ  High  |  The Hacker News  |  4 Jun 2026

Meta AI Chatbot Exploited for Instagram Account Takeover

Attackers are hijacking Instagram accounts by manipulating Meta's AI support chatbot into resetting passwords. Learn the attack chain and mitigation steps.

๐ŸŸ  High  |  Schneier on Security  |  4 Jun 2026

Meta AI Chatbot Exploited to Hijack Instagram Accounts

Hackers are abusing Meta's AI support chatbot to take over Instagram accounts via social engineering. Learn what this means for AI trust boundaries.

๐ŸŸ  High  |  Schneier on Security  |  4 Jun 2026

Fake Open-Source Sites Deliver Malware via Google SEO

Attackers are using SEO-optimised fake sites mimicking open-source tools to push malware via a Traffic Distribution System. Here's what cloud teams should

๐ŸŸ  High  |  The Hacker News  |  4 Jun 2026

Fake Open-Source Sites Deliver Malware via TDS

Attackers clone open-source project sites, rank them on Google, and use a Traffic Distribution System to deliver stealers and session hijacking malware to

๐ŸŸ  High  |  The Hacker News  |  4 Jun 2026

Executive Outlook Mailbox Spied on via OneDrive & Dropbox

Attackers silently exfiltrated a stock exchange executive's Outlook email for five months, hiding data theft behind Dropbox and OneDrive traffic.

๐ŸŸ  High  |  The Hacker News  |  4 Jun 2026

Stock Exchange Exec Outlook Hacked via OneDrive Exfil

Attackers spent five months silently exfiltrating a stock exchange executive's Outlook mailbox via OneDrive and Dropbox. Here's what cloud architects need

๐ŸŸ  High  |  The Hacker News  |  4 Jun 2026

CVE-2026-9149: Libsolv Heap Buffer Overflow in Azure

CVE-2026-9149 is a heap buffer overflow in libsolv triggered by a crafted .solv file. Learn the impact on Azure Linux workloads and how to remediate.

๐ŸŸ  High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-9150: Libsolv Buffer Overflow in Azure

CVE-2026-9150 is a stack-based buffer overflow in libsolv's Debian metadata parser affecting SHA-384/SHA-512 checksums. Learn the Azure security impact and

๐ŸŸ  High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-46598: Go SSH Agent Client Panic Flaw

CVE-2026-46598 allows pathological inputs to crash Go SSH agent clients, risking denial of service in Azure and other Go-based workloads.

๐ŸŸ  High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-27136: XSS in golang.org/x/net/html on Azure

CVE-2026-27136 is an XSS flaw in Go's golang.org/x/net/html package. Azure-hosted Go apps may be at risk โ€” patch now.

๐ŸŸ  High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-42506: Go x/net/html Namespace Parsing Flaw

CVE-2026-42506 affects golang.org/x/net/html, causing incorrect handling of namespaced elements in foreign content. Azure Go apps may be at risk of XSS or

๐ŸŸ  High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-25681: Go HTML Parsing Flaw in Azure

CVE-2026-25681 affects golang.org/x/net/html with incorrect DOCTYPE character reference handling. Azure workloads using Go may be at risk.

๐ŸŸ  High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-39827: Go SSH Memory Leak DoS Vulnerability

CVE-2026-39827 is a memory leak in golang.org/x/crypto/ssh that enables Denial of Service by rejecting SSH channels. Azure workloads at risk.

๐ŸŸ  High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-39835: Go SSH Library Server Panic Flaw

CVE-2026-39835 allows attackers to crash Go-based SSH servers without authentication via a panic in golang.org/x/crypto/ssh. Azure workloads at risk.

๐ŸŸ  High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-25680: Go HTML Parser DoS Vulnerability

CVE-2026-25680 allows denial of service via malicious HTML in golang.org/x/net/html. Azure-hosted Go apps processing untrusted HTML should patch immediatel

๐ŸŸ  High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-42502: Go HTML Parsing Flaw in Azure

CVE-2026-42502 affects golang.org/x/net/html with incorrect HTML element handling in foreign content. Azure workloads using Go may be at risk.

