ZeroHour

Search: “Amazon VPC”

26 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

Dutch NCSC warns exploitation is imminent for critical Check Point VPN RCE flaws CVE-2026-85102 and CVE-2026-85103, urging immediate patching of Security Gateways.

The Dutch NCSC assesses the likelihood and impact of exploitation as high for two critical Check Point VPN flaws, though no public PoC exploit has been reported. CVE-2026-85102 is improper validation of certificate data during VPN negotiation, and CVE-2026-85103 is a heap overflow in the VPN certificate ASN.1 decoder; both enable remote code execution on Security Gateways, the latter also on Security Management Servers. Affected releases span R81.20, R82, R82.10, R81.10.x, R82.00.x and EoS versions R80 through R81.10, while R82.20 is unaffected. Check Point shipped fixes on September 9 via LivePatch Take 24 and Jumbo Hotfix Accumulator takes, and NCSC advises restricting Site-to-Site VPN rules to trusted IPs.

BleepingComputerupdated · 4h agofirst · 4d agoVulnerability 9 sourcesCVE-2026-85102CVE-2026-851032

New Phishing Attacks Use Trusted Email Infrastructure and URL Cloaking to Bypass Security Tools

Virus Bulletin Q3 2026 report details phishing using DKIM-aligned senders, Amazon SES delivery, and real-time URL cloaking to evade email security and scanners.

Virus Bulletin's Q3 2026 testing found phishing campaigns delivered through trusted infrastructure like Amazon SES with DKIM-aligned sender domains. Samples included a German overdue-invoice lure redirecting to OpenSea crypto fraud and a Romanian BCR-branded PSD2 banking credential-theft campaign. Cloaking pages used hidden iframes, browser fingerprinting, and time-zone checks to show different content to scanners versus victims. Defenders are urged to inspect full redirect chains rather than attachments or initial URLs alone.

Cyber Security Newsupdated · 1d agofirst · 1d agoPhishing & fraud in the wild 2 sources

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Cisco warns CVE-2026-76461 in Secure Email Gateway AsyncOS is actively exploited, letting unauthenticated attackers run root commands via crafted emails.

Cisco disclosed CVE-2026-76461, a CVSS 9.8 flaw in AsyncOS for Cisco Secure Email Gateway caused by insufficient validation in email parsing, allowing unauthenticated remote attackers to execute arbitrary SQL statements leading to root command execution. Active exploitation began in September 2026, and CISA added the flaw to its KEV catalog, requiring FCEB agencies to patch by September 17, 2026. Fixes are available in AsyncOS 15.5.5-0141, 16.0.4-302, and 16.5.0-780, with no workarounds. Cisco also contacted Secure Email Cloud customers where malicious activity was detected, and the article separately notes large-scale credential attacks on Fortinet VPN appliances generating tens of millions of authentication failures.

The Hacker Newsupdated · 8h agofirst · 1d agoExploit / PoC in the wild 17 sourcesCVE-2026-76461

Top 10 Best AWS Security Tools in 2026

Editorial roundup ranking the ten best AWS security tools of 2026, from native GuardDuty and Security Hub to CNAPPs like Wiz and Prisma Cloud.

The article recommends enabling AWS-native services first: GuardDuty for threat detection, Security Hub for posture aggregation, the free IAM Access Analyzer, plus CloudTrail logging and Config rules. It then reviews third-party platforms including Wiz, Palo Alto Prisma Cloud, CrowdStrike Falcon Cloud Security, Trend Micro Cloud One, and Orca Security. It is an editorial vendor assessment with pricing described by model only, highlighting cross-account correlation and attack-path prioritization as third-party differentiators.

Cyber Security News · 12h agoTools

AWS Console Private Access can block sign-ins to personal accounts

AWS Console Private Access goes GA, letting internet-isolated VPCs reach the console fully over PrivateLink and blocking personal account sign-ins.

