ZeroHour

Search: “remote-management”

37 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability

Cisco fixed an unauthenticated Java deserialization RCE in FMC's External Database Access feature allowing root command execution via a TCP port.

Insecure deserialization of a user-supplied Java byte stream in Cisco Secure Firewall Management Center's External Database Access feature lets an unauthenticated remote attacker execute arbitrary commands and elevate to root. Exploitation requires sending a crafted serialized stream to a specific TCP port from a host configured in the external database access list. Cisco has released software updates.

Panzer Ransomware Targets Italian Manufacturers and Telecom Firms With ESXi-Ready RaaS

New Panzer ransomware-as-a-service operation lists Italian firms Doimo Cucine and NTE Italia as victims, offering encryptors for Windows, Linux, FreeBSD, and ESXi.

Panzer, a ransomware-as-a-service operation that surfaced August 5, listed a kitchen manufacturer in Treviso (Doimo Cucine) and a telecommunications engineering firm in Catanzaro (NTE Italia) among alleged victims, claiming 30 GB and 16 GB of stolen data respectively. The group advertises encryptors for Windows, Linux, FreeBSD, and VMware ESXi, a Tox-based affiliate recruitment process with screening, an affiliate dashboard, and an 80/20 revenue split. Neither victim had publicly confirmed the incidents when researcher Andrea Fortuna's report was published, and the group's first access method and payload have not been independently analyzed. Panzer posted victims across 11 countries as claimed Italian ransomware incidents reached 212 by September 6, already above 2025's full-year total of 169.

Cyber Security News · 8d agoRansomware in the wild

RMM Abuse: How Attackers Exploit Remote Access Tools | Huntress

Huntress reports RMM tool abuse jumped 277% and now appears in nearly 40% of its investigations as attackers leverage trusted remote access software.

Huntress observed a 277% increase in remote monitoring and management (RMM) tool abuse, with such abuse now present in nearly 40% of its investigations. Attackers exploit legitimate, trusted remote access tools to gain access and persistence, complicating detection because the software is expected on endpoints. The write-up explains common abuse patterns and defenses against them.

Huntress · 26d agoThreat actor in the wild

3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

Hunt.io found an attacker holding root access inside Thai ISP 3BB via a MeshCentral backdoor, targeting subscriber RADIUS credential databases.

Hunt.io discovered an exposed attacker server on June 3, 2026 revealing an ongoing intrusion at 3BB, one of Thailand's largest broadband providers. The attacker maintained hidden MeshCentral agents reporting to www.ayuthayatech[.]com (device group TH-3BB) and held root on internal servers. Recovered scripts sprayed passwords over SSH against more than 55 internal machines, planted web shells, added SSH keys, searched for stored credentials, and targeted RADIUS subscriber credential databases, though exfiltration was not confirmed. The toolkit included a full exploit for FortiGate SSL-VPN flaw CVE-2024-21762 against mail.3bb.co[.]th, but the initial access vector is unestablished, and a cleanup script erased logs while preserving the backdoor.

The Hacker Newsupdated · 1d agofirst · 2d agoData breach in the wild 3 sourcesCVE-2024-217621

AWS Systems Manager Agent Vulnerability Allows Attackers to Bypass Port-Forwarding Restrictions

Critical SSRF flaw in AWS SSM Agent (CVE-2026-89049) lets authenticated users bypass link-local denylists and reach EC2 Instance Metadata Service for IAM credentials.

CVE-2026-89049 (Critical, CVSS v3.1 AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) affects Amazon SSM Agent versions earlier than 3.3.4851.0, with the fix shipping in 3.3.4851.0. The remote-host port-forwarding feature's denylist for link-local addresses can be bypassed because equivalent address representations are not validated, enabling SSRF to restricted endpoints such as the EC2 Instance Metadata Service at 169.254.169.254. An attacker with authenticated AWS access and ssm:StartSession permission could retrieve instance profile IAM credentials and pivot to S3, Secrets Manager, Lambda, or other cloud resources depending on role permissions.

Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk

ANY.RUN's August 2026 roundup shows US and EU firms hit via Microsoft 365 session hijacking, remote-tool abuse, and hiring lures.

ANY.RUN's August 2026 review catalogs attacks on US and European businesses abusing Microsoft 365 sessions, legitimate remote-management tools, and business-themed files. Observed techniques included account takeover, session hijacking, persistence via remote access, credential exposure, and exploitation of hiring processes. The report stresses that attacker activity frequently resembled legitimate business behavior.

