Tag: access
-
15 TP-Link Omada Flaws Exploit Zero-Touch Provisioning to Hijack Devices and Infiltrate Networks
Security researchers have disclosed 15 vulnerabilities in TP-Link’s Omada zero-touch provisioning (ZTP) ecosystem, which can be exploited to hijack devices, compromise controllers, expose credentials, and create access points into internal networks. The research, titled >>Zero Day Provisioning,<< was presented at Black Hat USA 2026 and focuses on weaknesses in the trust relationships that enable Omada…
-
ScreenConnect Attackers Hide Windows, Delete Installers and Masquerade as Software Updates
ScreenConnect is being systematically weaponized in the SMOKE#SCREEN campaign, where attackers hide execution windows, delete installers, and disguise malicious activity as routine software updates to plant fully functional, signed ScreenConnect agents across Windows and macOS endpoints. The result is persistent, “legitimate-looking” remote access that blends into normal IT operations while silently bypassing user awareness and…
-
Bank of America impersonators weaponize ScreenConnect, then make it hard to remove
A phishing campaign impersonating Bank of America (BoA) is underway, trying to trick Windows users into installing ScreenConnect remote access software and then making it … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/05/fake-bank-of-america-email-account-guard/
-
Kali365 Exploits Microsoft Device Login to Access US Corporate Data
Learn how Kali365 has been abusing Microsoft device login to gain OAuth tokens, targeting US firms, and how SOC teams can detect, hunt, and stop these phishing attacks. First seen on hackread.com Jump to article: hackread.com/kali365-exploit-microsoft-device-login-access-us-data/
-
Fake Bank of America Phishing Scam Installs Remote Access Malware
Cybercriminals are using a fake Bank of America phishing campaign to trick users into downloading a malicious script that installs ScreenConnect, enabling remote access and persistence on compromised systems First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fake-bank-of-america-phishing-scam/
-
Polish convenience store chain Żabka hacked through third-party account
Reports said intruders appeared to gain access to the Jira environment and other sensitive data of the Żabka retail chain. The company confirmed an intrusion occurred in late July. First seen on therecord.media Jump to article: therecord.media/poland-convenience-store-chain-zabka-cyberattack
-
Why Non-Human Identities Break Legacy Access Models
Keeper Security’s Darren Guccione on Governing Agentic Identity. Non-human identities now outnumber humans across the enterprise, but legacy access tools built for people can’t track or govern them. Darren Guccione of Keeper Security says boards must fund identity governance for agentic AI and quantum-resistant encryption on the sidelines of Black Hat 2026. First seen on…
-
Salt Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection
Tags: access, ai, api, attack, ceo, credentials, detection, email, endpoint, exploit, intelligence, marketplace, threat, waf, xssThe WAF gap no one is talking about Your WAF is doing its job. It’s blocking SQLi, XSS, and the usual suspects. But here’s the problem: it wasn’t built for APIs, and it definitely wasn’t built for AI agents. APIs now power nearly every digital experience. And AI agents, the automated systems that access your…
-
INC Ransomware is Calling Victims Pressure Tactics Post SonicWall Zero-Day Exploit
INC Ransomware exploits SonicWall SMA 1000 flaws, using calls and emails to pressure victims during extortion campaigns targeting global organizations. Resecurity disclosed that INC Ransomware has emerged as the dominant threat actor exploiting the recently disclosed SonicWall Secure Mobile Access (SMA) 1000 vulnerabilities. According to the company’s research, the group has accelerated its operations since…
-
Varonis Agent IBAC keeps AI agents within their intended boundaries
AI agents need broad access to be useful, but traditional access controls cannot determine whether an action aligns with a user’s intent. Varonis explains how Agent IBAC detects intent drift and enforces real-time guardrails to keep agents within their intended boundaries. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/varonis-agent-ibac-keeps-ai-agents-within-their-intended-boundaries/
-
Automated Access Governance: From Review Completion to Risk Closure
Ask an IAM or compliance team how many segregation of duties conflicts appeared in its last access review. Then ask how many had already appeared in the review before that. If the answer is “most of them,” the organisation does not have a review-frequency problem. It has a risk-closure problem. Access reviews can be completed……
-
Apple launches new legal challenge against UK over iCloud access
Seeking to protect users’ iCloud accounts, Apple is reportedly mounting a new challenge to British legal demands for ways around the company’s Advanced Data Protection feature. First seen on therecord.media Jump to article: therecord.media/apple-uk-tcn-icloud-new-legal-challenge