๐ŸŸ  High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-39828: Go SSH Certificate Bypass in Azure

CVE-2026-39828 allows SSH certificate restriction bypass in golang.org/x/crypto/ssh. Azure-hosted Go workloads may be at risk โ€” patch promptly.

๐ŸŸ  High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-41140: Poetry Path Traversal in Python

CVE-2026-41140 exposes a path traversal flaw in Poetry's tar extraction on Python 3.10โ€“3.11. Learn the risk and how to remediate.

๐ŸŸ  High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-35414: OpenSSH Principals Auth Bypass

CVE-2026-35414 affects OpenSSH before 10.3, mishandling authorised_keys principals with CA comma characters โ€” risking unauthorised SSH access on Azure VMs.

๐ŸŸ  High  |  Microsoft Security Response Center  |  4 Jun 2026

Open Source AI Powers Enterprise Network Worms

Researchers prove free open source AI models can build self-spreading worms that exploit known vulnerabilities at scale โ€” no advanced tools needed.

๐ŸŸ  High  |  The Register โ€” Security  |  4 Jun 2026

Passwords in Active Directory Description Fields Risk

Plaintext passwords stored in Active Directory description fields are readable by any domain user โ€” learn how to audit and remediate this credential exposu

๐ŸŸ  High  |  The Register โ€” Security  |  4 Jun 2026

Rethinking Cloud Resilience Against AI-Driven Attacks

Commvault warns AI-powered attackers are targeting backup infrastructure, leaving victims unable to recover. Here's what cloud architects need to do now.

๐ŸŸ  High  |  The Register โ€” Security  |  3 Jun 2026

Rethinking Cloud Resilience Against AI-Powered Attacks

Commvault warns AI-driven attackers are targeting backup systems, leaving organisations unable to recover. Here's what cloud architects must do now.

๐ŸŸ  High  |  The Register โ€” Security  |  3 Jun 2026

Google Gemini Android Hijack via Notification Prompt Injecti

A prompt injection flaw let malicious WhatsApp, Slack, or SMS notifications hijack Google Gemini on Android โ€” no malware required. Here's what architects n

๐ŸŸ  High  |  The Hacker News  |  3 Jun 2026

Google Gemini Android Prompt Injection via Notifications

A prompt injection flaw let hostile WhatsApp, Slack, and Signal notifications hijack Google Gemini on Android โ€” no malicious app required.

๐ŸŸ  High  |  The Hacker News  |  3 Jun 2026

One-Click GitHub OAuth Token Theft via VS Code

A one-click attack exploiting GitHub.dev and VS Code lets attackers steal GitHub OAuth tokens, exposing private repositories to full read/write access.

๐ŸŸ  High  |  The Hacker News  |  3 Jun 2026

One-Click VS Code Attack Steals GitHub OAuth Tokens

A one-click attack via VS Code's GitHub.dev feature can steal full GitHub OAuth tokens, exposing private repos to read/write access.

๐ŸŸ  High  |  The Hacker News  |  3 Jun 2026

Redis RCE Flaw CVE-2026-23479: 2-Year Bug Patched

Redis patches CVE-2026-23479, a use-after-free RCE flaw active since v7.2.0. Authenticated attackers could execute OS commands on the host. Patch now.

๐ŸŸ  High  |  The Hacker News  |  3 Jun 2026

Redis RCE Flaw CVE-2026-23479: Patch Now

CVE-2026-23479 is a 2-year-old use-after-free RCE vulnerability in Redis 7.2.0+. Learn the risk and how to protect your cloud infrastructure.

๐ŸŸ  High  |  The Hacker News  |  3 Jun 2026

Google DoubleClick Abused to Deliver DesckVB RAT

A new malspam campaign exploits Google's trusted DoubleClick domain to bypass security tools and deliver the DesckVB remote access trojan to victims.