ANY.RUN · 15d agoThreat actor in the wild1

Top 10 Best Browser Isolation Solutions in 2026

A 2026 market overview ranks ten remote browser isolation tools, with Menlo Security as the pure-play reference as SSE vendors bundle isolation.

The article compares ten remote browser isolation (RBI) options, including Menlo Security, Zscaler, Cloudflare, Palo Alto Networks, Broadcom (Symantec), Forcepoint, Skyhigh Security, Ericom (Cradlepoint), Authentic8, and Garrison. It argues that RBI has become a bundled policy action inside SSE platforms from Zscaler, Cloudflare, Palo Alto, Broadcom, Forcepoint, and Skyhigh, compressing standalone pricing and driving consolidation such as Ericom's isolation moving under Cradlepoint (Ericsson). Enterprise browsers like Island and Chrome Enterprise Premium are reshaping the RBI-versus-browser decision for managed users, while selective policy-driven isolation of risky categories is described as the prevailing 2026 architecture. The piece is a buyer's guide with vendor positioning, not an incident or vulnerability report.

Cyber Security News · 5d agoIndustry

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Microsoft details Teams IT-support impersonation campaigns deploying Node.js implants, AD reconnaissance, and WinRM lateral movement toward domain controllers.

Microsoft Threat Intelligence describes a human-operated campaign where attackers impersonate IT/helpdesk staff via Microsoft Teams external collaboration, talk users into granting remote sessions, and use RMM tools for interactive access. During the session they run PowerShell to silently install a malicious MSI that stages a portable Node.js runtime and obfuscated JavaScript implant for C2, executing follow-on payloads via rundll32. Operators then perform host and Active Directory reconnaissance, capture desktop screenshots, and pivot via WinRM on port 5985 to domain controllers and certificate authorities. The hands-on-keyboard chain, which can precede data theft and ransomware, blends into normal operations by relying on Teams, Quick Assist, msiexec, and Node.js; Microsoft shares hunting and mitigation guidance.

Microsoft Security Blog · 13d agoThreat actor in the wild

Best Practices for Good Endpoint Hardening | Huntress

Huntress outlines endpoint hardening best practices, citing exposed RDP, RMM tool abuse, and ClickFix social engineering as common SMB intrusion paths.

Huntress published defensive guidance on endpoint hardening for small and mid-sized businesses, drawing on observations from its SOC. The post describes common intrusion vectors: internet-exposed RDP brute-forced by automated scanners, phishing emails delivering attacker-controlled remote monitoring and management (RMM) tools, with Huntress reporting a 277% spike in RMM abuse in 2025, and ClickFix attacks using fake CAPTCHA pages that trick users into running malicious commands. Recommended controls include scanning for exposed RDP, SSH, and VPN interfaces, removing unneeded local admin rights, enabling Windows Defender tamper protection, disabling SMBv1, and standardizing on one approved remote access tool, guided by CIS and NIST frameworks.

Huntress · 6d agoAdvisory

MikroTik router flaws allow takeover without a password

Attackers actively exploit chained MikroTik RouterOS SSH flaws CVE-2026-67276 and CVE-2026-86060, bypassing authentication and escalating to admin to seize edge routers.

CERT Polska warns of active exploitation of a two-flaw chain dubbed 'MikroTrick' against internet-exposed MikroTik RouterOS devices with SSH remote management enabled. CVE-2026-67276 is an SSH authentication bypass in RSA public-key handling, and CVE-2026-86060 is a privilege-escalation flaw triggered via a specially crafted username, letting attackers gain full administrator control without a password. Patched RouterOS packages are already public, and MikroTik added a startup detection that flags unauthorized configuration changes. Compromised edge routers enable DNS hijacking, traffic capture, remote-access tunnels, firewall changes, and lateral attacks.

Malwarebytes Labs · 8d agoExploit / PoC in the wildCVE-2026-67276CVE-2026-860603

12 Best Endpoint Privilege Management (EPM) Tools Compared (2026): Features & Pricing

A 2026 buyer's guide compares 12 endpoint privilege management tools, ranking CyberArk and BeyondTrust as enterprise leaders.

An editorial comparison evaluates 12 endpoint privilege management (EPM) tools on elevation control, manageability, and pricing model. The guide argues that standing local-admin rights fuel ransomware and lateral movement, making their removal a high-impact control that cyber insurers increasingly mandate. CyberArk and BeyondTrust are positioned as enterprise-depth leaders, with Delinea, Heimdal, and ManageEngine for the mid-market, and Admin By Request and CyberFOX AutoElevate for SMBs and MSPs. Pricing is generally per endpoint or per user, and the article is explicitly an assessment rather than a product release or incident report.

