ZeroHour

Search: “authentication bypass”

49 stories in the last 3d

Critical pgAdmin Authentication Bypass Lets Attackers Login as Administrator Without Credentials

pgAdmin 4 versions 6.2-9.17 contain critical auth bypass CVE-2026-86863 (CVSS 9.8) letting unauthenticated attackers impersonate administrators; fixed in 9.18.

A critical authentication bypass (CVE-2026-86863, CVSS 3.1 score 9.8) affects pgAdmin 4 versions 6.2 through 9.17 when Webserver authentication is enabled in AUTHENTICATION_SOURCES. The WebserverAuthentication.get_user() function falls back to client-controlled HTTP headers such as X-Forwarded-User when the WEBSERVER_REMOTE_USER environment variable is absent, allowing unauthenticated remote attackers to log in as any user, including administrators, without a password or MFA. Successful attackers could view, alter, or delete PostgreSQL database objects and data accessible through the hijacked privileged session. Version 9.18 fixes the issue by trusting only genuine CGI/WSGI environment variables by default and requiring explicit options like WEBSERVER_REMOTE_USER_FROM_HEADER with trusted proxies for header-based identity.

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

Cisco patches dozens of critical flaws in FMC, ISE and Nexus Dashboard, including ISE bugs and an authentication bypass already exploited in the wild.

Cisco released patches for dozens of critical-severity CVEs in Secure Firewall Management Center, Identity Services Engine and Nexus Dashboard. ISE updates cover 20 CVEs including 12 critical ones; three publicly disclosed flaws (CVE-2026-20282, CVE-2026-20283, CVE-2026-20284) enable SQL injection, data tampering and command execution but require administrative access. FMC patches fix 18 CVEs, eight critical, several shared with ASA and FTD, where CVE-2026-20079 and CVE-2026-20316 have been exploited since August. Cisco also warned of a critical-severity ISE authentication bypass exploited in the wild as a zero-day.

Cisco drops another exploited zero-day, this time a perfect 10

Cisco's CVSS 10.0 CVE-2026-76460 authentication bypass in Identity Services Engine is actively exploited, granting unauthenticated attackers root command execution.

Cisco disclosed CVE-2026-76460 (CVSS 10.0), an authentication bypass in Identity Services Engine (ISE) and ISE-PIC APIs that gives unauthenticated remote attackers command execution with root privileges; CISA added it to the KEV catalog. It follows CVE-2026-76461 (CVSS 9.8), an actively exploited flaw in Cisco Secure Email Gateway and Secure Email and Web Manager disclosed days earlier. Permanent fixes ship in ISE 3.1 Patch 12 through 3.5 Patch 4; ISE 3.0 is end-of-maintenance and ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4 are available. No workaround exists, though ACLs restricting management traffic can serve as temporary mitigation.

The Register · Securityupdated · 17h agofirst · 1d agoExploit / PoC in the wild 26 sourcesCVE-2026-76460CVE-2026-764615· 1 read

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco patched CVE-2026-76460, a maximum-severity authentication bypass in Identity Services Engine actively exploited in attacks; CISA added it to KEV with a three-day federal deadline.

CVE-2026-76460 is a maximum-severity authentication bypass in an API endpoint of Cisco Identity Services Engine (ISE) and ISE-PIC, exploitable regardless of configuration, allowing attackers to access the web-based management interface. Cisco PSIRT confirmed active exploitation; no workarounds exist, and fixed releases are available for ISE 3.1 through 3.5, with re-imaging of suspect nodes recommended. CISA added the flaw to its Known Exploited Vulnerabilities Catalog and ordered federal agencies to patch within three days. Cisco also patched CVE-2026-76423 and five other critical ISE flaws (CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, CVE-2026-20284) that are not yet flagged as exploited.

BleepingComputer · 1d agoExploit / PoC in the wildCVE-2026-76460CVE-2026-76423CVE-2026-20176+4 CVEs1· 1 read

TP-Link Cameras 0-Day Vulnerabilities Allow Attackers to Spy on Users

Two zero-day flaws in TP-Link Tapo C200 cameras allowed authentication bypass and denial-of-service; fixed in firmware V5_1.4.6.