๐ŸŸ  High  |  The Hacker News  |  3 Jun 2026

Microsoft Exploit Leak: Researcher Bypasses Disclosure

A bug hunter has publicly leaked Microsoft exploits in protest at Redmond's disclosure handling, raising urgent patching concerns for Azure and Windows env

๐ŸŸ  High  |  The Register โ€” Security  |  3 Jun 2026

Microsoft Exploit Leaked: Researcher Bypasses Disclosure

A bug hunter has leaked Microsoft exploit code publicly, bypassing responsible disclosure. Cloud architects should patch Microsoft systems immediately.

๐ŸŸ  High  |  The Register โ€” Security  |  3 Jun 2026

Windows Search URI Flaw Leaks NTLMv2 Hashes โ€“ Unpatched

An unpatched Windows search: URI handler vulnerability lets attackers steal NTLMv2 hashes for credential relay or offline cracking. No patch available yet.

๐ŸŸ  High  |  The Hacker News  |  3 Jun 2026

CVE-2025-60876: BusyBox wget Header Injection Flaw

CVE-2025-60876 affects BusyBox wget โ‰ค1.3.7, allowing HTTP header injection via control characters in URLs. Patch container images now.

๐ŸŸ  High  |  Microsoft Security Response Center  |  3 Jun 2026

CVE-2026-25541: Integer Overflow in Rust BytesMut

CVE-2026-25541 exposes an integer overflow in the Rust bytes crate's BytesMut::reserve, risking memory corruption in Azure and cloud-native Rust apps.

๐ŸŸ  High  |  Microsoft Security Response Center  |  3 Jun 2026

CVE-2024-7598: Azure Kubernetes Network Bypass Flaw

CVE-2024-7598 exposes a race condition in Kubernetes namespace termination that allows network restriction bypass in Azure environments. Patch now.

๐ŸŸ  High  |  Microsoft Security Response Center  |  3 Jun 2026

HTTP/2 Bomb DoS Flaw Hits NGINX, Apache, IIS & Envoy

The HTTP/2 Bomb vulnerability enables remote denial-of-service attacks against NGINX, Apache, IIS, Envoy, and Cloudflare Pingora via default HTTP/2 configs

๐ŸŸ  High  |  The Hacker News  |  3 Jun 2026

CVE-2026-10584: AWS Graph Explorer HTTPS Fallback Flaw

CVE-2026-10584 causes Graph Explorer (v1.1.0โ€“3.0.1) to silently fall back to HTTP, exposing Amazon Neptune data in cleartext. Upgrade to v3.0.1 now.

๐ŸŸ  High  |  AWS Security Bulletins  |  2 Jun 2026

Android CVE-2025-48595: June 2026 Patch Alert

Google's June 2026 Android update patches 124 flaws including CVE-2025-48595, an actively exploited privilege escalation bug requiring no user interaction.

๐ŸŸ  High  |  The Hacker News  |  2 Jun 2026

Gamaredon Exploits WinRAR CVE-2025-8088 Malware

Russian APT Gamaredon exploits WinRAR path traversal flaw CVE-2025-8088 to deploy GammaWorm and GammaSteel malware against Ukrainian targets.

๐ŸŸ  High  |  The Hacker News  |  2 Jun 2026

Oracle WebLogic CVE-2024-21182 Actively Exploited

CISA adds CVE-2024-21182 to KEV catalogue after active exploitation. The CVSS 7.5 flaw lets unauthenticated attackers take control of Oracle WebLogic serve

๐ŸŸ  High  |  The Hacker News  |  2 Jun 2026

CVE-2026-10591: Kiro IDE RCE via File Write Flaw

CVE-2026-10591 affects Kiro IDE versions below 0.11, allowing unauthenticated attackers to execute arbitrary commands via writes to sensitive IDE config pa

๐ŸŸ  High  |  AWS Security Bulletins  |  2 Jun 2026

NanoClaw + JFrog: Securing AI Agent Package Downloads

NanoClaw integrates JFrog registries to control what AI agents can download, reducing supply chain risk from autonomous agent package fetching.