GBHackersupdated · 8h agofirst · 5d agoIndustry 14 sources

Slovakia Warns of Cyber Risks in Road Speed Cameras

Slovakia's NBÚ warns that speed camera systems from SODASUS, Simicon and NEROline pose cyber risks including undocumented remote access.

Slovakia's National Security Authority (NBÚ) warned of a significant cyber threat tied to several road speed camera products: NERO R-ONE units sold by Cyprus-based SODASUS, and Cordon-series cameras made by Russia's Simicon and sold by Croatia's NEROline. A security analysis requested by the Interior Ministry found weak protections, mismatches between documented and actual communication settings and software versions, unclear hardware/software provenance, and pre-configured remote-access mechanisms outside operator control. NBÚ warned that compromised cameras could expose vehicle and licence-plate data, tamper with records, or serve as a foothold into public-sector networks lacking segmentation. The Interior Ministry reportedly removed the units from its pilot deployment and asked the supplier to replace them with equipment meeting Slovak and EU security requirements.

Security Affairs · 23d agoAdvisory

RMM Tools for MSPs: Features, Risks & How to Stay Secure

Threat actors continue abusing MSP remote monitoring and management tools to reach downstream customers, four years after the Kaseya supply chain attack.

Huntress examines how RMM platforms remain a favored gateway for attackers targeting managed service providers and their clients. A recent incident demonstrates that adversaries still successfully pivot from MSP RMM tooling into downstream customer environments. The piece also covers RMM features, associated risks, and hardening guidance for providers.

Huntress · 15d agoThreat actor in the wild

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

Cisco warns of static low-privileged credentials in Secure Firewall Management Center's web interface, letting unauthenticated remote attackers log in and access sensitive data.

Cisco disclosed a vulnerability in the web interface of Secure Firewall Management Center (FMC) Software caused by the presence of static credentials for a low-privileged account. An unauthenticated remote attacker could log in to an affected device using the static account and access sensitive data within impacted systems. The attack surface is reduced when the FMC management interface does not have public internet access.

Cisco Security Advisories · Aug 11, 2026Advisory

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

U.S. Treasury sanctioned nearly 60 Iran-linked entities, including MOIS-affiliated Mabna Institute hackers behind breaches of U.S. critical infrastructure and millions in crypto theft.

The U.S. Treasury launched Operation Economic Outcast, designating nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, cyber, and digital asset networks. Five sanctioned individuals are members of the Tehran-based Mabna Institute indicted last week; three allegedly breached and exfiltrated data from U.S. energy, defense, healthcare, IT, and financial organizations since late 2023. TRM Labs traced roughly $16.8 million across 30 wallets tied to the members, and the State Department announced a reward of up to $10 million. The action follows Iranian hacking of FBI Director Kash Patel's email and attacks on over 30 U.S. water and wastewater utilities.

The Hacker News · 21d agoPolicy & legal in the wild

Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence

Phishing emails with browser-in-the-browser fake Adobe pages trick users into installing rogue ScreenConnect clients granting persistent remote access.

Huntress SOC investigated two August incidents where phishing links led to fake CAPTCHA checks and Adobe PDF Reader lures rendered as browser-in-the-browser (BiTB) pages spoofing legitimate domains like get.adobe.com. Victims downloaded what they believed was Acrobat Reader but actually installed ScreenConnect.ClientSetup.exe from attacker infrastructure, yielding two rogue ScreenConnect clients with service-based persistence. The attacker used cmd.exe and curl to stage a second client connecting to 144.172.115.59, leveraged a ScreenConnect Trial Relay domain for stealth, and ran HideCursor.exe as a defense-evasion binary. Incident 2 arrived via AT&T Office@Hand (RingCentral), with both chains stopped before broader impact.

Huntress · 7d agoPhishing & fraud in the wild

[webapps] Joomla JCE_2.9.15 - Remote Code Execution

A remote code execution proof of concept for Joomla Content Editor (JCE) 2.9.15 was published on Exploit-DB.

Exploit-DB added a webapps proof-of-concept for remote code execution affecting the Joomla Content Editor (JCE) component version 2.9.15. JCE is a widely deployed editor extension used on Joomla websites. The entry provides no CVE id and no evidence of in-the-wild exploitation.