OPSWAT researchers Khoi Tran and Thai Do found CVE-2026-15315, an authentication bypass in the Tapo C200's local HTTPS interface that lets network-adjacent attackers replay an authentication value to gain administrator access, and CVE-2026-15316, an unauthenticated denial-of-service in the Wi-Fi onboarding process that crashes the camera's HTTPS service. TP-Link was notified on April 16, 2026, confirmed the flaws on July 10, and released patches on August 18, 2026 in firmware V5_1.4.6. Exploitation requires local network access but no valid account, existing session, or user interaction, exposing live feeds and stored recordings to surveillance risk.

Enterprises Warned of Attacks Exploiting WSO2 Vulnerability

Attackers are actively exploiting CVE-2026-5430 (CVSS 10), a WSO2 JWT authentication bypass, to access enterprise API credentials and sensitive data.

WatchTowr's honeypot network recorded the first exploitation attempt of CVE-2026-5430 on September 13, roughly two months after the CVE record was published in early August. The flaw, patched by WSO2 in April with an advisory in May, carries a maximum CVSS score of 10 and allows JWT authentication bypass via tokens signed with unsupported algorithms, enabling unauthorized access and full account takeover. A forged JWT observed in the wild granted access to API backend endpoints, credentials, and consumer keys and secrets for every registered application. WSO2's API Manager, API Control Plane, Traffic Manager, and Universal Gateway are affected, and the platform serves nearly 1,000 enterprise customers in banking, government, telecom, and logistics.

SecurityWeekupdated · 1d agofirst · 2d agoExploit / PoC in the wild 3 sourcesCVE-2026-54302· 1 read

New Check Point flaw lets hackers execute code with root privileges

Check Point patched CVE-2026-91843, a stack-based buffer overflow in Security Management Server logins enabling unauthenticated root remote code execution.

Check Point fixed CVE-2026-91843, a stack-based buffer overflow in the Security Management Server and Log Server login process that allows unauthenticated, low-complexity root RCE without user interaction. All Security Management Server deployments are vulnerable regardless of configuration. Fixes ship via LivePatch, with mitigation limiting SmartConsole Trusted Clients to trusted IPs, and attacks are detectable via 'Administrator failed to log in: Username too long' alerts. The new flaw is not yet flagged as exploited, though Check Point zero-days CVE-2026-50751 and CVE-2026-16232 are actively abused, including by a Qilin ransomware affiliate, and NCSC-NL urged fast patching of CVE-2026-85102 and CVE-2026-85103.

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco warns CVE-2026-76460 (CVSS 10.0), an unauthenticated ISE auth bypass leading to root command execution, is under active exploitation and was added to CISA's KEV.

Cisco warned that CVE-2026-76460 (CVSS 10.0), an insufficient-authentication flaw in an Identity Services Engine (ISE) API endpoint, is being actively exploited by unauthenticated remote attackers and can yield root-privilege command execution on ISE and ISE-PIC regardless of configuration. Fixes shipped across ISE 3.1 through 3.5 patch branches; Cisco advised reviewing access.log for unexpected usernames (e.g., "dummyuser"), re-imaging affected nodes, and using iACLs, since no workarounds exist. CISA added the flaw to its KEV catalog on September 16, 2026, requiring FCEB agencies to patch by September 19. Cisco simultaneously issued 77 new CVEs, 41 affecting ISE and 28 affecting Secure Firewall products, days after confirming active exploitation of CVE-2026-76461 in Secure Email Gateway.

The Hacker News · 1d agoExploit / PoC in the wildCVE-2026-76460CVE-2026-76461CVE-2026-20176+27 CVEs2

Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Vulnerabilities

Cisco fixed sftunnel flaws in Secure Firewall Management Center and Threat Defense allowing unauthenticated authentication bypass or denial of service.

Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) and Secure Firewall Threat Defense (FTD) software could allow an unauthenticated attacker to bypass sftunnel authentication or mount a sftunnel denial-of-service attack. Cisco has released software updates addressing these vulnerabilities. No workarounds are available. The advisory is part of a grouped Cisco release.

Cisco Security Advisories · 1d agoAdvisory 6 sources

Hackers Exploit MikroTik Vulnerabilities to Take Over MikroTik Routers Without Authentication

Attackers chained SSH authentication bypass CVE-2026-67276 and privilege flaw CVE-2026-86060 to fully hijack internet-exposed MikroTik routers before patches existed.

