Tag: authentication
-
Misconfigured Supabase apps expose data in over 16,000 databases
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/misconfigured-supabase-apps-expose-data-in-over-16-000-databases/
-
Microsoft Entra TrustSink Attack Uses Rogue MFA Provider to Steal Passwords
TrustSink, a post-compromise credential-phishing technique that abuses Microsoft Entra External Authentication Methods (EAMs) to place a rogue password prompt inside an otherwise legitimate Microsoft sign-in flow. The attack enables an adversary with elevated tenant privileges to capture plaintext passwords while returning a valid signed token to Entra, allowing the victim’s login to complete without an…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Operation Master Exploits GlobalProtect CVE-2026-0257 and Deploys AdaptixC2 Across Enterprise Networks
Tags: attack, authentication, credentials, cve, cyber, cybercrime, data, exploit, finance, fraud, network, theft, vpn, vulnerability“Operation Master,” an end-to-end cybercrime operation that combined GlobalProtect VPN exploitation, web-application attacks, credential theft, data monetization, and an industrial-scale invoice-fraud platform. The campaign illustrates how enterprise intrusions can be converted into persistent, localized financial fraud operations rather than ending with data theft or ransomware. The operation exploited CVE-2026-0257, an authentication-bypass vulnerability affecting Palo Alto…
-
Hackers Turn an Open-Source AI Agent Into a Tool for Controlling Compromised Docker Servers
Tags: access, ai, authentication, botnet, control, cyber, data-breach, docker, framework, hacker, open-source, tool, wormA Docker-focused botnet that repurposes the legitimate, open-source Hermes Agent framework as an interactive post-compromise control layer. The campaign, tracked as CARBONATO, targets Docker daemons exposed without authentication on TCP port 2375, then combines worm-like propagation, stealthy persistence, reverse SSH access and Telegram-driven AI-agent operations. The investigation began in August 2026 after researchers identified a…
-
ViewSonic vCast Vulnerabilities Let Attackers Gain Full Device Control Without Authentication
The CERT Coordination Center (CERT/CC) has revealed a chain of three vulnerabilities in ViewSonic’s vCast software that could enable unauthenticated attackers on a shared network to steal displayed screen content, install malicious Android applications, and ultimately gain full control of affected ViewBoard smart displays. These vulnerabilities, tracked as VU#234131, affect vCast, the wireless casting and…
-
Authorizer: Open-source authentication and authorization for your apps
Authorizer is an open-source server for sign-in and access control in web and mobile apps. Teams run it on their own infrastructure and keep user accounts in a database they … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/28/authorizer-open-source-authentication-server/
-
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
Tags: adobe, attack, authentication, cisa, cybersecurity, exploit, flaw, hacker, infrastructure, software, vulnerabilityThe Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploited-in-attacks/
-
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.The issue stems from a preg_replace() backslash First…
-
U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
Tags: adobe, authentication, cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first flaw added to the catalog, tracked as CVE-2026-5430 (CVSS score 10.0), is an authentication bypass in multiple WSO2 products…
-
U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog
Tags: adobe, authentication, cisa, cve, cybersecurity, exploit, flaw, infrastructure, kev, vulnerabilityU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first flaw added to the catalog, tracked as CVE-2026-5430 (CVSS score 10.0), is an authentication bypass in multiple WSO2 products…
-
AI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOS
MikroTrick chains two RouterOS flaws to bypass authentication and gain admin access. AI helped researchers uncover the attack chain within days. MikroTik pushed out patches on September 3, 2026 for several RouterOS issues at once, calling it an important security update without saying what it actually fixed. That silence was deliberate, and it didn’t last…
-
Roundcube Webmail Flaw Lets Attackers Trigger SQL Injection Without Authentication
