Tag: cyber
-
Google PageBreak AI Agent Finds Over 500 XSS Vulnerabilities Across Its Web Applications
Google has disclosed that PageBreak, an internal AI security agent developed by its Product Security team, has identified and validated more than 500 cross-site scripting (XSS) vulnerabilities across the company’s first-party web applications, including sensitive domains. The initiative highlights a shift from AI-assisted vulnerability triage to agentic testing that produces exploit-backed findings rather than noisy…
-
Citrix NetScaler SAML Vulnerability Enables Unauthenticated Remote DoS Attacks
Citrix has released emergency security updates to address a high-severity memory overflow vulnerability in NetScaler ADC and NetScaler Gateway. This flaw, tracked as CVE-2026-88779, could allow unauthenticated remote attackers to cause persistent denial-of-service conditions. The vulnerability specifically affects appliances configured for SAML authentication, whether set as a Service Provider (SP) or an Identity Provider (IdP).…
-
Citrix NetScaler SAML Vulnerability Enables Unauthenticated Remote DoS Attacks
Citrix has released emergency security updates to address a high-severity memory overflow vulnerability in NetScaler ADC and NetScaler Gateway. This flaw, tracked as CVE-2026-88779, could allow unauthenticated remote attackers to cause persistent denial-of-service conditions. The vulnerability specifically affects appliances configured for SAML authentication, whether set as a Service Provider (SP) or an Identity Provider (IdP).…
-
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations.The campaigns have impersonated prominent economists and AI policymakers, as well as a prominent Anthropic employee, to single out an AI policy expert at…
-
N0n ransomware: what you need to know
N0n is a newly-emerged cyber extortion gang. The group was first spotted in the middle of September 2026, and within days it had published on its dark web leak site details of what it claimed to be around a dozen victims. Since then, the tally has continued to grow. First seen on fortra.com Jump to…
-
Cling Malware Masquerades as Google STUN Traffic to Control Compromised IoT Devices
A newly identified IoT botnet, Cling, disguises its command-and-control communications as legitimate STUN traffic, including packets that appear to originate from Google’s public STUN infrastructure. The technique enables attackers to manage compromised internet-facing devices while blending activity into routine NAT-traversal traffic used by real-time communications platforms. Nozomi Networks Labs discovered the campaign while investigating a…
-
Microsoft Warns ClickFix Attacks Use Fake CAPTCHA Lures to Execute Malicious Commands
Microsoft Threat Intelligence has identified a ClickFix campaign in which compromised websites use fake CAPTCHA-style verification prompts to trick Windows users into executing malicious commands. The operation stages its payload inside the browser cache before the victim runs the command, helping attackers evade conventional download-based detection and work around Windows Run dialog character limits. The…
-
Critical GitLab AI Gateway Flaw Lets Attackers Execute Arbitrary Commands
GitLab has issued emergency security updates for a critical vulnerability in its Self-Hosted AI Gateway that could allow authenticated attackers to execute arbitrary commands on vulnerable AI Gateway deployments. The flaw, tracked as CVE-2026-90970, carries a CVSS severity score of 9.9 out of 10. The company released GitLab AI Gateway versions 19.2.4, 19.3.2, and 19.4.1…
-
AWS AI Agent Vulnerabilities Let Attackers Bypass Authentication and Steal Credentials
Tags: access, ai, authentication, cloud, credentials, cyber, flaw, open-source, service, vulnerabilityAWS has released security fixes for four vulnerabilities affecting its open-source Loom AI agent orchestration platform and Amazon SageMaker Unified Studio. The flaws could allow attackers to bypass authentication, steal OAuth2 tokens and temporary cloud credentials, access internal services, and execute arbitrary code in another user’s SageMaker environment. AWS disclosed the issues in security bulletins…
-
Citrix NetScaler Appliances Reboot Repeatedly After 0-Day Security Update
Citrix NetScaler administrators report repeated appliance crashes and forced reboots after deploying emergency updates for recently disclosed zero-day vulnerabilities, with the disruption now linked to a newly observed issue affecting SAML authentication deployments. The reports involve internet-facing NetScaler ADC and Gateway systems running patched releases, including version 14.1-73.37, which Citrix previously designated as a fixed…
-