CERT Polska disclosed six MikroTik RouterOS vulnerabilities on September 5, 2026, and confirmed real-world exploitation of SSH-exposed devices beginning around September 2, before public disclosure and patched releases. The actively exploited MikroTrick chain pairs CVE-2026-67276, an SSH authentication bypass, with CVE-2026-86060, a session privilege manipulation flaw, both CVSS 9.2, yielding full administrative control of internet-facing routers. Bishop Fox independently reproduced a related chain using CVE-2026-67279 and CVE-2026-86060 and found post-compromise persistence, including unauthorized full-privilege accounts, scripts, and schedulers showing the unusual owner="0" value. Fixes are available in RouterOS 6.49.21, 7.23.4, and 7.24.2, but updating cannot remove attacker-created persistence.

GBHackersupdated · 4h agofirst · 4h agoExploit / PoC in the wild 2 sourcesCVE-2026-67276CVE-2026-86060CVE-2026-672791

Hitachi Energy FACTS Control Platform (FCP)

CISA republished Hitachi Energy's advisory on five flaws, including two critical CVSS 9.9 issues, in the FACTS Control Platform GWS component for grid systems.

CISA republished Hitachi Energy's advisory for the FACTS Control Platform (FCP) with the GWS component, versions 3.4.0 through 4.1.1, deployed in energy infrastructure such as SVC Light STATCOMs, series capacitors, and synchronous condensers. Five issues are covered: CVE-2024-4872 authenticated query injection (CVSS 9.9), CVE-2024-3980 path traversal (9.9), CVE-2024-3982 capture-replay authentication bypass (8.2), CVE-2024-7940 unauthenticated exposed local service (8.3), and CVE-2024-7941 open redirect. Deployments from 2020 onwards that include the GWS component are likely affected, and vendor mitigation guidance is provided.

Critical HPE Vulnerabilities Allow Remote Attackers to Achieve Complete System Compromise

HPE patched critical EdgeConnect SD-WAN flaws, including CVSS 9.8 unauthenticated API bypass and gateway RCE, enabling full system compromise.

HPE Security Bulletin HPESBNW05135 covers critical flaws in EdgeConnect SD-WAN Orchestrator and Gateways: CVE-2026-76669 and CVE-2026-76670 (CVSS 9.9 authorization bypass/privilege escalation), CVE-2026-76672 (CVSS 9.9, leaks third-party API tokens and credentials), CVE-2026-76673 (CVSS 9.8, unauthenticated Orchestrator API authentication bypass granting administrative privileges), and CVE-2026-76674 (CVSS 9.8, unauthenticated buffer overflow enabling arbitrary code execution on gateways). Fixes are available in ECOS 9.7.1.0/9.6.4.0/9.5.9.0/9.4.9.0 and Orchestrator 9.7.1/9.6.4/9.5.9/9.4.11 or later. HPE reported no public exploit code or active exploitation at publication and recommends isolating management interfaces on a dedicated VLAN.

Cyber Security Newsupdated · 1d agofirst · 2d agoVulnerability 2 sourcesCVE-2026-76669CVE-2026-76670CVE-2026-76672+2 CVEs

The Apple Security Update Review for September 2026

Apple's September 2026 updates patch 45+ flaws, including a 9.8 Screen Sharing authentication bypass (CVE-2026-65400) already listed in CISA's KEV.

ZDI's review of Apple's September 2026 security updates catalogs dozens of CVEs across macOS, iOS, iPadOS, watchOS and other platforms. CVE-2026-65400 (CVSS 9.8) lets a network attacker authenticate to Screen Sharing Server without valid credentials and is flagged as KEV, while CVE-2026-65414 (CVSS 9.8) enables remote code execution via Bluetooth. The set also includes 8.8-rated memory corruption flaws in WebKit, WebRTC, CUPS, ImageIO and the kernel, plus sandbox escapes, privilege escalations to root, and arbitrary code execution via crafted files.

U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog

CISA added actively exploited flaws in Cisco ISE, Acronis Backup, and Google Pixel (CVE-2026-76460, CVE-2026-87886, CVE-2026-58704) to its KEV catalog.

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-76460 (CVSS 10.0), an unauthenticated API authentication bypass in Cisco Identity Services Engine that Cisco confirms is being actively exploited; CVE-2026-87886, a local privilege escalation in the Acronis Backup plugins for cPanel/WHM and Plesk exploited in limited targeted attacks; and CVE-2026-58704 (CVSS 8.8), a Google Pixel cellular modem permission bypass exploited in limited, targeted attacks and patched in the September 2026 Pixel update. Under BOD 22-01, federal agencies must remediate KEV entries by the stated due dates. Google has not attributed the Pixel exploitation to any actor.