AWS Console Private Access became generally available on August 28, allowing the AWS Management Console, sign-in flows, static assets, and console-only APIs to run entirely over PrivateLink endpoints from VPCs with no internet connectivity. Deployment requires three interface endpoints per Region, correct Private DNS and security group settings, and uses aws:PrincipalOrgID policies plus sign-in resource control policies to deny authentication from unexpected networks, which blocks corporate-network users from signing into personal AWS accounts. IAM Identity Center sign-in and consoles for services without PrivateLink support still need internet access, and a misconfigured policy can lock out the whole organization, so AWS recommends an excluded break-glass role; CLI and SDK SigV4 requests bypass these policies and serve as a recovery path.

Help Net Security · 16d agoTools

Reducto Releases r-1: A Single Pass Document Parsing Model That Cuts Errors 20% at 1 Cent Per Page

Reducto launched r-1, a single-pass document parsing model claiming 20% error reduction over its legacy agentic pipeline, priced at 1 cent per page.

Reducto announced r-1, the first model in a new parsing family that replaces multi-stage agentic OCR with one full-page pass handling text, tables, figures, layout, formatting, and grounding with page-relative bounding boxes. The company reports a 20% error reduction measured against its own legacy agentic pipelines, plus vendor-run wins over Amazon Textract and Azure Document Intelligence on complex documents. Pricing is a flat 1 cent per page versus 3-6 cents for legacy models; r-1 is available in preview via the V3 Parse API with no open weights.

MarkTechPost · 8d agoModel release1

Attack Paths Into VMs in the Cloud

Unit 42 maps attack paths into AWS, Azure, and GCP VMs through intended features like startup scripts and SSH key pushes.

Palo Alto Unit 42 reviewed attack vectors against virtual machine services on AWS, Azure, and GCP, finding that 11% of internet-exposed cloud hosts carry Critical or High severity vulnerabilities. The attack paths rely on legitimate features such as EC2 User Data, VM custom data, EC2 Instance Connect, SSM Run Command, and serial consoles rather than vulnerabilities, and exploiting them requires attackers to first obtain control plane permissions. A compromised VM exposes not only its data but the workload identity and cloud permissions assigned to it, making identity compromise potentially more damaging than data theft. The firm places mitigation responsibility on cloud users and administrators.

Palo Alto Unit 42 · Aug 17, 2026Research1

AWS Systems Manager Agent Vulnerability Allows Attackers to Bypass Port-Forwarding Restrictions

Critical SSRF flaw in AWS SSM Agent (CVE-2026-89049) lets authenticated users bypass link-local denylists and reach EC2 Instance Metadata Service for IAM credentials.

CVE-2026-89049 (Critical, CVSS v3.1 AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) affects Amazon SSM Agent versions earlier than 3.3.4851.0, with the fix shipping in 3.3.4851.0. The remote-host port-forwarding feature's denylist for link-local addresses can be bypassed because equivalent address representations are not validated, enabling SSRF to restricted endpoints such as the EC2 Instance Metadata Service at 169.254.169.254. An attacker with authenticated AWS access and ssm:StartSession permission could retrieve instance profile IAM credentials and pivot to S3, Secrets Manager, Lambda, or other cloud resources depending on role permissions.

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

CISA warns CVE-2026-77477 (CVSS 4.6) lets local attackers hijack a privileged console during OPC UA LDS installation below version 1.04.420.

CISA published ICSA-26-246-01 for CVE-2026-77477, CWE-250 execution with unnecessary privileges in OPC Foundation UA-LDS-Installers below 1.04.420. An attacker able to launch the installer with elevated privileges and access the keyboard and display can intercept a high-privilege console window during installation and run arbitrary commands. CVSS 3.1 score is 4.6, the issue is not remotely exploitable, and no public exploitation has been reported. Lukas Schumaker of Rockwell Automation reported the flaw to OPC Foundation.

CISA Advisories · 13d agoAdvisoryCVE-2026-77477

Cisco security advisory (AV26-197) – Update 3

CISA added Cisco CVE-2026-20079 to its KEV catalog; the Canadian Cyber Centre urges updates across Secure Firewall ASA, FTD, FMC, and SCC products.

