Tag: authentication
-
ServiceService Authentication: Patterns for Securing API and Microservices
First seen on scworld.com Jump to article: www.scworld.com/tech-explainer/service-to-service-authentication-patterns-for-securing-api-and-microservice
-
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain requires…
-
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Tags: authentication, data, data-breach, endpoint, exploit, extortion, flaw, Internet, login, ransomware, rce, remote-code-execution, threatThreat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.”Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling…
-
Apache Syncope Flaws Let Users Gain Admin Roles and Execute Remote Code
Tags: apache, authentication, cve, cyber, flaw, injection, remote-code-execution, service, sql, vulnerabilityApache Syncope has released versions 4.1.24.1, 4.1.24.1.2, and 4.0.74.0.7 to address six security vulnerabilities affecting the 4.1, 4.0, and 3.0 release branches. These vulnerabilities include a self-service privilege escalation bug, multiple post-authentication remote code execution (RCE) pathways, authenticated server-side request forgery (SSRF), and SQL injection issues. Apache Syncope Flaws CVE-2026-62183 affects deployments that utilize the…
-
Next.js Patches Nine Security Flaws Enabling SSRF, Middleware Bypass, DoS, and Internal Endpoint Disclosure
The Next.js team has released security updates that address nine vulnerabilities affecting the App Router, Server Actions, rewrites, image optimization, caching, and middleware deployments. Organizations are urged to upgrade to Next.js versions 15.5.21 or 16.2.11 immediately, as these updates fix high- and moderate-severity flaws that could lead to server-side request forgery (SSRF), authentication bypass, denial…
-
Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)
Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/23/check-point-vulnerability-cve-2026-16232/
-
Check Point patches actively exploited SmartConsole authentication bypass flaw
Check Point addressed a critical authentication bypass flaw, tracked as CVE-2026-16232, in SmartConsole that is being actively exploited. Check Point has released security updates to fix multiple vulnerabilities, including CVE-2026-16232 (CVSS score of 9.3), a critical authentication bypass flaw affecting Security Management and Multi-Domain Management (MDSM). The vulnerability, which is under active exploitation, allows unauthenticated…
-
Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access
Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation in the wild.The security flaw, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass affecting the Check Point SmartConsole login process that allows an First seen…
-
OneSpan launches unified platform for financial institution authentication
First seen on scworld.com Jump to article: www.scworld.com/brief/onespan-launches-unified-platform-for-financial-institution-authentication
-
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”).”The filename parameter is concatenated into First seen on thehackernews.com Jump to article: thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html
-
Hackers Clone Microsoft Login Portals to Capture Credentials and Session Tokens in Real Time
An active adversary-in-the-middle (AiTM) phishing campaign that clones Microsoft authentication pages to intercept credentials, Multi-Factor Authentication (MFA) codes, and session tokens in real time. Rather than relying on simple password harvesting, this technique hijacks authenticated user sessions directly. Detailed by Infoblox Threat Intel researchers Darby Wise and Nick Sundvall, the widespread campaign has targeted universities,…
-
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and…
-
Hackers Exploit ServiceNow AI Platform Flaw to Gain Unauthenticated Remote Code Execution
Tags: advisory, ai, authentication, cve, cyber, exploit, flaw, hacker, remote-code-execution, threat, vulnerabilityThreat actors are actively exploiting CVE-2026-6875, a critical pre-authentication remote code execution vulnerability in the ServiceNow AI Platform. This vulnerability allows attackers to escape a restricted server-side script sandbox and execute code without valid credentials. Reports from Defused indicate observed exploitation activity targeting this flaw. Initially, ServiceNow’s advisory stated it was not aware of any…
-
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims’ networks, according to cybersecurity company Arctic Wolf. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks/
-
Attackers Exploit Critical ServiceNow RCE Flaw CVE-2026-6875
Attackers are exploiting critical ServiceNow flaw CVE-2026-6875, allowing unauthenticated remote code execution on self-hosted instances. Searchlight Cyber researchers disclosed a critical pre-authentication remote code execution vulnerability, tracked as CVE-2026-6875, in the ServiceNow AI Platform on July 14. The same day, ServiceNow released patches for self-hosted instances. Since July 17, attackers have started exploiting it in…