Cisco patches max-severity ISE flaw, the second critical zero-day this week

Cisco emergency-patched actively exploited CVE-2026-76460 (CVSS 10.0), an unauthenticated API flaw granting root on ISE appliances; CISA added it to KEV.

Cisco patched CVE-2026-76460, a CVSS 10.0 authentication bypass in a Cisco Identity Services Engine management API that lets unauthenticated attackers gain root privileges. It affects ISE and ISE-PIC in all configurations and is fixed in 3.1 Patch 12 through 3.5 Patch 4. CISA added the flaw to its Known Exploited Vulnerabilities catalog after confirmed in-the-wild exploitation. A broader review fixed 21 critical ISE flaws plus high- and medium-severity issues, following earlier exploited firewall flaws CVE-2026-20079 and CVE-2026-20131.

CSO Online · 17h agoExploit / PoC in the wildCVE-2026-76460CVE-2026-20079CVE-2026-201312· 2 reads

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

Cisco Talos reports 90 ransomware incidents hit Japanese organizations in H1 2026, led by The Gentlemen, with Qilin using AI for efficiency.

Cisco Talos observed 90 ransomware incidents against Japanese organizations from January to July 2026, up about 4.7% year over year, with manufacturing accounting for 34% of victims. The Gentlemen was the most active group with 14 incidents; its leak-site listings grew from 48 in January to 105 in July. Qilin and SafePay followed with seven incidents each, and Talos notes Qilin is leveraging AI to improve operational efficiency.

Cisco Talosupdated · 6h agofirst · 1d agoRansomware in the wild 4 sources1

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

Unit 42 exposed CL-CRI-1171, a pay-per-install operation spreading OfferLoader and Insomnia RAT via YouTube and SEO poisoning to corporate and government targets.

The ThreatsDay bulletin leads with Unit 42's disclosure of CL-CRI-1171, a pay-per-install marketplace using YouTube channels and SEO-poisoning funnels to push trojanized software and the OfferLoader loader, which delivered Docro Hijacker, ARKTunnel and the cross-platform Insomnia RAT between July 2025 and April 2026. Oasis Security reported that 230 of 243 unauthenticated LocalAI instances were exploitable, with root command execution confirmed on 23 servers, theft of 127 AWS credential records, and exfiltration from a Thai military workstation. The roundup also covers Irregular's research on agentic self-modification, an AEPD-notified breach executed with an AI agent, CISA's warning that ransomware gangs exploit VMware vCenter CVE-2026-59310, and Oracle's September 2026 CPU fixing over 800 flaws.

The Hacker News · 20h agoThreat actor in the wildCVE-2026-59310

Top 10 Best Cloud Encryption Solutions in 2026

A 2026 buyer's guide reviews ten cloud encryption and key management platforms, spanning hyperscaler-native KMS and dedicated multicloud sovereignty solutions.

The roundup compares AWS KMS, Azure Key Vault, Google Cloud KMS, Thales CipherTrust, Fortanix, HashiCorp Vault, and Entrust. It highlights BYOK/HYOK, external key managers such as Google Cloud EKM, HSM integration, and confidential computing as differentiators for regulated multicloud estates. Pricing models span usage-based native KMS and enterprise quotes for dedicated KMS/HSM platforms.

Cyber Security News · 6h agoTools

16-31 August 2026 Cyber Attacks Timeline Infographic

Hackmageddon mapped 110 confirmed cyber incidents from August 16-31, 2026, with cybercrime driving 78.2% and malware the top technique.

The biweekly timeline aggregates 110 confirmed incidents across 64 countries, with 86 attributed to cybercrime, 16 to espionage and 4 to hacktivism. Exploitation of public-facing applications (T1190) was the leading initial access vector with 33 incidents, followed by spearphishing attachments with 13. The United States was the most targeted country with 38 incidents, and information and communication was the top sector with 29.

Hackmageddon · 1d agoResearch 2 sources

Mitsubishi Electric GX Works3 and Motion Control Settings

CISA warns CVE-2026-15688 lets a local attacker bypass block password authentication in Mitsubishi Electric GX Works3 and tamper with control programs.