The Canadian Centre for Cyber Security updated advisory AV26-197 covering March 2026 Cisco advisories for Security Cloud Control, Secure Firewall Management Center, ASA, and FTD. Cisco confirmed CVE-2026-20131 was actively exploited on March 18, 2026, and CISA added it to KEV on March 19. In Update 3, dated September 9, 2026, CISA added CVE-2026-20079 to the KEV catalog. The underlying flaws include FMC authentication bypass and remote code execution, ASA TCP-flood denial of service, and ASA/FTD IPsec denial of service.

Orthanc DICOM Server

CISA advisory flags CVE-2026-87020, an integer overflow in Orthanc DICOM Server <1.13.0 causing heap out-of-bounds write and denial of service when decoding crafted PNG/JPEG images.

CISA published ICSMA-26-253-02 for Orthanc DICOM Server versions below 1.13.0, used in healthcare environments worldwide. CVE-2026-87020 (CWE-190) is an integer overflow in pitch and buffer-size computation causing a heap out-of-bounds write when decoding attacker-supplied PNG or JPEG images. An authenticated remote attacker can crash the Orthanc process and cause denial of service; CVSS v3.1 is 8.1 HIGH. CISA states no known public exploitation targeting this flaw has been reported.

CISA Advisories · 6d agoAdvisoryCVE-2026-87020

Adobe security advisory (AV26-808) – Update 1

Canada's Cyber Centre updated Adobe advisory AV26-808 to flag that CVE-2026-71362 in Adobe Commerce is being exploited in the wild.

The Canadian Centre for Cyber Security advisory AV26-808 (Update 1) lists vulnerabilities affecting Adobe products including Campaign Classic, Adobe Commerce, Magento Open Source, ColdFusion 2023/2025, Lightroom Classic, and Content Credentials SDKs. Update 1 notes that open-source reporting indicates CVE-2026-71362 is being exploited in the wild. Users and administrators are urged to review the referenced links and apply updates, including those in Adobe bulletin APSB26-92 for Adobe Commerce.

Canadian Centre for Cyber Securityupdated · 5h agofirst · 6d agoAdvisory in the wild 16 sourcesCVE-2026-71362

ZDI-26-557: (Pwn2Own) Amazon Smart Plug Insecure Fallback Information Disclosure Vulnerability

ZDI disclosed a Pwn2Own information disclosure flaw (CVSS 4.3) in Amazon Smart Plug, letting unauthenticated network-adjacent attackers access sensitive information.

The Zero Day Initiative published ZDI-26-557 for an insecure fallback information disclosure flaw in Amazon Smart Plug, demonstrated at Pwn2Own. Unauthenticated network-adjacent attackers can disclose sensitive information on affected installations. ZDI rated the issue CVSS 4.3.

ZDI Published Advisories · Aug 12, 2026Advisory

ZDI-26-558: (Pwn2Own) Amazon Smart Plug OTA Update Process Improper Certificate Validation Vulnerability

ZDI disclosed a Pwn2Own certificate validation flaw (CVSS 6.8) in Amazon Smart Plug's OTA process, allowing network-adjacent attackers to bypass update verification.

The Zero Day Initiative published ZDI-26-558 for an improper certificate validation flaw in the Amazon Smart Plug OTA update process, demonstrated at Pwn2Own. Network-adjacent attackers need no authentication to bypass certificate validation for over-the-air updates. ZDI rated the issue CVSS 6.8.

ZDI Published Advisories · Aug 12, 2026Advisory

Mitsubishi Electric CNC Series (Update A)

CISA's updated ICS advisory details CVE-2025-2399, an out-of-bounds read in Mitsubishi Electric CNC series that lets a remote attacker cause a denial-of-service condition.

CISA released Update A of ICS advisory ICSA-26-078-05 covering Mitsubishi Electric CNC series controllers. The vulnerability CVE-2025-2399 is an out-of-bounds read that a remote attacker can exploit to trigger a denial-of-service condition. Affected products include M800VW, M800VS, M80V, M80VW, M800W, M800S and M80 series controllers up to specified firmware revisions. No exploitation is reported in the advisory.

CISA Advisories · 20d agoAdvisoryCVE-2025-2399

Check Point security advisory (AV26-902)

Canada's Cyber Centre issued advisory AV26-902 warning of two Check Point RCE flaws, including VPN authentication bypass CVE-2026-85102.

