ZeroHour

Search: “manipulation”

3 stories in the last 7d

Cisco Identity Services Engine Authentication Bypass Vulnerabilities

Cisco fixed multiple authentication bypass flaws in Identity Services Engine and ISE-PIC enabling remote data access, manipulation, and certificate material disruption.

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on affected devices. Cisco has released software updates, and no workarounds are available. The advisory is part of Cisco's September 2026 publication batch.

Cisco Security Advisoriesupdated · 15m agofirst · 20h agoAdvisory 21 sources

CISA Updates Insider Threat Guide With New Mitigation Advice

CISA updated its Insider Threat Mitigation Guide on September 9 with new case studies and guidance on hybrid work, AI and employee separations.

CISA published a revision of its Insider Threat Mitigation Guide, first issued in 2020, adding case studies, statistics and guidance for security, HR and leadership audiences. New material covers hybrid and remote work changes to physical and digital access, AI used to manipulate or deceive, access control, visitor screening and adverse employee separations. The agency framed the update around growing insider threat impact on critical infrastructure and pointed to preparedness resources for organizations without existing programs.

Infosecurity Magazine · 6d agoAdvisory

Siemens Reyrolle 7SR5

CISA advisory covers 14 vulnerabilities, CVSS 9.8, in Siemens Reyrolle 7SR5 energy-sector protection relays before V2.70.

CISA advisory ICSA-26-258-05 covers 14 vulnerabilities in Siemens Reyrolle 7SR5 protection relays before V2.70, used in the energy sector worldwide, with aggregate CVSS v3 of 9.8. Flaws include Cesanta Mongoose web server issues (CVE-2024-42384 through CVE-2024-42392) and new bugs such as web-interface session-ID exposure enabling authentication bypass (CVE-2026-62645, CVSS 9.8), predictable session tokens (CVE-2026-62646, CVE-2026-62647), and pre-auth out-of-bounds writes (CVE-2026-62648). Siemens has released V2.70 and recommends updating to the latest version.