CISA republished Mitsubishi Electric advisory 2026-007 describing CVE-2026-15688, an incorrect implementation of the authentication algorithm (CWE-303) in GX Works3 and the bundled Motion Control Settings, affecting all versions. A local attacker can authenticate with an invalid block password, modify an executable module in memory, and view, tamper with, destroy, or delete control programs. CVSS v3.1 base score is 8.8 (v4.0: 9.2), and CISA recommends isolating control system networks and minimizing internet exposure.

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

CISA and NIST published NIST IR 8587, final guidance for protecting identity tokens from forgery, theft, replay, and signing-key compromise.

NIST Interagency Report 8587 (September 15, 2026) expands the IA-13 'Identity Providers and Authorization Servers' control from NIST SP 800-53 R5.1.1, guiding federal agencies and cloud providers on SSO, identity federation, and machine-to-machine authentication. It requires hardware-backed signing-key storage for moderate-impact systems, 90-day key rotation for high-impact systems, token lifetimes under one hour, and sender-constrained mechanisms such as mutual TLS and DPoP. The report cites incidents including forged SAML assertions that exposed over 60,000 emails from a federal agency. It also extends guidance to agentic AI systems using signed tokens and urges post-quantum cryptography migration planning.

Cyber Security News · 2d agoAdvisory1

CISA and NIST Issue Guidance to Protect Cloud Identity Tokens

CISA and NIST published Interagency Report 8587 with voluntary guidance to harden cloud identity tokens against theft, forgery, and lateral movement.

CISA and NIST released NIST Interagency Report 8587 on September 15 with final voluntary guidance for federal agencies, cloud providers, and their customers on protecting SSO, federation, and API tokens. Requirements include one-hour maximum token lifetimes, 90-day signing key rotation for high-impact systems, hardware-backed key storage, explicit audience fields, and keeping tokens out of logs. The guidance was motivated by the 2020 ADFS compromise where forged SAML assertions bypassed MFA, and an incident where a leaked consumer signing key enabled token forgery and theft of 60,000+ emails from one agency. Nearly 250 public comments shaped the text, with input from Google, Microsoft, Okta, AWS, Oracle, IBM, HashiCorp, Wiz, and the OpenID Foundation via the Joint Cyber Defense Collaborative.

Infosecurity Magazine · 2d agoAdvisory

Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability

Cisco patched a BroadWorks CommPilot authorization bypass letting low-privileged authenticated users alter device configurations via crafted HTTP requests.

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software is caused by missing authorization checks. An authenticated remote attacker with low privileges can send crafted HTTP requests to alter configurations on select pages. Cisco has released software updates and no workarounds are available.

Cisco Security Advisories · 1d agoAdvisory

CVE-2026-79993: Apache ZooKeeper: Missing ACL check on deleteContainer opcode allows unauthorized deletion of any empty persistent/container znode

Critical ZooKeeper flaw lets any authenticated client delete arbitrary empty persistent or container znodes by bypassing ACL checks.

CVE-2026-79993 (critical severity) affects Apache ZooKeeper 3.9.0-3.9.5 and 3.8.0-3.8.6. The deleteContainer opcode (0x14/20) is processed without verifying the caller's ACL permissions, allowing any authenticated client to delete specific empty znodes in the data tree regardless of ACL restrictions on the znode or its parent. This can corrupt coordination state for dependent distributed systems like Kafka, HBase, or Solr clusters relying on ZooKeeper.

oss-security · 2d agoVulnerabilityCVE-2026-79993

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

Two unauthenticated CVSS 9.8 code-injection and PHP object injection flaws in The Events Calendar plugin expose 200,000+ WordPress sites to RCE and takeover.

Defiant identified two critical vulnerabilities in The Events Calendar WordPress plugin, which has over 600,000 active installations. CVE-2026-78159, unauthenticated code injection during single-event HTML processing, was patched in version 6.17.3.1 on August 25; CVE-2026-78006, unauthenticated PHP object injection via event comments, was patched in 6.17.4.1 on September 10. Both independent chains lead to remote code execution and full site compromise. Roughly 240,000 sites run versions vulnerable to both flaws, and about 300,000 downloads between September 10 and 14 suggest half of installations may still lack the second fix.

1Password's AI patching benchmark is misleading

Trail of Bits reanalysis says 1Password's 26% AI clean-fix rate is misleading; 86% of eligible patches blocked exploits.