The Canadian Centre for Cyber Security released advisory AV26-902 on September 9, 2026, covering vulnerabilities in Check Point Security Gateway, Spark Firewall with Site-to-Site or Remote Access VPN, and Security Management Server across multiple versions. CVE-2026-85102 is an authentication bypass and remote code execution flaw in Remote Access and Site-to-Site VPN, while CVE-2026-85103 is an ASN.1 decoding heap overflow enabling remote code execution. Administrators are urged to review the linked advisories and apply updates as they become available.

VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

ONLYOFFICE's ownCloud integration plugin 9.12 has an SSRF flaw (CVE-2026-84282) letting authenticated admins probe internal networks; no patch exists yet.

CERT/CC published VU#943094 for a server-side request forgery in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin version 9.12, tracked as CVE-2026-84282. The /apps/onlyoffice/ajax/settings/address endpoint does not validate the user-supplied document server URL, so an authenticated administrator can make the ownCloud server send arbitrary requests to localhost and internal hosts. Differences in error responses (connection failures vs SSL/TLS errors) let attackers enumerate open and closed TCP ports for internal reconnaissance. The vendor could not be reached, so no official patch is available; CERT recommends disabling the plugin and applying egress filtering until a fix ships.

HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures

A custom HVNC backdoor is targeting Latin American financial organizations via fake DocuSign and NFe tax-document lures, giving attackers hidden persistent remote access.

ANY.RUN researchers analyzed a multi-stage phishing campaign delivering a custom HVNC backdoor to banking and financial organizations in Latin America. The chain starts with fake DocuSign and NFe tax-document pages that serve per-visitor ZIP archives, followed by an LNK dropper, an NSIS loader, and a 64-bit backdoor masquerading as Windows Update Assistant. The implant provides hidden remote desktop control, keystroke monitoring, Firefox data theft, Startup-folder persistence, and EDR-aware behavior, communicating over TCP/27015.

ANY.RUN · 8d agoMalware in the wild

Organizations Warned of Cisco Secure FMC Exploitation

Cisco and CISA warn that critical FMC authentication bypass CVE-2026-20079 is actively exploited; CISA added it to the KEV catalog with a September 12 deadline.

Cisco and CISA flagged active exploitation of CVE-2026-20079, a critical authentication bypass in Cisco Secure Firewall Management Center allowing remote, unauthenticated attackers to run malicious scripts and gain root access via crafted HTTP requests. Cisco patched the flaw in early March and added IoCs in late July, but confirmed active exploitation in its September 9 advisory; CISA added it to the KEV catalog requiring federal remediation by September 12. Talos identified three activity clusters exploiting CVE-2026-20079 and CVE-2026-20316, including state-sponsored and financially motivated actors, and this is the third FMC vulnerability in KEV this year after CVE-2026-20316 and CVE-2026-20131.

SecurityWeekupdated · 2d agofirst · 6d agoExploit / PoC in the wild 9 sourcesCVE-2026-20079CVE-2026-20316CVE-2026-20131

Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence

Phishing emails with browser-in-the-browser fake Adobe pages trick users into installing rogue ScreenConnect clients granting persistent remote access.

Huntress SOC investigated two August incidents where phishing links led to fake CAPTCHA checks and Adobe PDF Reader lures rendered as browser-in-the-browser (BiTB) pages spoofing legitimate domains like get.adobe.com. Victims downloaded what they believed was Acrobat Reader but actually installed ScreenConnect.ClientSetup.exe from attacker infrastructure, yielding two rogue ScreenConnect clients with service-based persistence. The attacker used cmd.exe and curl to stage a second client connecting to 144.172.115.59, leveraged a ScreenConnect Trial Relay domain for stealth, and ran HideCursor.exe as a defense-evasion binary. Incident 2 arrived via AT&T Office@Hand (RingCentral), with both chains stopped before broader impact.

