ZeroHour

Search: “manipulation”

5 stories in the last 24h

CVE-2026-87976: Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension Bundles

Apache NiFi Registry 0.4.0-2.11.0 allows path manipulation when storing extension bundle content from uploaded NAR manifests (CVE-2026-87976, High).

Apache NiFi Registry versions 0.4.0 through 2.11.0 are affected by improper limitation of a pathname (CVE-2026-87976), rated High severity by the maintainers. When storing extension bundle content, the default file persistence provider used group, artifact, and version coordinates from uploaded NAR manifests as filesystem path components without sufficient validation. The disclosure was posted by Apache NiFi maintainer David Handermann on the oss-security mailing list.

Jenkins Patches 20 Plugin Flaws Leading to RCE, XSS and Credential Theftnew

Jenkins patched 20 vulnerabilities across 13 plugins, including Groovy sandbox bypasses enabling remote code execution on CI/CD controllers.

Jenkins released security updates on September 16, 2026 for 20 vulnerabilities across 13 plugins, including nine fixes in the Script Security Plugin for Groovy sandbox bypasses. CVE-2026-92127 (classpath abuse) and CVE-2026-92128 (TOCTOU race on remote JAR loading) could allow arbitrary code execution in the controller JVM, exposing build secrets, credentials, and downstream deployment environments. Other flaws include stored XSS in the Warnings, Coverage, OWASP Dependency-Check and Gitee plugins, SSRF in the Gradle and Bitbucket plugins enabling credential capture, credential exposure via CVE-2026-92130, arbitrary file write via CVE-2026-92137, OAuth token theft, and an open redirect in the Keycloak Authentication Plugin. No exploitation is reported; fixes include Script Security Plugin 1422.v06869826dd9b_.

NightEagle Hackers Target Russian Companies Using GhostContainer Backdoor

Kaspersky links NightEagle (APT-Q-95) intrusions in Russia to stolen VPN credentials, the GhostContainer Exchange backdoor, BlueKeep exploitation, and covert tunneling for espionage.

Kaspersky's Global Emergency Response Team attributes new intrusions against Russian companies to NightEagle (APT-Q-95), active since at least 2023 and previously focused on Asian organizations. The group uses valid VPN credentials, deploys the .NET-based GhostContainer backdoor on Microsoft Exchange servers, and tunnels RDP via Microsoft Dev Tunnels and rdp2tcp. In one incident operators exploited BlueKeep (CVE-2019-0708) to create an administrator account, and they performed DCSync replication against Active Directory to harvest domain password hashes. GhostContainer reuses code from Neo-reGeorg, ExchangeCmdPy.py (CVE-2020-0688), and ysoserial, and tampers with AMSI and Windows event logging to evade detection.

Parallels Desktop Vulnerability Lets Non-Admin Mac Users Execute Code as Root

JFrog researchers disclosed CVE-2026-90894, a critical Parallels Desktop local privilege escalation letting non-admin Mac users execute code as root; fixed in 27.0.0.

JFrog researchers found that Parallels Desktop's privileged prl_disp_service daemon on macOS accepts unsigned local clients through a world-writable socket and allows argument injection into a tar command during appliance installation. Injecting the --use-compress-program option makes tar execute an attacker-controlled program as root, and a one-line proof of concept yielded a root shell without needing a running virtual machine. The flaw, dubbed ParaShells, was confirmed in Parallels Desktop 26.4.0 build 57513 on Apple Silicon and is fixed in version 27.0.0. No exploitation in the wild has been reported; administrators should inventory and upgrade affected installations and restrict local account access.

Cyber Security Newsupdated · 17h agofirst · 21h agoVulnerability 4 sourcesCVE-2026-90894

Microsoft Releases Emergency Windows 11 Update Following Patch Tuesday Bugs

Microsoft issued emergency Windows 11 update KB5129195 to fix Patch Tuesday regressions and fully close the CVE-2026-62721 privilege escalation flaw.

Microsoft shipped out-of-band cumulative update KB5129195 for Windows 11 24H2 and 25H2 (builds 26100.9457 and 26200.9457) after the September 8 Patch Tuesday rollup, which addressed over 960 CVEs including two actively exploited flaws, broke Remote Desktop Services, Hyper-V Plan9 folder sharing, and USB audio. The emergency release also strengthens the incomplete fix for CVE-2026-62721, an elevation-of-privilege flaw in the Windows User-Mode Power Service that could let a local attacker gain SYSTEM privileges. Companion patches cover Windows 11 26H1, Windows 10, and Windows Server. Some USB Audio Class 1.0 and AMD Radeon graphics issues remain unresolved.

Cyber Security News · 23h agoVulnerability in the wildCVE-2026-627211