Trail of Bits critiques 1Password's FLAWED AI patching benchmark, arguing its 26% clean-fix headline mixes trials where agents were instructed to apply wrong fixes (22% of data) with trials that prohibited compiling or testing (36%). Restricting to reasonable conditions, 2,634 of 3,067 patches (86%) blocked the supplied exploit. Trail of Bits also reports 12.5% of 2,265 developer first fixes failed in its own 2024-2026 assessments, and released post-patch-validation and review-walkthrough agent skills.

Lobsters · security · 2d agoResearch1

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory

CISA and five international agencies publish joint guidance detailing 17 techniques attackers use to compromise Microsoft Active Directory environments.

CISA, NSA, and the Australian Signals Directorate's ACSC, with contributions from Canadian, UK, and New Zealand cyber centers, released technical guidance on 17 Active Directory attack techniques. It covers AD Domain Services, AD Certificate Services, and AD Federation Services, including Kerberoasting, DCSync, Golden Ticket, Golden SAML, Skeleton Key, and Shadow Credentials. The guidance recommends treating domain controllers, CAs, AD FS servers, and Entra Connect systems as Tier 0 assets with phishing-resistant MFA, Kerberos pre-authentication enforcement, and disabling NTLM/SMBv1.

Cyber Security News · 2d agoAdvisory

Hackers Allegedly Selling Fortinet FortiGate 1-Day Vulnerability on Underground Forums

An unverified underground listing offers a claimed FortiGate SSL VPN RCE exploit for FortiOS 7.2.x/7.4.x amid ongoing exploitation of known Fortinet flaws.

Dark Web Intelligence shared an advertisement for a private '1-day' remote code execution exploit targeting FortiGate SSL VPN appliances on FortiOS 7.2.x and 7.4.x, with a claimed proof-of-concept video but no CVE, firmware builds, or technical details. The listing coincides with confirmed in-the-wild exploitation of CVE-2025-25249, an unauthenticated heap-based buffer overflow patched in January 2026 but exploited since July 2026, and CVE-2024-21762, a critical out-of-bounds write in the FortiOS and FortiProxy SSL VPN component. Fortinet has advised disabling SSL VPN where immediate upgrades are not possible.

GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds

eSentire identified GhostCode, a phishing kit abusing Microsoft 365 OAuth device-code sign-in to steal tokens and take over accounts in seconds.

eSentire analysts identified GhostCode in late August, a phishing kit that uses business contact-form messages and an NDA pretext to deliver a password-protected HTML attachment leading victims to a Microsoft device-code sign-in. Victims authenticate on legitimate Microsoft pages, letting the kit obtain a Primary Refresh Token in 32 seconds and register three devices in 78 seconds, with residential proxies matching the victim's location. The kit hides its redirect with encrypted addresses, junk data, and scanner-filtering challenges, and uses GHOSTnet-linked infrastructure during device enrolment. eSentire recommends blocking device-code authentication via Conditional Access, invalidating tokens, and reviewing newly enrolled devices.

Cyber Security News · 1d agoPhishing & fraud in the wild 2 sources5

WordPress Urges Immediate Update After Fixing 11 Security Vulnerabilities

WordPress 7.1.1 fixes 11 core vulnerabilities including stored XSS, path traversal, and authorization bypass flaws; admins urged to update immediately.

WordPress released version 7.1.1, a security and maintenance update fixing 11 vulnerabilities including multiple stored XSS flaws, an authenticated path traversal in the WP REST Templates Controller reported by Anthropic, missing authorization checks, and an XML-RPC issue bypassing edit_css checks. The release also includes 17 core bug fixes and 19 Block Editor fixes, with security fixes backported to supported branches through 4.7. No exploitation is reported; administrators are urged to update immediately or rely on automatic background updates.

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple's coordinated rollout patches 273 unique vulnerabilities across iOS 27, macOS Golden Gate 27, watchOS and Safari, including remote code execution flaws.

Apple shipped one of its largest coordinated security updates on September 14, 2026, fixing 273 unique CVEs across iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27 and Xcode 27. Highlights include CVE-2026-65414, a Bluetooth out-of-bounds write enabling remote code execution, and CVE-2026-84607, an AVEVideoEncoder race condition granting kernel privileges to sandboxed apps. macOS Golden Gate 27 covers the broadest set with 210 CVEs, and Apple states none of the flaws were exploited in the wild.

