Tag: authentication
-
ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)
Tags: ai, authentication, cve, exploit, intelligence, rce, remote-code-execution, threat, vulnerabilityAttackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/20/servicenow-cve-2026-6875-exploited/
-
Salt Security tackles AI governance challenge with 100 pre-built agentic security policies
Salt Security has expanded its Policy Hub to include 100 pre-built security policies, as organisations look for practical ways to govern AI agents across enterprise environments. The company says the milestone creates one of the industry’s largest libraries of governance policies for agentic AI, covering APIs, Model Context Protocol (MCP) servers, authentication, access controls, compliance…
-
GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE
Tags: authentication, cyber, exploit, flaw, injection, rce, remote-code-execution, sql, vulnerability, wordpressA critical vulnerability chain in WordPress, called wp2shell, that allegedly allows unauthenticated attackers to exploit a pre-authentication SQL injection flaw to achieve remote code execution (RCE) on typical WordPress installations running MySQL. Security researcher Adam Kues discovered this vulnerability chain using GPT-5.6 Sol Ultra during a multi-agent audit of the WordPress source code. GPT-5.6 Sol…
-
Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits
Public exploits are now available for two critical WordPress flaws that attackers can chain to gain remote code execution without authentication. Public proof-of-concept exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core. The flaws, tracked as CVE-2026-63030 and CVE-2026-60137, can be chained to achieve pre-authentication remote code execution on default WordPress installations…
-
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/
-
Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution
A newly disclosed a pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed >>wp2shell,<< that requires no authentication and affects stock WordPress installations with zero plugins installed. Given that WordPress powers an estimated 500 million websites globally. The flaw represents one of the most significant CMS security disclosures in recent memory. The issue stems…
-
Claude can now sign into websites with 1Password without exposing your credentials
1Password has introduced 1Password for Claude, a beta integration that lets Anthropic’s AI assistant complete browser tasks requiring authentication without accessing … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/17/1password-anthropic-claude-integration/
-
Critical Notepad++ Bugs Could Lead to Code Execution, Patch Available
The latest Notepad++ vulnerabilities addressed in version 8.9.7 include several high-impact security flaws that could expose Windows systems to arbitrary code execution, file overwrite attacks, memory corruption, and authentication bypass. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/notepad-vulnerabilities-v897/
-
Phishing Toolkits Harvest Entra Tokens in Real Time
Jalisco Device Code Phishing Tool Use Also Tied to EvilTokens and Kali365 Customers. Sophisticated phishing-as-a-service toolkits are driving a surge in phishing attack volume, experts warn, by giving users highly automated tools for personalizing lures and accessing previously niche tactics for generating valid authentication tokens for persistent access. First seen on govinfosecurity.com Jump to article:…
-
New phishing kits target Microsoft 365 accounts, evade MFA
Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA). First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-phishing-kits-target-microsoft-365-accounts-evade-mfa/
-
Attackers Distribute Password Attacks Across Fictional OAuth Apps to Evade SOC Alerts
Attackers are increasingly abusing spoofed OAuth application identifiers to enumerate Microsoft Entra ID accounts, test credentials, and fragment authentication activity across hundreds of thousands or millions of fictional applications. The technique exploits how Entra ID processes the client_id parameter in OAuth authentication requests. Every registered OAuth application is assigned a globally unique application identifier, and…
-
Microsoft Entra ID gets passkeys default authentication starting September
Microsoft has announced that passkeys will become the default authentication method for the Entra ID enterprise identity service starting September 2026. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-entra-id-gets-passkeys-default-authentication-starting-september/
-
Google adds FIDO2 keys and phone passkeys to Windows login via GCPW
Google has started rolling out FIDO2-compliant physical security key support as a second factor for authentication in Google Credential Provider for Windows (GCPW) to all … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/security-key-windows-login-google-workspace/
-
Microsoft Entra ID authentication overhaul to start in September 2026
Microsoft will begin rolling out passkeys as the default authentication experience for Microsoft Entra ID in the public cloud on September 1, 2026. Organizations with SMS or … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/14/microsoft-entra-passkey-authentication/
-
Critical WordPress OAuth SSO Plugin Flaw Allows Unauthenticated Attackers to Gain Admin Access