Huntress · 7d agoPhishing & fraud in the wild

Adobe security advisory (AV26-888)

Canada's Cyber Centre warns CVE-2026-75650 in Adobe Commerce and Magento Open Source is exploited in the wild; hotfixes and updates are available.

Canadian Centre for Cyber Security advisory AV26-888 (September 8, 2026) covers CVE-2026-75650 in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Adobe states the vulnerability is being exploited in the wild. Affected versions extend through the August 2026 patch levels across the 2.4.4-2.4.9 branches, with B2B versions 1.3.x-1.5.x also affected. Administrators are urged to apply the available hotfixes and updates.

CVE-2026-34486: Apache Software Foundation Apache Tomcat

CISA added CVE-2026-34486, an actively exploited Apache Tomcat EncryptInterceptor bypass enabling unauthenticated deserialization RCE, to its KEV catalog.

CVE-2026-34486 allows bypass of Apache Tomcat's EncryptInterceptor, a flaw introduced by the fix for padding-oracle issue CVE-2026-29146 in Tribes cluster encryption. CISA added the flaw to the Known Exploited Vulnerability catalog on August 4, 2026, alongside actively exploited Langflow and N-central flaws, with remediation required under BOD 26-04 guidance. Official patches and workarounds are available, and reporting notes unauthenticated remote code execution through Java deserialization on the Tribes receiver port 4000.

GNU security advisory (AV26-923)

Canadian Cyber Centre advisory AV26-923 flags a stack overflow in GNU libextractor before v1.15 via OLE2 files.

The Canadian Centre for Cyber Security issued advisory AV26-923 on September 15, 2026, covering CVE-2026-91752, a stack overflow vulnerability in GNU libextractor versions prior to 1.15 triggered via OLE2 file parsing. The Cyber Centre encourages users and administrators to review the provided links and apply necessary updates as they become available.

Amazon launches Alexa+ in India with Hindi support

Amazon launched its generative AI Alexa+ assistant in India with Hindi support in Early Access, free for Prime customers after testing.

Amazon announced that Alexa+, its generative AI-powered conversational assistant, is now available in India in Early Access with Hindi and English support, including mid-sentence language switching and long-form context retention. The assistant handles multi-step tasks such as ordering groceries via Amazon Now and controlling smart home devices, with integrations including Swiggy, District, MakeMyTrip, EazyDiner, Amazon Music, and JioSaavn. It will be free for Prime members after the testing period and cost about $20.85 per month for non-Prime customers. Amazon is targeting India's 600 million-plus Hindi speakers, and says smart device adoption grew 20% year over year.

TechCrunch · AI · 11h agoAI industry

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA added four actively exploited vulnerabilities to its KEV catalog, covering Adobe Commerce/Magento, Microsoft Windows, and N-able N-central.

CISA added CVE-2026-75650 (Adobe Commerce and Magento, improper neutralization in a template engine), CVE-2026-81963 (Microsoft Windows link following), CVE-2026-85880 (Microsoft Windows heap-based buffer overflow), and CVE-2026-86218 (N-able N-central static code injection) to the Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Under Binding Operational Directive 26-04, federal civilian agencies must prioritize rapid remediation of KEV-listed vulnerabilities on exposed assets that grant total control post-exploitation and check for pre-patch compromise. All organizations are encouraged to prioritize these flaws in risk-based patching.

CISA Advisories · 8d agoExploit / PoC in the wildCVE-2026-75650CVE-2026-81963CVE-2026-85880+1 CVEs1

Tycon Systems TPDIN-Monitor-WEB2 (Update A)

CISA details CVE-2026-61884 (CVSS 9.8) in Tycon Systems TPDIN-Monitor-WEB2: unauthenticated access to power relays when credentials are unset; fixed in 2.4.5.

CISA updated its advisory for Tycon Systems TPDIN-Monitor-WEB2 firmware below 2.4.5, covering two vulnerabilities. CVE-2026-61884 (CVSS 9.8, CWE-306) lets any network attacker reach full device controls, including power relay management and reboots, on units left without configured HTTP credentials. CVE-2026-55985 exposes stored system credentials in cleartext to authenticated dashboard users, enabling compromise of other local systems. No public exploitation has been reported to CISA.