A highly severe vulnerability in Roundcube Webmail is being actively exploited, posing risks to unpatched email servers through unauthenticated SQL injection attacks. This vulnerability, tracked as CVE-2026-48842, affects Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. On September 21, the Canadian Center for Cyber Security updated advisory AV26-503, warning that reports from the…
-
Hackers Exploit Check Point VPN RCE and Management Zero-Day in Attacks
Tags: attack, authentication, cve, cvss, cyber, exploit, flaw, hacker, rce, remote-code-execution, update, vpn, vulnerability, zero-dayCheck Point has warned customers about the active exploitation of two critical vulnerabilities in its VPN gateway and Security Management products: CVE-2026-85102 and the newly disclosed CVE-2026-93616. Both vulnerabilities have a CVSS score of 9.8 and allow for pre-authentication attacks, making immediate patching and reducing exposure essential. Check Point Flaws CVE-2026-85102 is an improper certificate-validation…
-
Whitepaper: Der Perimeter hat sich aufgelöst, Identitäten sind der neue Kontrollpunkt
Identitäten sind der neue Kontrollpunkt der IT-Sicherheit. In hybriden Architekturen entscheidet nicht mehr der Netzwerkstandort, sondern eine belastbare Kette aus Verifikation, Authentifizierung, Autorisierung und laufender Bewertung. Das gilt für Menschen ebenso wie für Workloads und KI-Agenten und wird mit EUDI-Wallet, Schweizer E-ID und wachsender Agenten-Autonomie zur Managementaufgabe. Management Summary Der Perimeter ist zur Identitätsfrage… First…
-
Whitepaper: Der Perimeter hat sich aufgelöst, die Fristen laufen
Identitäten sind der neue Kontrollpunkt der IT-Sicherheit. In hybriden Architekturen entscheidet nicht mehr der Netzwerkstandort, sondern eine belastbare Kette aus Verifikation, Authentifizierung, Autorisierung und laufender Bewertung. Das gilt für Menschen ebenso wie für Workloads und KI-Agenten und wird mit EUDI-Wallet, Schweizer E-ID und wachsender Agenten-Autonomie zur Managementaufgabe. Management Summary Der Perimeter ist zur Identitätsfrage… First…
-
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication…
-
DNSSEC und DANE sollen EKommunikation noch besser absichern
Das deutsche Unternehmen Conbool ist in die ‘Hall of Fame 2.0″ des E-Mail-Sicherheitsjahres von BSI, Eco und Bitkom aufgenommen worden. Das Hamburger Unternehmen hat DNSSEC nach der technischen Richtlinie BSI-TR-03108 umgesetzt und setzt zusätzlich auf DANE (DNS-based Authentication of Named-Entities), um die Verschlüsselung von E-Mail-Verbindungen gegen Manipulationen abzusichern. Mit der Aufnahme in die Hall of…
-
Microsoft reminds admins to migrate Entra ID users to passkeys
Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-reminds-admins-to-migrate-entra-id-users-to-passkeys/
-
Hackers Abuse Critical cPanel Authentication Bypass to Compromise Hosting Servers
Threat actors rapidly exploited a critical authentication bypass in cPanel and WHM to compromise internet-facing hosting servers, with Japanese telemetry data linking the campaign to a sharp rise in Mirai-like scanning and attack traffic targeting Telnet services. The activity centers on CVE-2026-41940, a critical vulnerability in cPanel and WHM’s session-management layer that enables a remote,…
-
Cisco Zero-Day Highlights API Endpoint Authentication Issues
The authentication bypass flaw CVE-2026-76460 impacts Cisco’s Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues
-
Critical pgAdmin Authentication Bypass Lets Attackers Login as Administrator Without Credentials
A critical vulnerability in pgAdmin 4 could allow unauthenticated remote attackers to impersonate arbitrary users, including existing administrator accounts, by supplying a malicious HTTP identity header. This vulnerability, tracked as CVE-2026-86863, affects installations using pgAdmin’s Webserver authentication mode and has a CVSS 3.1 score of 9.8 out of 10. The issue impacts pgAdmin 4 versions…
-
Hackers Exploit MikroTik Vulnerabilities to Take Over MikroTik Routers Without Authentication
Attackers are actively exploiting a critical vulnerability chain dubbed MikroTrick to seize full administrative control of internet-exposed MikroTik RouterOS devices without valid credentials. CERT Polska disclosed six RouterOS vulnerabilities on September 5, 2026, warning that two critical vulnerabilities could be chained to take over publicly reachable routers. The Polish national CSIRT said it had confirmed…
-
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation.The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication.”This vulnerability is due to insufficient authentication control on an API endpoint,” Cisco said. “An attacker First seen on thehackernews.com…