๐ŸŸก Medium  |  The Register โ€” Security  |  12 Jun 2024

Google Sues Chinese Smishing Network Using Gemini AI

Google is suing a Chinese cybercrime group that allegedly used Gemini AI to power a phishing-as-a-service platform targeting US users via SMS.

๐ŸŸก Medium  |  The Hacker News  |  12 Jun 2024

Google Sues Chinese Phishing Group Over AI Fraud Ops

Google sues alleged Chinese phishing group 'Outsider Enterprise' for AI-powered fraud sending millions of scam texts via Telegram, impersonating trusted br

๐ŸŸก Medium  |  The Register โ€” Security  |  12 Jun 2024

Rethinking MDR in the Age of AI-Powered Attacks

AI is outpacing traditional MDR models. Learn why cloud security architects must reassess their managed detection and response strategy now.

๐ŸŸก Medium  |  The Hacker News  |  12 Jun 2024

INTERPOL Dismantles Sniper Dz Phishing Platform

INTERPOL's Operation Ramz takes down Sniper Dz phishing-as-a-service platform with 201 arrests across 13 MENA countries. What it means for your security po

๐ŸŸก Medium  |  The Hacker News  |  12 Jun 2024

Europol Dismantles AudiA6 Crypto Laundering Service

Europol has disrupted AudiA6, a crypto laundering service used by ransomware gangs to clean over โ‚ฌ336 million in illicit funds.

๐ŸŸก Medium  |  The Hacker News  |  12 Jun 2024

Weekly Threat Bulletin: AI Agents, C2 Tools & JS Backdoors

Weekly security bulletin covering AI agent abuse, C2 tooling, ClickFix social engineering, JavaScript backdoors and 20+ active threats.

๐ŸŸก Medium  |  The Hacker News  |  4 Jun 2026

Five Eyes Warns of China LinkedIn Recruitment Campaign

Five Eyes agencies warn China is using LinkedIn to recruit insiders for cash-for-secrets operations. What cloud security teams need to know.

๐ŸŸก Medium  |  The Register โ€” Security  |  4 Jun 2026

RAC Data Breach Duo Ordered to Repay ยฃ118k

Two former RAC staff ordered to repay ยฃ118k after selling car crash victims' personal data. A stark reminder of insider threat and GDPR risks.

๐ŸŸก Medium  |  The Register โ€” Security  |  4 Jun 2026

RAC Data Breach: Duo Ordered to Repay ยฃ118k

Two ex-RAC staff who sold car crash victims' personal data must repay ยฃ118k under POCA, highlighting insider threat and data governance risks.

๐ŸŸก Medium  |  The Register โ€” Security  |  4 Jun 2026

CVE-2026-43964: Postfix Buffer Over-Read Crash Flaw

CVE-2026-43964 affects Postfix mail servers, causing process crashes via malformed status codes. Learn the impact and how to patch on Azure infrastructure.

๐ŸŸก Medium  |  Microsoft Security Response Center  |  4 Jun 2026

DoJ Freezes $3.8M in Southeast Asia Crypto Fraud Bust

US DoJ's Disruption Week takedown targets Southeast Asian crypto fraud networks, freezing $3.8M and removing millions of fraudulent accounts.

๐ŸŸก Medium  |  The Hacker News  |  4 Jun 2026

Curved Radio Beams Can Defeat Anti-Jamming Systems

Rice University researchers show curved radio beams can evade anti-jamming tech by hiding signal origins โ€” implications for GPS and satellite-dependent clo

๐ŸŸก Medium  |  The Register โ€” Security  |  3 Jun 2026

Reducing IAM Attack Surface with IVIP Platforms

Identity Dark Matter is exposing enterprise cloud environments to risk. Learn how Identity Visibility and Intelligence Platforms help close IAM gaps.

๐ŸŸก Medium  |  The Hacker News  |  3 Jun 2026

CVE-2025-29923: go-redis Out-of-Order Response Flaw

CVE-2025-29923 in go-redis can cause out-of-order responses when CLIENT SETINFO times out. Learn the risk and remediation steps.

