ZeroHour

News

18 stories in the last 48h

Cisco Identity Services Engine Authorization Bypass Vulnerabilities

Cisco fixed authorization bypass flaws in ISE and ISE-PIC web management letting authenticated admins modify file descriptions via crafted HTTP requests.

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine and ISE Passive Identity Connector result from missing server-side validation of Administrator permissions. An authenticated remote attacker with valid Administrator credentials can submit crafted HTTP requests to modify descriptions of files on specific pages. Cisco has released software updates addressing the issues.

Cisco Security Advisoriesupdated · 19m agofirst · 19h agoAdvisory 21 sources

Scammers leave AI fingerprints all over fake antivirus renewal page

Malwarebytes found an AI-built fake Avast renewal page in Belgium whose contractor-style code comments show scammers now generate polished pages with AI.

Malwarebytes analyzed a fake Avast Premium Security renewal page targeting Belgian users, claiming a €129.99 subscription renewal and asking for name, email, and Belgian mobile number. Harvested numbers feed callback scams where fake support agents persuade victims to install remote access software. French comments in the code, written like an AI assistant's unfinished handover, plus leftover styling and feature-free marketing copy suggest the page was generated with AI, meaning convincing localized scam pages can now be produced in minutes.

Hackers Stole Flock’s Camera Software, Revealing How the Company Tracks Cars and People

Hackers who removed a Flock Safety license plate camera dumped its data, revealing person-detection capabilities and an encryption key stored unencrypted on the device.

A hacker collective calling itself stegan0gram physically removed a Flock Safety automatic license plate reader camera from a roadway, copied its storage, and shared the files with 404 Media, WIRED, and Distributed Denial of Secrets. Analysis found an encryption key in an unencrypted 'media' partition that unlocked videos of thousands of vehicle detections, with logs showing more than a million images generated in weeks. The software explicitly detects people, bicycles, and even bumper stickers, and records from one Georgia city were searchable by more than 2,000 agencies nationwide. The findings follow 2025 research by Jon Gaines documenting flaws enabling root-level access to Flock cameras.

404 Mediaupdated · 1h agofirst · 1d agoResearch in the wild 4 sources

Re: Retrospective by 'gpg.fail' authors

GnuPG's Werner Koch says gpg.fail samples only crash GnuPG via DER-as-printf format string in --debug x509; RCE claim remains unproven.

Werner Koch replied to the gpg.fail retrospective, noting that GnuPG versions above 2.2 produce garbled stderr or crash when the project's certificates are used with --debug x509 because DER data is passed as a printf format string. Testing the certificates from the researchers' Git repo yielded only a segfault, not demonstrated code execution. Koch states how remote code execution would be achieved is unclear and asks for a real reproducer.

oss-securityupdated · 8h agofirst · 1d agoVulnerability 9 sources

GNU security advisory (AV26-923)

Canadian Cyber Centre advisory AV26-923 flags a stack overflow in GNU libextractor before v1.15 via OLE2 files.

The Canadian Centre for Cyber Security issued advisory AV26-923 on September 15, 2026, covering CVE-2026-91752, a stack overflow vulnerability in GNU libextractor versions prior to 1.15 triggered via OLE2 file parsing. The Cyber Centre encourages users and administrators to review the provided links and apply necessary updates as they become available.

Canadian Centre for Cyber Securityupdated · 12h agofirst · 1d agoAdvisory 2 sourcesCVE-2026-91752

Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack

The International Meteor Organization says a cyberattack dealt a critical blow to its infrastructure, taking much of its site offline for weeks.

The International Meteor Organization (IMO), a nonprofit coordinating amateur and professional meteor observations since 1988, reported a cyberattack that took much of its website offline. The organization expects several weeks of partial downtime while transitioning to new infrastructure and is prioritizing fireball reporting through alternate channels. The attack vector and whether any data was accessed remain undisclosed; the IMO's observation databases and WGN journal are widely used in the field.

Ars Technica · Security · 14h agoData breach in the wild 2 sources

USN-8775-1: SQLite vulnerability

Ubuntu issued USN-8775-1 fixing a buffer overflow in SQLite's sqlar extension that could cause denial of service via a crafted archive.

Ubuntu Security Notice USN-8775-1 addresses a buffer overflow in the sqlar extension of SQLite. An attacker could trick a user into opening a specially crafted SQLar archive, causing a denial of service. No CVE id is listed in the notice and no exploitation is reported.

Ubuntu Security Noticesupdated · 15h agofirst · 18h agoAdvisory 7 sources

Scans Targeting Hospitality Applications, (Wed, Sep 16th)

Scans from a bulletproof-hosting IP target the abandoned PIAF-HMS hospitality application, which contains numerous unpatched SQL injection flaws.

SANS ISC observed requests for /PIAF-HMS/ using the unusual user-agent Farez-Sorter/1.0, along with paths like /admin/, /ucp/, /hms/, and /hotel/, starting September 15 from the single source IP 94.102.49.125 (IP Volume, AS202425, a bulletproof hoster). PIAF-HMS, a PBX in a Flash Hospitality Management System, was last updated 10 years ago and a SQL injection vulnerability was reported recently; the code shows many injection flaws and lacks authentication and access control. The handler notes hotels are soft targets for personal data theft and guest MitM attacks, and asks for community insight on the campaign.

SANS Internet Storm Center · 16h agoExploit / PoC

Data Broker Radaris Loses Domains in Privacy Fight

A New Jersey court ordered people-search broker Radaris to transfer radaris.com and a dozen related domains to Atlas Data Privacy over Daniel's Law violations.