-
CVE-2026-58048: cPanel Bug Enables Full Database Administrator Access
A critical cPanel flaw (CVE-2026-58048) lets authenticated users execute SQL as root. Users should update to fixed versions immediately. If you run a shared hosting box, this one’s worth reading before your morning coffee gets cold. cPanel just patched a flaw, tracked as CVE-2026-58048 (CVSS score of 9.4), that let an ordinary authenticated hosting customer,…
-
Fake Bank of America Phishing Emails Found Delivering Disguised ScreenConnect RAT via UAC Bypass
Researchers at Huntress have identified an active phishing campaign impersonating Bank of America that culminates in the covert installation of a remote monitoring and management (RMM) tool, giving attackers persistent, hard-to-detect access to victims’ Windows machines. The campaign was flagged after a message landed in one of Huntress’s spamtrap accounts on 28 July, sent from…
-
Fake Xeno Roblox Cheats Deliver Java RAT That Steals Discord and Gaming Accounts
Fake Roblox cheat tools are once again being weaponized, with a newly observed campaign distributing a sophisticated Java-based remote access trojan (RAT) disguised as an “undetected” version of the popular Xeno script executor. Security researchers warn that the operation specifically targets gamers through Discord communities and underground forums, leveraging trust in widely used cheat utilities…
-
Escape joins Anthropic’s Cyber Verification Program to advance AI-powered offensive security
Good news doesn’t arrive alone. This month we joined not one frontier AI program but two! Yesterday we shared that Escape joined OpenAI’s Trusted Access for Cyber. Today we’re a verified member of Anthropic’s Cyber Verification Program. Both programs solve the same First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/escape-joins-anthropics-cyber-verification-program-to-advance-ai-powered-offensive-security/
-
Russian Access Broker Sells Network Access to Ransomware Gangs While Spying on Ukraine
Tags: access, cyber, data-breach, defense, exploit, intelligence, network, ransomware, russia, ukraineAn exposed server linked to a Russian”‘speaking initial access broker (IAB) has revealed a sprawling operation that simultaneously fuels ransomware intrusions worldwide and supports Russian state-aligned intelligence collection against Ukrainian defense and aerospace targets. The artefacts show a mature, high”‘volume access brokerage pipeline that industrialises exploitation of internet”‘facing appliances, pivots to full Active Directory compromise,…
-
Barracuda Networks Shows How AI Agents Can Compromise Business Email
Barracuda Networks shows how attackers could hijack Microsoft Copilot to access sensitive emails, impersonate executives and execute convincing business email compromise attacks. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/barracuda-networks-shows-how-ai-agents-can-compromise-business-email/
-
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims’ browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.”The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes the…
-
cPanel Database Privilege Escalation Flaw Enables Full Administrative Access
CVE-2026-58048 is a critical privilege-escalation vulnerability in the database management functionality of cPanel & WHM. This flaw allows an authenticated cPanel user to execute arbitrary database commands with full administrative privileges. cPanel Database Privilege Escalation Flaw All supported versions of cPanel & WHM before the recently released security updates are affected. As WebPros states, an…
-
Apple files fresh claim against Home Office move to access encrypted cloud data
Apple files fresh legal complaint over secret Home Office order to require it to provide access to encrypted iCloud data stored by UK customers First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366647012/Apple-files-fresh-claim-against-Home-Office-move-to-access-encrypted-cloud-data
-
New DOUBLECUP ClickFix service hides malware in browser cache images
A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named DeviceManager to Windows systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hides-malware-in-browser-cache-images/
-
Fake Roblox Xeno script launcher pushes infostealer, RAT malware
Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fake-roblox-xeno-script-launcher-pushes-infostealer-rat-malware/
-
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users
Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments.One of the packages in question is “lib-mtop,” an unscoped package with the same name as a private…
-
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws
The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances.In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data…
-
âš¡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended.Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned…