๐ŸŸก Medium  |  Microsoft Security Response Center  |  3 Jun 2026

CVE-2020-8561: Kubernetes Webhook Redirect Flaw in AKS

CVE-2020-8561 allows webhook redirect abuse in kube-apiserver, enabling SSRF via Kubernetes admission webhooks. Affects AKS and self-managed clusters.

๐ŸŸก Medium  |  Microsoft Security Response Center  |  3 Jun 2026

Weedhack MaaS Campaign Hits 86K via Minecraft Mods

The Weedhack malware-as-a-service campaign targets Minecraft players via YouTube, deploying CountLoader and cryptominers across 86,000+ systems since Janua

๐ŸŸก Medium  |  The Hacker News  |  3 Jun 2026

Weedhack MaaS Targets Minecraft Users via YouTube

The Weedhack malware-as-a-service campaign targets Minecraft players via YouTube, with CountLoader hitting 86K victims. Learn what this means for security

๐ŸŸก Medium  |  The Hacker News  |  3 Jun 2026

Ransomware Operator Breaks CIS Rule: What It Means

A ransomware criminal ignored the unwritten rule protecting CIS nations from attack. Here's what this shift means for cloud security teams.

๐ŸŸก Medium  |  The Register โ€” Security  |  2 Jun 2026

Ransomware Operator Caught Breaking CIS No-Target Rule

A ransomware criminal was exposed after targeting Russia-linked CIS countries, violating the unwritten rules that shield many cybercrime groups from prosec

๐ŸŸก Medium  |  The Register โ€” Security  |  2 Jun 2026

Manage Unused AWS KMS Keys & Prevent Deletions

Learn how to audit unused AWS KMS keys, reduce costs, meet compliance requirements, and prevent accidental key deletions across multi-account environments.

๐ŸŸก Medium  |  AWS Security Blog  |  2 Jun 2026

Secure Multi-Tenant AI Agents on AWS Bedrock AgentCore

Learn how AWS Bedrock AgentCore resource-based policies enforce tenant isolation, cross-account access controls, and VPC-only traffic for SaaS AI workloads

๐ŸŸก Medium  |  AWS Security Blog  |  2 Jun 2026

Amazon Cognito Multi-Region Replication | AWS

Amazon Cognito now supports multi-Region replication for user pools, improving authentication resilience and enabling near real-time failover across AWS Re

๐ŸŸข Low  |  AWS What's New  |  4 Jun 2026

AWS Cognito New Lambda Trigger for Federated Sign-In

AWS adds a new Cognito Lambda trigger enabling custom logic during federated sign-in via SAML, OIDC, and social providers. Here's what architects need to k

๐ŸŸข Low  |  AWS Security Blog  |  4 Jun 2026

CVE-2025-1149: GNU Binutils ld Memory Leak โ€“ Azure

CVE-2025-1149 is a memory leak in GNU Binutils ld (xmalloc.c). Learn about the Azure security impact and recommended patching guidance.

๐ŸŸข Low  |  Microsoft Security Response Center  |  4 Jun 2026

AWS IoT Device Management MQTT Session Data API

AWS IoT Device Management adds MQTT session and socket data to its connectivity API. Learn the IAM controls and security implications for IoT fleets.

๐ŸŸข Low  |  AWS What's New  |  3 Jun 2026

AWS IoT Device Management: MQTT Session Data in API

AWS IoT Device Management adds MQTT session data to its connectivity status API, with indefinite retention and IAM-controlled socket-level access for IoT f

๐ŸŸข Low  |  AWS What's New  |  3 Jun 2026

AWS Step Functions Adds AI Agent Steps via AgentCore

AWS Step Functions integrates with Amazon Bedrock AgentCore to embed AI reasoning steps in workflows. Key security considerations for architects.

๐ŸŸข Low  |  AWS What's New  |  3 Jun 2026

OpenAI GPT-5.4 on AWS Bedrock GovCloud (US-West)

OpenAI GPT-5.4 is now available on Amazon Bedrock in AWS GovCloud (US-West), offering isolated inference for government and regulated-industry workloads.

