- Key Takeaways
- What Is Data Privacy Weekly, and Why Does This Edition Matter?
- This Week's Data Privacy and Security Headlines
- Story-to-Action Decision Table
- How to Turn This Week's Headlines Into Action
- Encryption Consulting's Take
- Limitations of This Roundup
- Key Terms in This Edition
- Frequently Asked Questions
- How Encryption Consulting Can Help
- Conclusion
Data Privacy Weekly is Encryption Consulting’s recurring roundup of the data-privacy and security stories that mattered that week. This edition covers the Zenbleed AMD CPU vulnerability, the Maximus MOVEit breach affecting roughly 8 million people, APT31’s campaign against air-gapped systems in Eastern Europe, Google AMP phishing abuse, and Ninja Forms plugin vulnerabilities. The one action to prioritize: confirm hardware-level and third-party vulnerabilities are patched with the same urgency as application-level ones.
Key Takeaways
- The Zenbleed vulnerability let attackers extract sensitive data, including passwords and encryption keys, from all AMD Zen 2 processors; AMD’s microcode patches have since fully closed the gap for systems that applied them.
- US government contractor Maximus disclosed a breach affecting roughly 8 million people, one of the largest single disclosures tied to the Clop group’s mass MOVEit exploitation campaign.
- Chinese state-linked group APT31 ran a multi-stage campaign to compromise air-gapped industrial systems in Eastern Europe, using removable-drive-based implants rather than network access.
- Threat actors abused Google AMP URLs to bypass email security filters and host evasive phishing pages, exploiting the trust associated with Google’s domain.
- Multiple vulnerabilities in the Ninja Forms WordPress plugin, including a reflected XSS flaw, put over 800,000 sites at risk until users updated to the patched version.
What Is Data Privacy Weekly, and Why Does This Edition Matter?
Data Privacy Weekly is a curated recap of the week’s most consequential data-privacy, encryption, and security-incident news, each item paired with a plain-language note on what it means for enterprise security teams. Stories are selected from named primary reporting and vendor advisories at the time of original publication (August 2023); this edition was reviewed in September 2026, with the Zenbleed patch status specifically re-verified against vendor and OS-maintainer documentation.
This edition spans four different layers of the stack in five stories: the CPU itself (Zenbleed), a third-party file-transfer vendor (Maximus/MOVEit), physical media bridging an air gap (APT31), a trusted domain being abused for phishing (Google AMP), and a website plugin (Ninja Forms). The common thread is that “patch your software” has to extend to firmware, vendors, physical media policy, and plugins alike.
This Week’s Data Privacy and Security Headlines
01. Zenbleed Vulnerability Puts AMD Ryzen Users at Risk of Data Theft
What happened: Google security researcher Tavis Ormandy disclosed “Zenbleed” (CVE-2023-20593), a flaw in AMD’s Zen 2 processor family (Ryzen 3000/4000/5000, Threadripper, and Epyc server chips) where a register-clearing error during speculative execution let attackers extract sensitive data, including passwords and encryption keys, from other processes at up to roughly 30KB per core per second. The bug could be triggered without physical access and, according to some researchers, potentially via JavaScript in a browser.
Where this stands now: AMD released microcode patches for its Epyc server line first, with patches for the remaining Zen 2 desktop and mobile chips following through the rest of 2023. Major cloud and OS vendors, including Cloudflare and Ubuntu, applied the fix to their own fleets within days of disclosure. Systems that never applied the relevant microcode, BIOS, or OS-level mitigation remain exposed; this is a patch-verification task, not a closed issue by default.
Why this matters for enterprises: A CPU-level flaw can leak data across process, container, and virtual-machine boundaries, which means it undermines isolation assumptions that application-level encryption depends on. Firmware and microcode patching needs the same tracked, verified rollout as any other critical vulnerability, not a “the hardware vendor will handle it” assumption.
02. US Govt Contractor Maximus Hit by Data Breach: 8 Million People Affected
What happened: US government contractor Maximus disclosed that roughly 8 million people were affected by a breach traced to the Clop group’s exploitation of a zero-day in the MOVEit Transfer application, the same campaign covered in earlier editions of this series. Stolen data included Social Security numbers and health information. Maximus estimated roughly $15 million in investigation and remediation costs and said it found no evidence of further network intrusion beyond the MOVEit-related exposure.
Why this matters for enterprises: Maximus is one more entry in a MOVEit/Clop victim list that grew to more than 2,600 organizations and over 77 million individuals by the time reporting wound down, a scale that underscores why a single third-party software vulnerability now belongs on the same risk register as a direct attack on your own network.
