Tag: access
-
Sicherheitslücke in Adobe-Erweiterung ermöglichte Zugriff auf WhatsApp Web
Eine Schwachstelle in der Chrome-Erweiterung Adobe Acrobat ermöglichte den Zugriff auf Inhalte von WhatsApp Web. Adobe hat den Fehler behoben. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/whatsapp-web-adobe
-
Critical RefluXFS Linux Kernel Flaw Lets Local Attackers Gain Root Access
A critical vulnerability in the Linux kernel, identified as CVE-2026-64600 and referred to as RefluXFS. This vulnerability enables an unprivileged local user to gain root access on systems that utilize reflink-enabled XFS filesystems. The flaw resides in the XFS copy-on-write path and has reportedly existed since the release of Linux kernel version 4.1 in 2017.…
-
Ubuntu snap-confine vulnerability grants root access
First seen on scworld.com Jump to article: www.scworld.com/brief/ubuntu-snap-confine-vulnerability-grants-root-access
-
French Parliament greenlights social media ban for under-15s
Both houses of the French Parliament voted to block social media access for children under 15, making France the first European country to enact a ban amid a broadening global crackdown. First seen on therecord.media Jump to article: therecord.media/france-social-media-ban-parliament
-
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment.The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The disclosure comes as…
-
How enterprise GenAI can amplify ransomware risk, and how to contain it
Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/how-enterprise-genai-can-amplify-ransomware-risk-and-how-to-contain-it/
-
Adobe Chrome extension flaw let sites access private WhatsApp chats
The Adobe Acrobat extension for Chrome could be used to access conversations and data rendered in WhatsApp Web without any form of authentication. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-let-sites-access-private-whatsapp-chats/
-
New Ubuntu Desktop Vulnerability Turns Local Access Into Root Control
A vulnerability in snap-confine lets an unprivileged user gain root access on affected Ubuntu Desktop systems. Install the latest snapd update to fix the issue. First seen on hackread.com Jump to article: hackread.com/ubuntu-desktop-vulnerability-local-access-root-control/
-
Ubuntu snap-confine Vulnerability Enables Local Root Access
New Ubuntu snap-confine race condition lets local users escalate to root on default installs First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ubuntu-snap-confine-local-root-cve/
-
Xbox: Microsoft will Support für gehackte Konten verbessern
Laut einem Bericht arbeitet Microsoft an besseren Prozessen für gehackte Konten. Bislang konnten Betroffene dauerhaft den Zugriff verlieren. First seen on golem.de Jump to article: www.golem.de/news/xbox-microsoft-will-support-fuer-gehackte-konten-verbessern-2607-211149.html
-
North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs
North Korea’s Famous Chollima threat group, also tracked as Wagemole, is actively running a sophisticated cyberespionage campaign dubbed ClickFake Interview. The operation targets cryptocurrency and Web3 professionals, tricking candidates into executing terminal commands that infect their devices with platform-specific Remote Access Trojans (RATs): PylangGhost on Windows and GolangGhost on macOS. Detailed analysis by the SOCRadar…
-
Apple Faces Lawsuit Over Hide My Email Privacy Vulnerability
Apple is facing a proposed class-action lawsuit after Anthony Alvarez alleged that the company’s Hide My Email feature failed to protect users’ real email addresses as advertised. The complaint, filed in the U.S. District Court for the Northern District of California, claims Apple promoted Hide My Email as a privacy safeguard while continuing to charge customers for…
-
OpenAI Exploits Zero-Day to Gain Internet Access and Compromise Hugging Face Servers
OpenAI has revealed that during an internal evaluation of advanced cyber capabilities, AI agents exploited a zero-day vulnerability, escaped a constrained research environment, and compromised parts of Hugging Face’s production infrastructure. While Hugging Face detected and contained the activity, OpenAI’s internal security team also identified unusual behavior during the assessment. OpenAI Compromise Hugging Face Servers…
-
OpenAI Models Escaped Containment and Hacked Hugging Face
The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack. First seen on wired.com Jump to article: www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/