๐ŸŸข Low  |  AWS What's New  |  3 Jun 2026

AWS ARC Adds Aurora & Neptune Failover Automation

AWS ARC Region switch gains Aurora serverless, provisioned scaling, and Neptune failover blocks, automating multi-region DB recovery and reducing RTO.

๐ŸŸข Low  |  AWS What's New  |  3 Jun 2026

AWS SageMaker Unified Studio: 12-Language Support

Amazon SageMaker Unified Studio now supports 12 languages. No security impact โ€” a usability update for global teams with no changes to IAM or access contro

๐ŸŸข Low  |  AWS What's New  |  3 Jun 2026

AWS Config Adds 9 New Resource Types for Bedrock & SageMaker

AWS Config now supports 9 new resource types across Bedrock and SageMaker, improving compliance visibility for AI/ML workloads in your AWS environment.

๐ŸŸข Low  |  AWS What's New  |  3 Jun 2026

AWS ECS Managed Instances Adds Trainium & Inferentia

Amazon ECS Managed Instances now supports Trainium and Inferentia AI accelerators. Learn the security implications for cloud architects running ML workload

๐ŸŸข Low  |  AWS What's New  |  3 Jun 2026

HD Moore Webinar: See Your Network Like an Attacker

HD Moore joins a webinar on moving beyond zero-day patching to network shape and blast radius reduction. Key viewing for cloud security architects.

๐ŸŸข Low  |  The Hacker News  |  3 Jun 2026

AI Cracks Medieval Ciphers: Lessons for Modern Crypto

AI is being used to break historical medieval ciphers. Here's what it means for cloud security architects relying on legacy or weak encryption schemes.

๐ŸŸข Low  |  Schneier on Security  |  3 Jun 2026

AI Decrypts Medieval Ciphers: Crypto Lessons

Researchers use AI to crack historical medieval ciphers. Here's what it means for modern cryptography and legacy encryption risks.

๐ŸŸข Low  |  Schneier on Security  |  3 Jun 2026

UK Banks Excluded from Anthropic Glasswing AI Programme

Anthropic expands its Glasswing partner programme but excludes UK banks, while OpenAI offers GPT-5.5 access โ€” implications for UK financial sector AI strat

๐ŸŸข Low  |  The Register โ€” Security  |  3 Jun 2026

UK Banks Snubbed by Anthropic Glasswing, Offered OpenAI GPT-

Anthropic expands its Glasswing AI partner programme but excludes UK banks. OpenAI steps in with GPT-5.5 access. What this means for financial sector secur

๐ŸŸข Low  |  The Register โ€” Security  |  3 Jun 2026

AWS IoT Core Adds Auth & Ping Logs in CloudWatch

AWS IoT Core now offers Ping and Connection.AuthNError CloudWatch log types to help detect connectivity failures and authentication errors across IoT fleet

๐ŸŸข Low  |  AWS What's New  |  3 Jun 2026

Cisco Mythos AI Bug Hunting: What We Know So Far

Cisco praises its Mythos AI model for finding vulnerabilities but won't reveal the count. Here's what cloud security teams should consider.

๐ŸŸข Low  |  The Register โ€” Security  |  2 Jun 2026

AWS Config Internal Service Linked Rules Explained

AWS Config now supports internal service linked rules, letting AWS services like Security Hub CSPM run independent rule evaluations at no extra cost to cus

๐ŸŸข Low  |  AWS What's New  |  2 Jun 2026

AWS Deadline Cloud Adds Persistent EBS Storage for SMF

AWS Deadline Cloud now supports persistent EBS volumes for Service-Managed Fleets. Learn the security implications for cloud architects managing rendering

๐ŸŸข Low  |  AWS What's New  |  2 Jun 2026

AWS SageMaker Studio Auto-IAM Policy: Security Review

SageMaker Studio now auto-attaches an IAM policy for model customisation. Security architects should audit this managed policy against least-privilege prin

๐ŸŸข Low  |  AWS What's New  |  2 Jun 2026

๐Ÿ“ฌ Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. Learn more