03. Chinese Hackers Compromise Air-Gapped Systems in Eastern Europe
What happened: Kaspersky researchers attributed a prolonged, multi-stage campaign against industrial organizations in Eastern Europe to APT31, a China-linked group. The attackers used a chain of custom implants delivered via removable drives to compromise air-gapped systems, exfiltrate data, and establish command-and-control connections, concealing payloads inside binary data files and legitimate application memory to evade detection.
Why this matters for enterprises: Air-gapping a system reduces but does not eliminate risk; it shifts the attack surface to physical media and the humans who carry it. Organizations running industrial control systems or other air-gapped environments need removable-media controls (scanning, allow-listing, restricted ports) as a core part of the air gap, not an afterthought.
04. Security Alert: Google AMP Exploited for Evasive Phishing Attacks
What happened: Threat actors used Google’s Accelerated Mobile Pages (AMP) URLs, designed to speed up mobile web loading, to host phishing pages while borrowing the trust and reputation of Google’s own domain, making the resulting emails less likely to be flagged by security filters. Attackers layered additional evasion on top: image-based HTML emails, extra redirect steps, and CAPTCHA gates that specifically block automated security-scanner analysis.
Why this matters for enterprises: Email filters that trust a URL based on its domain reputation alone (Google, in this case) can be routed around by hosting the actual malicious content one hop downstream. Layered detection, sandboxed link analysis and user reporting alongside domain reputation, closes the gap that domain-only trust leaves open.
05. Multiple Vulnerabilities Found in Ninja Forms Plugin, 800,000 Sites at Risk
What happened: Researchers disclosed multiple vulnerabilities in the Ninja Forms WordPress plugin (versions 3.6.25 and below), including a reflected cross-site scripting flaw (CVE-2023-37979) and two broken access-control flaws (CVE-2023-38386 and CVE-2023-38393), together putting over 800,000 sites at risk of privilege escalation and sensitive-data exposure. Patchstack, which disclosed the issues, also found similar vulnerabilities in the Freemius WordPress SDK and the HT Mega plugin around the same time. Users were advised to update to version 3.6.26 or later.
Why this matters for enterprises: Website plugins are third-party code running with significant privileges inside your CMS, and a single plugin vulnerability can expose every site built on it, regardless of how well the core CMS itself is maintained. Plugin inventory and patch tracking deserve the same discipline as any other third-party software dependency.
Story-to-Action Decision Table
| Story | Risk Category | Business Impact | Recommended Action |
|---|---|---|---|
| Zenbleed | Hardware / CPU-level vulnerability | Severe if unpatched: crosses process/VM boundaries | Track and verify microcode/BIOS patch status across your fleet like any critical vulnerability |
| Maximus / MOVEit | Third-party software vulnerability | Severe: 8 million people affected, ~$15M remediation cost | Treat critical vendor software vulnerabilities as your own risk register item |
| APT31 air-gapped systems | Physical media / insider-carried threat | High: data exfiltration from supposedly isolated systems | Control and scan removable media at air-gap boundaries; don’t rely on isolation alone |
| Google AMP phishing | Email filtering evasion | Medium-high: bypasses domain-reputation-only filters | Layer sandboxed link analysis on top of domain-reputation filtering |
| Ninja Forms plugin | Third-party plugin vulnerability | High at scale: 800,000+ sites exposed | Maintain a plugin inventory with patch tracking equivalent to core software |
How to Turn This Week’s Headlines Into Action
- Map each story to your own exposure. Identify your AMD Zen 2 fleet, any use of MOVEit or similar file-transfer vendors, air-gapped or isolated systems, email filtering configuration, and website plugin inventory.
- Check current control coverage. Confirm microcode/firmware patch levels, vendor risk assessments, removable-media controls, layered email filtering, and plugin patch status.
- Prioritize by likelihood and impact. An unpatched CPU-level flaw or an unpatched, widely deployed plugin usually outranks a lower-volume, highly targeted campaign like APT31’s in immediate priority, unless you specifically run air-gapped industrial systems.
- Assign an owner and a deadline. Firmware patching often falls to infrastructure teams, plugin patching to web/marketing teams; make sure both have a named owner, since these gaps often fall through organizational cracks.
- Verify the fix. Confirm microcode versions post-patch, re-scan updated plugins, and test that removable-media controls actually block an unauthorized device.
Encryption Consulting’s Take
This edition is a useful antidote to the instinct to only worry about attacks that look sophisticated. Zenbleed and the Ninja Forms flaws are, in security terms, unglamorous: a hardware register-clearing bug and a WordPress plugin’s access-control mistake. Both were patched relatively quickly once disclosed, and both would have stayed fixed for anyone who actually tracked and applied the patch. Maximus is the more sobering story precisely because it required no clever targeting at all, just being one of thousands of organizations that happened to depend on a vendor running vulnerable file-transfer software. The APT31 air-gap story is the outlier that deserves real attention if you run industrial or isolated systems, because it shows physical isolation alone is not a security control, only a speed bump.