Exploit-DB · Aug 17, 2026Exploit / PoC1

Microsoft Confirms Remote Desktop Services Might Stop Working Following Sept. 2026 Security Update

Microsoft's September 2026 Patch Tuesday updates (KB5124008) can break Remote Desktop Services, causing RDP failures and freezes across Windows clients and servers.

Microsoft confirmed its September 2026 security updates, including KB5124008 for Windows 11 24H2/25H2, introduced a reliability regression where RDP connections fail after several minutes and servers hang at the 'Please wait for the Remote Desktop Configuration' screen. MMC, RDS Licensing Diagnoser, File Explorer, and the Windows Update settings page may also stop responding. The issue affects Windows 10/11 clients and Windows Server 2012 through 2025; Microsoft marked it Mitigated on September 11 and is developing a permanent fix, with VM restart offered as a temporary workaround.

Cyber Security News · 2d agoAdvisory

North Korean remote workers are broadening their job hunt beyond IT

Huntress links suspected North Korean remote workers to sales, marketing, and healthcare jobs using stolen identities, VPNs, proxies, and KVM hardware.

Huntress investigations identified suspected DPRK remote workers hired beyond IT in sales, marketing, and healthcare/financial organizations, sometimes actually performing the work they were hired for. Fraudulent documents included passports from the same city issued one day apart, ID cards with identical validity dates, and electricity bills built from the same online template with matching typos. A financial-services case found a PiKVM and Guermok USB capture card on a new hire's laptop within hours of delivery, suggesting a laptop farm, and another hire used a police mugshot with the photo digitally swapped. Researchers urge rigorous background checks and identity verification at the interview stage.

Help Net Security · 19d agoPhishing & fraud in the wild

CISA Warns of Critical ScreenConnect Vulnerability Actively Exploited in Attacks

CISA added actively exploited ConnectWise ScreenConnect flaw CVE-2026-84869 to the KEV catalog, setting a September 14 patch deadline.

CISA added CVE-2026-84869, a critical improper privilege management and missing authorization flaw (CWE-269, CWE-862) in ConnectWise ScreenConnect, to its Known Exploited Vulnerabilities Catalog on September 11, 2026, confirming active exploitation. The flaw lets attackers transfer files to a device and execute them during an active remote ScreenConnect session without authorization or host-user confirmation, enabling payload delivery, unauthorized tools, and persistence while blending into legitimate remote-management traffic. CISA set a September 14 remediation deadline under BOD 26-04 and flagged the vulnerability as requiring forensic triage. ConnectWise has published a security bulletin, and defenders are urged to review exposure, sessions, file-transfer records, and outbound connections.

mySCADA myPRO Manager

CISA advisory reveals unauthenticated privileged API access and arbitrary SMS sending in mySCADA myPRO Manager <=2.1, CVSS 9.8.

CISA advisory ICSA-26-258-03 discloses two vulnerabilities in mySCADA myPRO Manager <=2.1 with aggregate CVSS v3 of 9.8. CVE-2026-73807 (CVSS 9.8) lets unauthenticated network attackers access privileged management functions via the command API, while CVE-2026-82567 exposes an unauthenticated HTTP endpoint that sends arbitrary SMS messages through a connected GSM modem. Deployments span critical manufacturing, energy, food and agriculture, transportation, and water and wastewater sectors. CISA states no known public exploitation has been reported at this time.

The 12 Best Managed XDR Services, Compared and Priced

A comparison of twelve managed XDR providers covering pricing models, telemetry breadth, and distinguishing genuine MXDR from rebranded MDR services.

The article compares twelve managed XDR providers including Bitdefender, CrowdStrike, Palo Alto Unit 42, Trend Micro, Fortinet, Secureworks Taegis, Stellar Cyber, Ontinue, and ReliaQuest, highlighting pricing models and telemetry breadth. It explains that genuine MXDR must actively monitor identity, cloud, and email telemetry rather than merely ingest it, and typically costs 30-60% more than endpoint-only MDR. It also notes Sophos completed its approximately $859 million acquisition of Secureworks in February 2025.

GBHackers · 7d agoIndustry 3 sources2

Patch Tuesday to Pentest Wednesday: How an Equipment Rental Company Is Turning Continuous Testing Into Continuous Exposure Management

An equipment rental company uses Horizon3 NodeZero for continuous exposure management, surfacing an SSH key exposure in eight hours versus annual pentesting.