On August 26, a New Jersey judge found Radaris failed to defend claims that it violated Daniel's Law, which protects law enforcement officials' personal data and imposes $1,000 fines per ignored removal request. The court ordered radaris.com and more than a dozen related broker domains transferred to plaintiff Atlas Data Privacy Corp. Radaris had delayed litigation using offshore shell entities and previously used a fictitious CEO named 'Gary Norden' in investor-facing press releases.

Krebs on Security · 17h agoPolicy & legal

When Agents Look Like Beacons: NIDS Evasion by Model Context Protocol Traffic

Research shows Model Context Protocol agent traffic structurally resembles C2 beaconing and evades Suricata signatures and RITA behavioral scoring in testbeds.

An arXiv study demonstrates that Model Context Protocol (MCP) JSON-RPC traffic over Streamable HTTP mimics the polling patterns of C2 frameworks like Cobalt Strike and is not flagged as anomalous by standard enterprise defenses. In a Docker testbed with eleven traffic profiles across three TLS conditions, Suricata with the Emerging Threats Open ruleset produced near-zero alerts and RITA assigned a consistent 0.0 beacon score, regardless of jitter or TLS inspection. The authors propose an agent-native network indication standard using Agent-Native ALPN and out-of-band headers.

arXiv cs.CR · 18h agoResearch1

Google security advisory (AV26-926)

Canadian Cyber Centre relays Google's Chrome 153.0.8010.48 stable channel update fixing unspecified desktop vulnerabilities.

The Canadian Centre for Cyber Security issued advisory AV26-926 noting that Google Chrome versions prior to 153.0.8010.48 are affected by vulnerabilities. The advisory provides no CVE details or exploitation information and encourages users and administrators to apply the stable channel desktop update for September 15, 2026.

Canadian Centre for Cyber Security · 18h agoAdvisory

Cisco Nexus Dashboard Software Security Hardening Release: September 2026

Cisco released Nexus Dashboard hardening updates for multiple internally discovered vulnerabilities, grouped by CWE and not known to be exploited.

Cisco's Nexus Dashboard engineering team conducted an internal security review that found multiple vulnerabilities, addressed via software hardening releases. The issues were discovered during internal testing and are not known to be actively exploited. Cisco grouped the issues by CWE class and assigned a single CVE ID per issue before releasing fixes.

Cisco Security Advisories · 19h agoAdvisory

Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability

Cisco patched a BroadWorks CommPilot authorization bypass letting low-privileged authenticated users alter device configurations via crafted HTTP requests.

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software is caused by missing authorization checks. An authenticated remote attacker with low privileges can send crafted HTTP requests to alter configurations on select pages. Cisco has released software updates and no workarounds are available.

Cisco Security Advisories · 19h agoAdvisory

CVE-2026-86089: Apache NiFi: Missing Process Group Authorization for Connector Migration

Apache NiFi 2.11.0 Connector Migration REST APIs authorize only against the target Connector, skipping Process Group access checks (CVE-2026-86089, Low).

Apache NiFi 2.11.0 supports migrating version-controlled Process Group contents into a Connector via REST API methods that list eligible migration sources and submit migration requests. Both methods were authorized only against the target Connector, without evaluating user access to the involved Process Groups. The flaw, tracked as CVE-2026-86089, is rated Low severity and affects the nifi-web-api component.

Multiple vulnerabilities in Jenkins plugins

Jenkins releases security fixes for multiple plugins including Bitbucket, GitLab, Gitee, Coverage, and Gradle integrations.

Jenkins published security updates for several plugins, including Bitbucket Push and Pull Request Plugin 4.1.0, Bitbucket Server Integration Plugin 6.0.2, Coverage Plugin 3.3361.v0626103a_67e6, Gitee Plugin 1304.v2702f1d71cde, GitLab Plugin 1.2152.veec0897048b_0, and the Gradle Plugin. The announcement is a routine open-source security release notice without exploit details.

oss-security · 20h agoVulnerability 2 sources1

Forgery of C2PA on a Pixel 10

Researcher forged a Google Pixel 10 C2PA content credential with genuine signatures, showing root-level attackers can fake photo provenance.

A Hacker Factor blog post demonstrates an AI-generated 'unicorn glitter milk' news photo carrying a valid, cryptographically signed C2PA manifest traceable to Google's Pixel camera certificate chain, passing validation in Adobe Inspect and the CAI Verify tool with a verified timestamp. The author, working with UMBC's PASAWG working group, reported to Google and C2PA in November 2025 that root access on a Pixel device could sign arbitrary images as camera captures; after 90 days without resolution, details were published. The finding undermines C2PA Assurance Level 2 claims made for Pixel 10 Content Credentials.

Lobsters · security · 22h agoResearch

USN-8766-1: Suricata-Update vulnerability

Ubuntu patches Suricata-Update path validation flaw allowing arbitrary file writes outside the rules directory from malicious rule archives.

Ubuntu security notice USN-8766-1 fixes a Suricata-Update vulnerability discovered by Guillem Lefait. The tool did not properly validate destination paths when extracting files referenced by downloaded rule archives, allowing an attacker to write arbitrary files outside the configured rules directory. Users are advised to update the suricata-update package.

Ubuntu Security Notices · 1d agoAdvisory

Google’s New Search Redirects Make It Harder to Check Where Links Lead Before Clicking

Malwarebytes reports Google's new encoded google.com/goto?url= redirects break hover-preview link checking, weakening a common phishing defense.

Google now routes some search results through opaque google.com/goto?url= redirects using custom encoding, so browser link previews no longer reveal the true destination, only the claimed label above the result. Malwarebytes found the final destination is visible only in the redirect response's Location header, complicating hover-based safety checks as well as scraping, archiving, and audit tools. The change arrives amid malvertising, search-result poisoning, and fake installer campaigns like the recent Node.js infostealer lure. Google says it deploys measures against evolving abuse but did not explain the change.

Cyber Security News · 1d agoResearch