-
Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware
Tags: access, attack, authentication, corporate, cve, cyber, encryption, exploit, flaw, hacker, network, ransomware, vpn, vulnerabilityHackers are exploiting a high-severity vulnerability in Palo Alto Networks’ PAN-OS to gain initial access to corporate networks and deploy Qilin ransomware. Multiple intrusions investigated in June 2026 began with the exploitation of CVE-2026-0257, an authentication bypass flaw affecting GlobalProtect portal and gateway deployments. The attacks evolved from external VPN compromises to domain-wide encryption, with…
-
ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
Tags: ai, authentication, cve, exploit, intelligence, rce, remote-code-execution, threat, vulnerabilityAttackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/servicenow-cve-2026-6875-exploited/
-
Salt Security tackles AI governance challenge with 100 pre-built agentic security policies
Salt Security has expanded its Policy Hub to include 100 pre-built security policies, as organisations look for practical ways to govern AI agents across enterprise environments. The company says the milestone creates one of the industry’s largest libraries of governance policies for agentic AI, covering APIs, Model Context Protocol (MCP) servers, authentication, access controls, compliance…
-
GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE
Tags: authentication, cyber, exploit, flaw, injection, rce, remote-code-execution, sql, vulnerability, wordpressA critical vulnerability chain in WordPress, called wp2shell, that allegedly allows unauthenticated attackers to exploit a pre-authentication SQL injection flaw to achieve remote code execution (RCE) on typical WordPress installations running MySQL. Security researcher Adam Kues discovered this vulnerability chain using GPT-5.6 Sol Ultra during a multi-agent audit of the WordPress source code. GPT-5.6 Sol…
-
Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits
Public exploits are now available for two critical WordPress flaws that attackers can chain to gain remote code execution without authentication. Public proof-of-concept exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core. The flaws, tracked as CVE-2026-63030 and CVE-2026-60137, can be chained to achieve pre-authentication remote code execution on default WordPress installations…
-
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/
-
Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution
A newly disclosed a pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed >>wp2shell,<< that requires no authentication and affects stock WordPress installations with zero plugins installed. Given that WordPress powers an estimated 500 million websites globally. The flaw represents one of the most significant CMS security disclosures in recent memory. The issue stems…
-
Claude can now sign into websites with 1Password without exposing your credentials
1Password has introduced 1Password for Claude, a beta integration that lets Anthropic’s AI assistant complete browser tasks requiring authentication without accessing … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/17/1password-anthropic-claude-integration/
-
Critical Notepad++ Bugs Could Lead to Code Execution, Patch Available
The latest Notepad++ vulnerabilities addressed in version 8.9.7 include several high-impact security flaws that could expose Windows systems to arbitrary code execution, file overwrite attacks, memory corruption, and authentication bypass. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/notepad-vulnerabilities-v897/
-
Phishing Toolkits Harvest Entra Tokens in Real Time
Jalisco Device Code Phishing Tool Use Also Tied to EvilTokens and Kali365 Customers. Sophisticated phishing-as-a-service toolkits are driving a surge in phishing attack volume, experts warn, by giving users highly automated tools for personalizing lures and accessing previously niche tactics for generating valid authentication tokens for persistent access. First seen on govinfosecurity.com Jump to article:…
-
Microsoft Entra ID gets passkeys default authentication starting September
Microsoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-entra-id-gets-passkeys-default-authentication-starting-september/
-
New phishing kits target Microsoft 365 accounts, evade MFA
Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-phishing-kits-target-microsoft-365-accounts-evade-mfa/
-
Attackers Distribute Password Attacks Across Fictional OAuth Apps to Evade SOC Alerts
Attackers are increasingly abusing spoofed OAuth application identifiers to enumerate Microsoft Entra ID accounts, test credentials, and fragment authentication activity across hundreds of thousands or millions of fictional applications. The technique exploits how Entra ID processes the client_id parameter in OAuth authentication requests. Every registered OAuth application is assigned a globally unique application identifier, and…