-
OpenAI Models Escaped Containment and Hacked HuggingFace
The cybersecurity-focused models, including GPT-5.6 Sol, broke out of a testing sandbox, exploited a zero-day, and gained access to the open internet to pull off the attack. First seen on wired.com Jump to article: www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/
-
Ubuntu-Sicherheitslücke CVE-2026-8933 ermöglicht lokalen Root-Zugriff über snap-confine
Auf diese Weise können beliebige Befehle mit Root-Rechten ausgeführt werden. Aus einem lokal angemeldeten Standardbenutzer wird damit ein vollständig privilegierter Systemadministrator. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/qualys-tru-ubuntu-sicherheitsluecke-cve-2026-8933-ermoeglicht-lokalen-root-zugriff-ueber-snap-confine/a45820/
-
Critical SharePoint RCE flaw exploited to steal machine keys
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-exploited-to-steal-machine-keys/
-
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
Google’s DeepMind on Tuesday announced the release of Gemini 3.5 Flash Cyber, a specialized artificial intelligence (AI) model built atop 3.5 Flash that’s designed to discover, validate, and patch vulnerabilities quickly and efficiently.According to the tech giant, the model will be exclusively available to governments and trusted partners via CodeMender as part of a limited-access…
-
Windows Privilege Escalation: SeRestorePrivilege
Overview SeRestorePrivilege is a Windows special privilege that allows its holder to restore files and directories, effectively bypassing discretionary access controls on the file system. First seen on hackingarticles.in Jump to article: www.hackingarticles.in/windows-privilege-escalation-serestoreprivilege/
-
KeeperPAM strengthens privileged access management for global construction SaaS provider Asite
Keeper Security has announced that UK-based construction technology provider Asite has deployed KeeperPAM® to strengthen privileged access management, secrets governance and credential security across its global operations. The deployment, detailed in a newly published customer case study, sees Asite replace a collection of legacy privileged access and secrets management tools with Keeper’s unified, cloud-native platform…
-
Closing the Identity Gaps in Critical Infrastructure Security
Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical systems. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/closing-the-identity-gaps-in-critical-infrastructure-security/
-
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and…
-
Microsoft Retires Copilot Podcasts and Removes Access to Previously Created Content
Microsoft has announced that it will retire the Podcasts feature in its consumer Copilot app on August 18, 2026. This decision will permanently remove the ability to generate new AI-created podcasts, as well as access to all previously created content. This change affects all Copilot customers, including both free users and paid subscribers, and raises…
-
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
A cloud tenant using nothing but ordinary GPU access can push a data center’s power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in.That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, the IACR’s hardware-security…
-
AsyncAPI Supply Chain Attack Deploys Miasma Backdoor Through Trusted npm Workflows
AsyncAPI’s npm ecosystem suffered a coordinated supply chain compromise on July 14, 2026, delivering a Miasma”‘associated Node.js backdoor through trusted GitHub Actionsdriven release workflows and exposing high”‘value developer and CI/CD environments to remote access, credential theft, and further lateral movement. Malicious versions were shipped for @asyncapi/generator@3.3.1, @asyncapi/generator-helpers@1.1.1, @asyncapi/generator-components@0.7.1, and @asyncapi/specs@6.11.2 and 6.11.2-alpha.1, together accounting for…
-
Hackers Exploit SonicWall SMA Zero-Days to Gain Root Access and Deploy ORANGETAIL Webshell
An ongoing exploitation of two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) devices. These vulnerabilities allowed a threat actor, identified as UTA0533, to gain root-level access, install persistent malware, and deploy the ORANGETAIL Java webshell on vulnerable VPN appliances. The affected SonicWall SMA models include the 1000 series, specifically models 6210, 7210, and 8200.…