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Attackers exploit CVE-2026-27540 in WooCommerce Wholesale Lead Capture to upload PHP web shells; Wordfence blocked 100,000+ attempts since June 2026.

Wordfence reports active exploitation of CVE-2026-27540 (CVSS 9.8), an unauthenticated arbitrary file upload in the wwlc_file_upload_handler AJAX action of the WooCommerce Wholesale Lead Capture plugin (versions through 2.0.3.1, 6,000+ installs), enabling remote code execution via uploaded PHP web shells. Over 100,000 exploit attempts were blocked since June 2026, including 99 in the last 24 hours, traced to ten listed IP addresses. Separately, two critical flaws (CVE-2026-78159 and CVE-2026-78006) in The Events Calendar, installed on 600,000+ sites, allow unauthenticated RCE and full site takeover via PHP object injection chains. StellarWP patched the affected plugin versions 6.17.3 and 6.17.4 in releases 6.17.3.1 and 6.17.4.1.

The Hacker Newsupdated · 2h agofirst · 2d agoExploit / PoC in the wild 9 sourcesCVE-2026-27540CVE-2026-78159CVE-2026-78006

Hackers Impersonate ChatGPT Subscription Alerts to Steal OpenAI Account Credentials

Cofense reports a phishing campaign using fake ChatGPT subscription payment notices to lure users to credential-harvesting pages and steal OpenAI account logins.

Cofense identified phishing emails impersonating ChatGPT subscription invoices, using the genuine logo, 'Subscription Payment Required' wording, and a 48-hour urgency deadline. Links route through a Google notifications API redirect wrapper to attacker-controlled nxcli[.]io infrastructure hosting a fake ChatGPT login page that forwards submitted credentials to the attackers before showing an error. Cofense published IOCs including sender support@9527db6e1a[.]nxcli[.]io and two stage-2 payload URLs; the operators behind the campaign were not named.

Cyber Security News · 1h agoPhishing & fraud in the wild

Apache Syncope Vulnerabilities Allow Attackers to Execute Malicious Code and Bypass Controls

Apache Syncope fixed three flaws enabling SQL injection, Groovy sandbox escape, and JWT token theft to impersonate higher-privileged users.

Apache Syncope, an open-source identity management and access governance platform, disclosed CVE-2026-82232, a stacked-query SQL injection in the Task search sort parameter; CVE-2026-77147, a Groovy sandbox escape via malicious Command classes; and CVE-2026-73178, retrieval of signed JWT access tokens via REST enabling impersonation of more privileged users. All three flaws require administrator-level entitlements to exploit and affect Syncope 3.0, 4.0, and 4.1 releases. Fixes shipped in versions 4.0.8 and 4.1.3, with researchers Alon Galili and n0mi1k credited.

Iranian Hackers Use Fake MRI Results to Infect Victims With CHOSEN BRICK Spyware

Iranian state-linked hackers deliver CHOSEN BRICK Windows spyware via fake MRI results to surveil dissidents, activists, and journalists in the UK, US, and Netherlands.

A joint advisory from the UK NCSC, FBI, and the Netherlands' AIVD links Iranian state-linked actors to CHOSEN BRICK, a Windows spyware family used for long-term surveillance since at least 2025. Targets are approached on WhatsApp or Telegram with tailored lures such as fake MRI scan results or application files, and operators often redirect victims to personal devices to bypass corporate controls. The malware persists via Run registry keys, adds antivirus exclusions, uses a per-victim Telegram bot for command and control, and exfiltrates data through cloud storage and proxy services. Capabilities include screenshots, audio recording, email and messaging theft, command execution, file deletion, data wiping, and some victims' details have appeared on pro-Iranian leak sites for harassment.

Cyber Security Newsupdated · 1d agofirst · 2d agoThreat actor in the wild 10 sources1

Steam Windows 0-Day Vulnerability Allows Users to Silently Escalate to Full SYSTEM Privileges

A public BrokenPipe PoC exploits a signature-coverage flaw in Steam's Windows service, letting unprivileged local users gain NT AUTHORITY\SYSTEM without a patch or CVE.