Chinese Open-Weight Models Closing In, Anthropic Warns
Researchers Find GLM-5.3 Safeguards Easy to Bypass. Anthropic conducted its own security assessment of GLM-5.3 from Chinese lab Zhipu AI, also known as Z.ai, and found that the model has strong capabilities for autonomously building end-to-end cyber exploits but lacks meaningful safeguards to limit its misuse. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/chinese-open-weight-models-closing-in-anthropic-warns-a-33009
-
CISA Sends Final CIRCIA Rule to White House for Review
Final Rule Goes to OMB as Defense Contractors Face Second Reporting Regime. The U.S. Cybersecurity and Infrastructure Security Agency sent its final cyber incident reporting rule to the White House for review Thursday after missing a September target, as analysts question whether existing Pentagon reporting will satisfy the new requirements. First seen on govinfosecurity.com Jump…
-
RemoteThreat Bets Security Teams Need to Test What Happens After Defenses Fail
The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers’ increasingly advanced capabilities. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/remotethreat-bets-security-teams-need-to-test-what-happens-after-defenses-fail
-
US Senate Unanimously Passes Health Cyber Bill
All Eyes for HIPAA and Regulatory Reform Are Focused on the House. The U.S. Senate on Thursday unanimously passed a bipartisan bill that proposes to bolster health sector cybersecurity and resiliency. Among other provisions, the bill calls for regulators to raise the bar on minimum cyber best practices for healthcare sector organizations. First seen on…
-
Sony PS5 Relapse Jailbreak Exploit Uses JSC Memory Corruption and Kernel UAF
A newly released PlayStation 5 jailbreak chain, called Relapse, targets PS5 and PS5 Pro consoles running firmware versions 7.00 through 13.60. This jailbreak combines a browser-based JavaScriptCore memory corruption technique with a kernel use-after-free race condition. The project’s source code and documentation outline a two-stage chain that ultimately provides kernel read/write access, allowing affected systems…
-
Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root
Two critical vulnerabilities in the open-source Zammad helpdesk and ticketing platform can be exploited together, enabling attackers to achieve remote code execution and gain root-level control of affected servers. The Dutch Institute for Vulnerability Disclosure (DIVD) and Merlon Security discovered these vulnerabilities, tracked as CVE-2026-102489 and CVE-2026-102490, during an investigation into a breach of DIVD’s…
-
Zammad Vulnerabilities Let Attackers Execute Code and Escalate Privileges to Root
Two critical vulnerabilities in the open-source Zammad helpdesk and ticketing platform can be exploited together, enabling attackers to achieve remote code execution and gain root-level control of affected servers. The Dutch Institute for Vulnerability Disclosure (DIVD) and Merlon Security discovered these vulnerabilities, tracked as CVE-2026-102489 and CVE-2026-102490, during an investigation into a breach of DIVD’s…
-
Safari History Database Tags Can Reveal Users’ Browsing Themes in Forensic Investigations
Safari’s History database contains a lesser-known tagging artifact that can help investigators infer a user’s browsing themes. While this feature is not definitive evidence of intent, when correlated with URLs, visit times, cache data, downloads, and network telemetry, it can provide useful context for macOS forensic timelines. Safari History Tags and Browsing Themes Safari’s History.db…
-
Exposed Hacker Server Reveals Toolkit Used in Viva Aerobus-Linked Intrusion
A publicly exposed attacker staging server has provided a rare, detailed view of a Microsoft SQL Server-focused intrusion linked to a Viva Aerobus-side environment. The server, hosted at 151.243.232.123, functioned as both a tool-delivery point and a repository for stolen material. It was left accessible without authentication, allowing unrelated internet hosts to enumerate its directories…
-
Multiple cPanel WHM Vulnerabilities Enable Root Code Execution and Admin Session Hijacking
cPanel has released security updates to address three vulnerabilities in cPanel & WHM that could allow attackers to hijack WHM administrator sessions or execute commands as the root user. Organizations using affected deployments should prioritize upgrades, as these flaws affect all supported versions of cPanel & WHM before the newly released fixed versions. cPanel &…
-
Multiple cPanel WHM Vulnerabilities Enable Root Code Execution and Admin Session Hijacking