Limitations of This Roundup
This edition reflects public reporting and vendor advisories available at the time each story was originally covered (August 2023), reviewed and fact-checked in September 2026, including AMD’s and OS vendors’ patch documentation for Zenbleed. This roundup is informational, not legal, compliance, or incident-response advice, and does not represent an exhaustive account of any referenced incident.
Key Terms in This Edition
- Zenbleed: a hardware vulnerability (CVE-2023-20593) in AMD Zen 2 processors that could leak data across process and VM boundaries via a CPU register-clearing error.
- Microcode: low-level firmware that runs on a CPU and can be updated to fix certain hardware-level flaws without replacing the chip.
- Air-gapped system: a computer or network physically isolated from the internet and other unsecured networks.
- AMP (Accelerated Mobile Pages): a Google web framework for fast-loading mobile pages, which can be abused to host content under a trusted Google domain.
- XSS (cross-site scripting): a vulnerability class where attacker-supplied script runs in a victim’s browser session.
- CVE: Common Vulnerabilities and Exposures, the standard identifier assigned to publicly disclosed security flaws.
Frequently Asked Questions
Is the Zenbleed vulnerability fully patched now?
Yes. AMD released microcode updates covering its Zen 2 processor line (Ryzen 3000/4000/5000, Threadripper, and Epyc) in the months following disclosure, and major operating system and cloud vendors, including Ubuntu and Cloudflare, rolled out the fix to their fleets shortly after disclosure in mid-to-late 2023. Systems that have not applied the relevant microcode or firmware update remain exposed.
Why could a CPU-level bug like Zenbleed leak encryption keys?
Zenbleed exploited a register-clearing error during speculative execution on AMD Zen 2 chips, allowing stale data from another process, potentially including encryption keys and passwords held in memory, to leak through a CPU vector register. Because it operated at the hardware level, it could cross process, container, and even virtual-machine boundaries on an affected system.
Was the Maximus breach part of the same MOVEit campaign as Shell and Colorado State University?
Yes. Maximus, a US government contractor, was one of the largest single disclosures in the Clop group’s mass exploitation of a MOVEit Transfer zero-day, ultimately affecting roughly 8 million people and prompting an estimated $15 million in investigation and remediation costs.
Are air-gapped systems actually safe from remote attackers?
Not automatically. As the APT31 campaign covered in this edition shows, attackers can bridge an air gap using removable media (infected USB drives) carried in by an insider or contractor, then exfiltrate data the same way. An air gap raises the cost of an attack; it does not make one impossible.
How Encryption Consulting Can Help
The thread connecting Zenbleed, Maximus, and the Ninja Forms flaws is cryptographic and software supply-chain visibility across layers you don’t fully control, from silicon to third-party plugins. CBOM Secure discovers and inventories cryptographic assets and dependencies across your environment, including the kind of vendor and plugin software that turned one MOVEit flaw into an 8-million-person breach. HSM-as-a-Service keeps the keys a Zenbleed-style memory-leakage bug could otherwise expose in hardware-isolated, access-controlled storage rather than general CPU memory.
Talk to an expert about CBOM Secure, or see HSM-as-a-Service in action.
Conclusion
None of this edition’s five stories required an especially exotic attack; they required a register-clearing bug, a file-transfer vendor’s unpatched zero-day, a carried-in USB drive, a trusted domain, and an under-patched plugin. Patch discipline has to extend past your own application code to firmware, vendors, physical media, and third-party plugins, or one of these five categories will eventually be the one that gets you.
Go back to the previous edition of Data Privacy Weekly.
- Key Takeaways
- What Is Data Privacy Weekly, and Why Does This Edition Matter?
- This Week's Data Privacy and Security Headlines
- 01. Zenbleed Vulnerability Puts AMD Ryzen Users at Risk of Data Theft
- 02. US Govt Contractor Maximus Hit by Data Breach: 8 Million People Affected
- 03. Chinese Hackers Compromise Air-Gapped Systems in Eastern Europe
- 04. Security Alert: Google AMP Exploited for Evasive Phishing Attacks
- 05. Multiple Vulnerabilities Found in Ninja Forms Plugin, 800,000 Sites at Risk
- Story-to-Action Decision Table
- How to Turn This Week's Headlines Into Action
- Encryption Consulting's Take
- Limitations of This Roundup
- Key Terms in This Edition
- Frequently Asked Questions
- How Encryption Consulting Can Help
- Conclusion