Researcher KillaBoi published the BrokenPipe PowerShell proof of concept on September 14, 2026, targeting steamservice.exe, Steam's privileged Windows client service. The flaw is a signature-coverage gap: the service accepts a caller-controlled installation root alongside a genuine Valve-signed install-script VDF, causing the SYSTEM-level service to execute a relocated attacker-chosen launcher. Testing reportedly succeeded on Steam 10.96.30.42 on recent 64-bit Windows 10 and Windows 11 builds, returning whoami output of NT AUTHORITY\SYSTEM (S-1-5-18). Valve was reportedly aware since March 2026, the HackerOne submission was marked duplicate, and no CVE, advisory, or fix exists at publication time.

Cyber Security Newsupdated · 9h agofirst · 10h agoVulnerability 2 sources

New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data

Zimperium details RatHat, a new Android banking trojan using a generative AI engine to automate credential and OTP theft.

Zimperium's zLabs identified RatHat, an Android malware delivered as fake APKs via malvertising, smishing and third-party forums, and published its analysis on September 16. Its three-part architecture combines a malicious app, a Go agent (liblocal-service.so) running privileged commands through the ADB shell, and an FRP client (libmedia_codec.so) maintaining a reverse tunnel to the C2. The app harvests banking credentials, notifications, 2FA codes and OTPs and captures screens and inputs, while a dropper abuses SessionInstaller APIs to bypass Android's restricted settings behind four anti-analysis and one anti-debug layers. Notably, RatHat serializes the Accessibility tree to XML and queries a generative AI assistant, likely Google's Gemini, in Mandarin to resolve click coordinates and navigation commands.

Infosecurity Magazineupdated · 4h agofirst · 1d agoMalware in the wild 6 sources

CISA Warns Hackers Exploit 17 Active Directory Techniques to Gain Control of Enterprise Networks

CISA and Five Eyes agencies issued joint guidance detailing 17 Active Directory attack techniques like Kerberoasting and DCSync, with hardening and detection advice.

CISA, the NSA, and cyber agencies from Australia, Canada, the UK, and New Zealand released joint guidance on September 15 covering 17 techniques attackers use to compromise Active Directory, including AD CS, Certificate Services, and Federation Services attacks. Named techniques include Kerberoasting, AS-REP roasting, password spraying, DCSync, NTDS.dit dumping, Golden and Silver Tickets, Golden SAML, and Skeleton Key. Recommendations include minimizing SPN accounts, enforcing AES encryption, disabling NTLM, account lockout thresholds of five attempts, phishing-resistant MFA, and Tier 0 prioritization. The guide also lists Windows event IDs 4769, 4768, 4625, 4771, and 2889 for detecting Kerberoasting and password spraying on domain controllers.

GBHackers · 2d agoAdvisory

Apple Releases iOS 27 Security Update to Fix Over 120 Vulnerabilities

Apple released iOS 27 and iPadOS 27 patching roughly 126 vulnerabilities across kernel, WebKit, sandboxing, and authentication components; no active exploitation reported.

Apple released iOS 27 and iPadOS 27 on September 14, 2026, fixing approximately 126 vulnerabilities across more than 90 components, including the kernel, WebKit, AppleKeyStore, Sandbox, and TCC. Flaws include memory corruption, information disclosure, denial-of-service, logic errors, sandbox escapes enabling root privileges, and a Bluetooth issue permitting remote code execution in specific circumstances. Apple also shipped iOS 26.7 and iPadOS 26.7 with over 80 fixes for users delaying the major upgrade, including 75 vulnerabilities shared with iOS 27. No vulnerabilities were reported as actively exploited at release time.

GBHackers · 2d agoAdvisory

CISA Urges Organizations to Deploy Cyber Decoys to Detect Hackers Inside Networks

CISA's new guidance urges organizations to deploy cyber decoys like honeytokens and tripwires to detect attackers using valid credentials and living-off-the-land techniques.

CISA published 'Using Cyber Decoys to Strengthen Detection and Response' on September 16, 2026, advising decoy assets that appear legitimate but generate high-confidence alerts when accessed. It describes tripwires, breadcrumbs, and honeytokens such as fake usernames, passwords, API keys, and cloud access tokens, and recommends starting with low-complexity deployments like nonfunctional Active Directory accounts, decoy file shares, and isolated mimic hosts. The agency warns decoys must be segmented and nonfunctional to prevent attackers pivoting to real systems, and aligns decoy planning with MITRE Engage and ATT&CK.

GBHackers · 1d agoAdvisory