Lazarus Windows Zero-Day: SYSTEM Access & Backdoor

🔴 Critical | Source: The Hacker News North Korea’s Lazarus Group has exploited a now-patched zero-day vulnerability in Microsoft Windows to gain SYSTEM-level privileges and deploy a previously unknown backdoor. The campaign, dubbed Operation Dream Job, has targeted defence and aerospace companies in France, Germany, Brazil, and India. This is a highly sophisticated, state-sponsored attack leveraging the highest level of Windows access, making detection and containment particularly challenging. Security Architect’s Take: Prioritise immediate deployment of the latest Microsoft Windows patches across all endpoints and server workloads, including cloud-hosted Windows VMs on Azure, AWS, and GCP. Review EDR telemetry for anomalous SYSTEM-level process creation and lateral movement patterns consistent with Lazarus TTPs, and enforce application allowlisting to limit backdoor execution opportunities. ...

12 August 2026 · ZX Cloud Security

Adobe CVSS 10.0 Flaws: CVE-2026-48362 ColdFusion

🔴 Critical | Source: The Hacker News Adobe has released emergency patches for three CVSS 10.0 vulnerabilities across ColdFusion, Commerce, and Campaign Classic. The most critical flaw (CVE-2026-48362) is an OS command injection vulnerability in ColdFusion that could allow a remote attacker to execute arbitrary commands on the underlying system. These are the highest possible severity ratings and represent serious risk to any organisation running affected Adobe products. Security Architect’s Take: Prioritise patching ColdFusion instances immediately, particularly any internet-facing deployments — CVSS 10.0 OS command injection flaws are frequently weaponised within days of disclosure. If ColdFusion or Campaign Classic runs in your cloud environment, verify patch status now and consider temporarily restricting public access or placing a WAF rule in front of affected services until patching is confirmed. ...

12 August 2026 · ZX Cloud Security

CVE-2026-59310: VMware vCenter RCE Exploited

🔴 Critical | Source: The Hacker News A critical directory-traversal vulnerability in VMware vCenter Server (CVE-2026-59310, CVSS 9.8) is being actively exploited in the wild, allowing unauthenticated attackers with network access to execute arbitrary code remotely. vCenter is a widely deployed management platform for VMware virtualisation infrastructure, meaning successful exploitation can grant attackers control over entire virtualised environments. Patches have been released by Broadcom and should be applied immediately given confirmed active exploitation. ...

12 August 2026 · ZX Cloud Security

Malicious LiteLLM PyPI Releases Expose 2,100+ Orgs

🔴 Critical | Source: The Hacker News Two malicious versions of the LiteLLM Python package were published to PyPI in March and remained available for approximately 40 minutes before removal. The packages contained credential-stealing code capable of harvesting cloud provider keys, SSH keys, Kubernetes tokens, and database credentials from any system that installed them. Threat intelligence firm CloudSEK has linked the incident to the earlier Trivy scanner compromise and estimates over 2,100 organisations may have been exposed based on a dataset of roughly 434,000 captured files. ...

12 August 2026 · ZX Cloud Security

SAP Commerce Cloud CVE-2026-58231: Critical RCE Flaw

🔴 Critical | Source: The Hacker News SAP has patched a maximum-severity vulnerability (CVE-2026-58231, CVSS 10.0) in Commerce Cloud’s Data Hub Adapter that allows unauthenticated attackers to execute arbitrary code. The flaw stems from insufficient authorisation checks and input validation, meaning no credentials are required to exploit it. This represents a critical risk for any organisation running SAP Commerce Cloud in production. Security Architect’s Take: Apply SAP’s patch immediately — a CVSS 10.0 unauthenticated RCE with no prerequisite access is as bad as it gets. Until patched, consider placing WAF rules or network-level controls in front of the Data Hub Adapter endpoint to restrict access to trusted IP ranges only. ...

12 August 2026 · ZX Cloud Security

Microsoft Patch Tuesday: 421 Bugs, One Exploited by North Ko

🔴 Critical | Source: The Register — Security Microsoft’s August 2025 Patch Tuesday addresses 421 vulnerabilities, marking one of the largest monthly patch releases on record. Critically, North Korean threat actors have already been observed actively exploiting at least one of the disclosed vulnerabilities in the wild, meaning some organisations may already be compromised. The sheer volume of patches and the confirmed nation-state exploitation make this a high-priority patching cycle for all Windows and Azure environments. ...

11 August 2026 · ZX Cloud Security

Microsoft Patches 398 Flaws – August 2026 Patch Tuesday

🔴 Critical | Source: Krebs on Security Microsoft’s August 2026 Patch Tuesday addresses 398 security vulnerabilities across Windows and related software — one of the largest single patch releases on record. One vulnerability is actively being exploited in the wild, whilst two others were publicly disclosed before patches were available, increasing the risk of targeted attacks. Organisations running Microsoft products should treat this release as urgent. Security Architect’s Take: Prioritise patching the actively exploited vulnerability and the two publicly disclosed flaws immediately — identify affected assets across cloud-hosted Windows workloads (Azure VMs, AVD, hybrid AD-joined machines) and push emergency patching cycles. Review your Defender for Cloud secure score and Update Manager compliance dashboards to assess exposure at scale before threat actors weaponise the remaining CVEs. ...

11 August 2026 · ZX Cloud Security

Zoom Annotation Bug Lets Attackers Hijack Meeting Clients

🔴 Critical | Source: The Hacker News A vulnerability in Zoom’s annotation feature allowed any meeting participant to silently take over the Zoom client of other attendees — including the presenter — without requiring any interaction from the victim. The flaw required no clicks, downloads, or prompts, meaning simply being present in a meeting was sufficient for exploitation. This represents a significant zero-interaction attack surface for any organisation using Zoom for internal or external meetings. ...

11 August 2026 · ZX Cloud Security

GCP CVE-2024-6387: OpenSSH RCE Bug Hits Compute Engine

🔴 Critical | Source: GCP Compute Engine Security Bulletins A critical remote code execution vulnerability (CVE-2024-6387, also known as ‘regreSSHion’) has been discovered in OpenSSH, allowing an unauthenticated attacker to execute arbitrary code as root. All GCP Compute Engine VMs running glibc-based Linux distributions with OpenSSH exposed to the network are potentially affected. Google has issued patched versions for Container-Optimized OS and TPU images, with broader Linux distribution patches also available. ...

11 August 2026 · ZX Cloud Security

GCP Log4Shell CVE-2021-44228: M4CE Patch Guidance

🔴 Critical | Source: GCP Compute Engine Security Bulletins A critical vulnerability in Apache Log4j (CVE-2021-44228), known as Log4Shell, allows attackers to execute arbitrary code on systems running Log4j version 2.14.1 or below by exploiting the JNDI lookup feature via crafted log messages. Google Cloud’s Migrate for Compute Engine (M4CE) was identified as an affected product. This vulnerability has an exceptionally wide blast radius given Log4j’s near-ubiquitous use in Java-based applications. ...

11 August 2026 · ZX Cloud Security

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options