A critical authentication bypass vulnerability has been disclosed in the widely used miniOrange OAuth Single Sign-On (SSO) WordPress plugin, carrying a near-maximum CVSS score of 9.8. This flaw, tracked as CVE-2026-57807, affects all plugin versions up to and including version 38.5.8. As of now, it remains unpatched, with no official fix available from the vendor.…
-
Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens
A misconfigured server in Budapest exposed a live phishing operation built to bypass Microsoft 365 multi-factor authentication and retain access to compromised accounts. The server, hosted at 185.163.204[.]7185.163.204[.]7185.163.204[.]7, was running python3 -m http.server 8080 with directory listing enabled, making its operational files publicly accessible. Researchers found phishing configurations, Telegram session artifacts, credential logs, RMM installers,…
-
Exposed Server Unmasks Evilginx Operators Stealing Microsoft 365 Sessions and OAuth Tokens
A misconfigured server in Budapest exposed a live phishing operation built to bypass Microsoft 365 multi-factor authentication and retain access to compromised accounts. The server, hosted at 185.163.204[.]7185.163.204[.]7185.163.204[.]7, was running python3 -m http.server 8080 with directory listing enabled, making its operational files publicly accessible. Researchers found phishing configurations, Telegram session artifacts, credential logs, RMM installers,…
-
Hidden Backdoor Found in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-found-in-tenda-router-firmware-a-32181
-
Hidden Backdoor Found in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-found-in-tenda-router-firmware-a-32181
-
Passwortlos wird MFA noch sicherer
Multifaktor-Authentifizierung (MFA) hat sich sowohl in Unternehmen als auch bei Privatanwendern als weitverbreitetes und etabliertes Standardverfahren zur Identitätsprüfung beim Login etabliert. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/passwortlos-wird-mfa-noch-sicherer
-
Neue Sicherheitslösung unterstützt FIDO2 und PKI für gesicherten logischen Zugriff
Die Infineon Technologies AG bringt SECORA ID Key S USB auf den Markt, eine auf Java Card basierende Lösung mit USB- und NFC-Konnektivität für gesicherte Authentifizierung und digitale Signaturen. Als erste für FIDO Level 3+ zertifizierte und CTAP 2.1-konforme Lösung ermöglicht der Authentifikator eine phishing-resistente, passwortlose Authentifizierung sowie Schutz vor aus der Ferne durchgeführten Softwareangriffen……
-
Hidden Backdoor in Tenda Router Firmware
Unauthenticated Flaw Allows Full Router, Network Takeover. A hidden backdoor, disclosed by CERT/CC and found in multiple firmware versions made by Chinese manufacturer Tenda, bypasses authentication and could grant attackers administrative access. Researchers are reporting exploitation and an Nmap script is making vulnerable devices easier to identify. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hidden-backdoor-in-tenda-router-firmware-a-32181
-
Critical Gitea Docker Bug Under Active Exploitation Exposes Repositories and Secrets
Attackers are exploiting a critical Gitea flaw (CVE-2026-20896) that bypasses authentication with a single HTTP header, exposing repositories and sensitive data. Sysdig researchers warn that attackers are actively exploiting a critical authentication bypass flaw, tracked as CVE-2026-20896 (CVSS score of 9.8), which affects Gitea official Docker images before version 1.26.3. >>CVE-2026-20896 exploited 13 days after…
-
Hidden backdoor in Tenda router firmware grants admin access
A hidden authentication backdoor has been found in multiple Tenda router firmware versions, potentially allowing an attacker to gain administrative access to the device’s web management panel. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hidden-backdoor-in-tenda-router-firmware-grants-admin-access/
-
BeyondTrust Patches Authentication Bypass Vulnerabilities
BeyondTrust has patched four RS and PRA vulnerabilities, including two critical authentication bypass flaws. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/beyondtrust-patches-authentication-bypass-vulnerabilities/
-
Authentication Bypass – Kritische SimpleHelp RMM-Schwachstelle wird aktiv ausgenutzt
Tags: authenticationFirst seen on security-insider.de Jump to article: www.security-insider.de/simplehelp-schwachstelle-oidc-auth-bypass-cve-2026-48558-a-b785971ada922f189ff5f132eaefaba6/
-
Hidden Tenda Router Backdoor Grants Admin Access, No Patch Available
CERT/CC warns an unpatched backdoor in several Tenda routers lets attackers bypass login and gain full admin access with a hidden password. CERT/CC published an alert documenting an undocumented authentication backdoor in multiple Tenda firmware versions, tracked as CVE-2026-11405. The flaw gives anyone who knows the right password full administrative access to the device’s web…
-
CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware
Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices’ web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday.”An attacker can exploit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process First seen on thehackernews.com…
-
BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA
BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices.The vulnerabilities are listed below – CVE-2026-40138 (CVSS score: 9.2) – A pre-authentication vulnerability exists in the First seen on thehackernews.com Jump…