The company moved from periodic penetration testing to continuous exposure management using the NodeZero Proactive Security Platform, feeding telemetry into a Splunk-based CTEM pipeline via Horizon3 APIs. NodeZero exposed SSH RSA key pairs from a PHP web server change about eight hours after introduction and found more findings in 12 hours than a third-party engagement found in roughly 30 days. An Active Directory password audit of 15,000 passwords found about 300 identical or similar compromised passwords, driving a banned-password list, 12-character minimums, service desk changes, and self-service reset rollout; users with similar passwords later dropped from 880 to 209. NodeZero also validated a suspected Cisco vulnerability as exploitable.

Horizon3.ai · 7d agoIndustry

Daisy-Chaining Trust: Investigating Faronics Deploy Abuse

Actors abuse Faronics Deploy in phishing campaigns to run PowerShell and deploy ScreenConnect while evading detection with trusted tools.

Huntress investigated attacks in which threat actors abuse Faronics Deploy, a legitimate remote management tool, as part of phishing-driven intrusions. The chain uses the trusted deployment tool to launch PowerShell commands and deploy ScreenConnect for remote access. Leveraging signed, legitimate software helps the actors blend in and evade detection.

Huntress · 15d agoThreat actor in the wild

[webapps] Ghost_CMS 6.19.0 - Remote Code Execution

A public proof-of-concept demonstrates remote code execution in Ghost CMS 6.19.0, the widely deployed open-source publishing platform.

Exploit-DB lists a remote code execution proof of concept affecting Ghost CMS version 6.19.0. Ghost is a popular open-source platform used by publishers and blogs worldwide. The listing does not cite a CVE id or report in-the-wild exploitation.

Exploit-DB · 14d agoExploit / PoC1

Synology ActiveProtect Manager 2.0 improves AI-driven security

Synology released ActiveProtect Manager 2.0, expanding backup coverage to EC2, Azure, Proxmox and Google Workspace, with AI anomaly detection and malware scanning coming in 2.1.

Synology launched ActiveProtect Manager 2.0 for its DP Series data protection appliances, adding platform coverage for Amazon EC2, Azure VM, Proxmox VE, Nutanix AHV and Google Workspace. The release introduces cross-platform recovery, expanded backup destinations including Azure Blob Storage, and volume-level software storage encryption. The upcoming 2.1 update will add AI/ML anomaly detection tracking change rates, mass deletions and entropy, plus pre-restore malware scanning using Microsoft Defender, Bitdefender and ESET with Auto Fallback to the last clean version.

Help Net Security · 12d agoTools

Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026

Cisco's September 2026 hardening release for Secure Email Gateway and Secure Email and Web Manager patches internally found flaws, one actively exploited.

Cisco issued a security hardening release for Cisco Secure Email Gateway and Secure Email and Web Manager covering multiple internally discovered vulnerabilities, grouped by CWE class to streamline patching. Cisco states one of the vulnerabilities is known to be actively exploited. The exploited issue is the Cisco Secure Email Gateway SQL Injection Vulnerability detailed in a companion advisory. Software updates are available.

Cisco Security Advisories · 2d agoAdvisory in the wild6

A revisit of remote Spectre attacks on Cloudflare Workers

Cloudflare details its 2024-2025 reassessment of remote Spectre attacks on Workers, covering new attack primitives and hardened defenses.

Cloudflare reassessed the feasibility of remote Spectre attacks against its Workers serverless infrastructure across 2024 and 2025. The write-up describes new attack primitives including Spectre gadgets, remote timers, and techniques for achieving co-location with victim workloads. It also explains new defenses that further harden Cloudflare Workers against speculative-execution side channels.

Cloudflare Blog · 28d agoResearch

Honeypot-Omaha and batch.py &#x5b;Guest Diary&#x5d;, (Wed, Sep 2nd)

A SANS ISC guest diary describes batch.py, a Python tool that consolidates honeypot logs and enriches IOCs with threat intelligence data.

Written by a SANS.edu BACS intern, the diary explains analysis of the DShield Honeypot-Omaha sensor, which uses Cowrie to emulate SSH and Telnet and log attacker activity. The author's batch.py script implements a four-phase pipeline with SHA-256-generated master and guest authentication to consolidate JSON and log files, correlate data via external APIs, and produce MITRE, CVE, geolocation, threat-score and fingerprint enrichment for investigated indicators.

SANS Internet Storm Center · 13d agoTools1

Top 10 Best Serverless Security Solutions in 2026

Buyer's guide ranks Palo Alto Prisma Cloud and Aqua top for serverless security; standalone serverless security has largely folded into CNAPP platforms.