cPanel has released security updates to address three vulnerabilities in cPanel & WHM that could allow attackers to hijack WHM administrator sessions or execute commands as the root user. Organizations using affected deployments should prioritize upgrades, as these flaws affect all supported versions of cPanel & WHM before the newly released fixed versions. cPanel &…
-
Capacitor Vulnerability Lets Remote Content Run With Full App Origin Trust
A critical vulnerability in Capacitor, identified as CVE-2026-103922, could allow attacker-controlled remote content to execute within vulnerable Android and iOS applications, posing as the application’s own trusted origin. This flaw, assigned a CVSS score of 9.3, affects WebView navigation handling in Capacitor and can expose same-origin data, cookies, local storage, and native functionality available through…
-
OpenAI Blocks 15,000 Requests Trying to Extract Protected Model Reasoning
OpenAI has disrupted a coordinated campaign to extract protected internal reasoning from its AI models on a large scale. The company took action against activity linked to more than 15,000 user accounts. The company described the operation as an adversarial model-distillation effort, in which attackers systematically sought model outputs or reasoning traces that could help…
-
Hackers Are Turning Trusted Software Updates Into Credential-Stealing Malware
Tags: attack, credentials, cyber, flaw, github, hacker, malicious, malware, open-source, software, supply-chain, updateA growing wave of supply-chain attacks is proving the opposite: attackers are compromising legitimate open-source packages and using trusted update channels to deploy credential-stealing malware directly into developer and enterprise environments. Malicious Nx releases, published after attackers stole an npm publishing token through a GitHub Actions workflow flaw, ran post-install scripts that searched systems for…
-
TIKTOUK WordPress Toolkit Could Enable AWS, SMTP and API Credential Theft Attacks
A credential-collection toolkit dubbed TIKTOUK that combines WordPress reconnaissance, exposed-file harvesting, plugin credential decryption, and JavaScript secret scanning. The toolkit consists of two Python scripts, wp2s_poll.py and wp2s_crack.py, alongside a stripped Go-based Linux crawler named jscrawl-amd64. All three components retrieve targets from a central HTTP hub, execute assigned collection tasks, and submit status reports and…
-
Authentication Bypass Successfully Impersonated 95 Users Without Passwords or MFA
A critical authentication bypass that enabled the impersonation of 95 employee accounts, including privileged users, without passwords, multi-factor authentication (MFA), or valid Microsoft Entra ID tokens. The issue stemmed from two flaws in the application’s custom session-cookie implementation: a predictable hard-coded signing secret and the use of public database identifiers as authenticated session payloads. Although…
-
Milk Dragon Phishing Kit Uses Facebook and TikTok Discounts to Steal Cards and Bypass MFA
A phishing-as-a-service operation dubbed Milk Dragon, also known as NaiLong, is abusing discount-themed Facebook and TikTok posts to steal payment-card data and intercept multi-factor authentication (MFA) challenges. Group-IB identified 258 phishing pages linked to the kit since October 2025, with victims across 66 countries. Rather than relying on classic delivery-failure notices, bank alerts, or account-lockout…
-
12 Best SSO Solutions Compared (2026): Features Pricing
Microsoft Entra ID is the best SSO for M365-licensed organizations bundled economics end most debates while Okta is the best neutral anchor for mixed-SaaS estates, with Auth0 (an Okta product line, not a separate vendor) leading developer login. Evaluating these platforms alongside the top enterprise Single Sign-On (SSO) solutions reveals how modern access control has…
-
12 Best SSO Solutions Compared (2026): Features Pricing
Microsoft Entra ID is the best SSO for M365-licensed organizations bundled economics end most debates while Okta is the best neutral anchor for mixed-SaaS estates, with Auth0 (an Okta product line, not a separate vendor) leading developer login. Evaluating these platforms alongside the top enterprise Single Sign-On (SSO) solutions reveals how modern access control has…
-
Windows 11 26H2 Enables Settings Backup by Default for Eligible Devices
Microsoft has automatically enabled Windows settings backup for eligible commercial devices running Windows 11, version 26H2. Microsoft positions this capability as a vital resilience measure for enterprise endpoint recovery. The change is applicable when organizations have left the relevant backup policy in a “Not Configured” state. Administrators’ decisions to explicitly turn the feature on or…