A top-ten listicle evaluates serverless security tools across FaaS platforms like AWS Lambda, Azure Functions, and Google Cloud Functions. Prisma Cloud and Aqua lead platform coverage, Snyk owns code/dependency scanning, and Sysdig covers runtime behavior. The guide's main conclusion is that the standalone serverless security category has largely consolidated into CNAPP platforms.

Cyber Security News · 1d agoIndustry

The 12 Best Unified Endpoint Management (UEM) Solutions, Compared and Priced

A buyer's guide compares 12 unified endpoint management platforms, recommending Microsoft Intune, Jamf and Omnissa for common scenarios.

The article compares 12 UEM solutions including Microsoft Intune, Omnissa Workspace ONE, Jamf, ManageEngine, Ivanti, SOTI and 42Gears, with pricing models and platform coverage. It flags ownership changes such as Workspace ONE becoming Omnissa, BlackBerry divesting Cylance to Arctic Wolf, and Citrix's status under Cloud Software Group. Guidance centers on checking existing Microsoft 365 licensing before purchasing, per-user versus per-device pricing, and combining platforms like Intune and Jamf for Apple estates.

GBHackersupdated · 6d agofirst · 6d agoIndustry 4 sources

Top 10 Best Mobile Device Management (MDM) Solutions in 2026

A 2026 MDM buyer guide ranks ten solutions, recommending Microsoft Intune for Microsoft 365 estates and Jamf for Apple-only environments.

A 2026 buyer guide evaluates ten mobile device management solutions, leading with Microsoft Intune as the default for Microsoft 365 organizations and Jamf for Apple estates. It recommends choosing the enrolment model before selecting a vendor and clarifying BYOD visibility to prevent privacy disputes. Kandji, Mosyle, Omnissa Workspace ONE, ManageEngine, Scalefusion, and Hexnode are covered as alternatives. Guidance ties MDM to Zero Trust data access policies via Apple User Enrolment and Android work profiles.

Cyber Security News · 7d agoIndustry

Cisco Integrated Management Controller Argument Injection Vulnerabilities

Cisco patched multiple argument-injection vulnerabilities in Cisco IMC's web management interface allowing authenticated attackers root command execution.

Cisco published an advisory covering multiple argument injection vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC). An authenticated, remote attacker could exploit them to execute arbitrary commands on the underlying operating system and elevate privileges to root. Cisco released software updates and states there are no workarounds; the advisory carries a High Security Impact Rating.

Cisco Security Advisories · 21h agoAdvisory

Top 10 Best Cloud Security Posture Management (CSPM) Tools in 2026

2026 CSPM comparison ranks Wiz atop cloud posture tools and recaps Google's pending roughly $32 billion acquisition of Wiz.

An editorial guide rates ten cloud security posture management (CSPM) tools, with Wiz ranked first for agentless visibility and attack-path context, Microsoft Defender for Cloud highlighted for Azure-centric economics, and Palo Alto Prisma Cloud noted for the broadest code-to-cloud module set. The article's biggest market note is Google's agreement to acquire Wiz for approximately $32 billion, described as the largest deal in security history, still progressing through regulatory review. It advises buyers to include roadmap-protection language in multi-year commitments and to press on multicloud neutrality post-close.

Cyber Security News · 5d agoIndustry

Cron Job Injection in Remote Backup

Fortinet FortiSandbox command injection flaw (CVSS 6.7) in remote backup cron jobs lets privileged attackers execute arbitrary code via crafted HTTP requests.

Fortinet advisory FG-IR-26-167 discloses a command injection vulnerability (CWE-77, CVSSv3 6.7) in FortiSandbox's remote backup cron job functionality. A privileged attacker can execute unauthorized code or commands via crafted HTTP requests. The advisory was revised on 2026-09-08.

Fortinet PSIRT · 8d agoAdvisory

Intezer adds native response automation without separate SOAR

Intezer launched Workflows, native response automation inside its AI SOC, letting teams automate remediation without a separate SOAR platform.

Intezer announced Workflows, a native automation and response builder inside its AI SOC platform that lets security teams run post-investigation actions such as closing alerts, isolating hosts, and updating tickets without a separate SOAR. Workflows are created through natural language via MCP, inherit full investigation context, and are logged for audit, with per-tenant routing and customer communications aimed at MSSPs. The announcement cites Intezer's AI SOC Report 2026 finding that nearly 1% of real incidents trace back to lowest-severity alerts.

Help Net Security · 28d agoTools