< ciso
brief />
Tag Banner

All news with #authentication bypass tag

404 articles

CISA orders federal patching for TrueConf flaws

πŸ”’ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has directed federal agencies to urgently patch two actively exploited critical vulnerabilities in the self-hosted TrueConf Server communications platform. The flaws, tracked as CVE-2026-72529 and CVE-2026-72530, allow unauthenticated remote code execution through a missing authentication function and complex code-injection attacks. CISA added both issues to its KEV catalog and mandated fixes within two weeks due to significant risk to the federal enterprise.
read more β†’

Cisco issues patches for Crosswork and Secure Workload

πŸ”’ Cisco released security updates for its Crosswork platforms and Secure Workload software following an internal review. Four critical flaws affecting Crosswork (including SQL injection and missing authentication) were fixed in Crosswork 7.2.1-SP. Five vulnerabilities impacting Secure Workload (SaaS and on-premises) were remediated in releases 3.10.9.1 and 4.0.4.16. Customers are urged to apply updates despite no known active exploitation.
read more β†’

Citrix issues critical patches for NetScaler gateways

πŸ”’ Citrix has released critical updates for customer-managed NetScaler ADC and NetScaler Gateway to address two serious vulnerabilities: a memory overflow that can cause unpredictable behavior or denial of service, and an authentication bypass that permits pre-authentication access. Supported on-premises builds and certain deployments are affected while Citrix-managed services have been updated; cloud marketplace images may still need manual replacement. Security experts urge immediate emergency patching, credential rotation, session termination, and active hunting due to the high risk of rapid weaponization against internet-facing gateways.
read more β†’

Citrix NetScaler critical authentication bypass patched

πŸ›‘οΈ Citrix released patches for two NetScaler ADC and Gateway flaws, including a critical authentication bypass affecting certain appliance configurations. The issues impact customer-managed NetScaler ADC/Gateway, some FIPS/NDcPP builds, and SecurAccess ZTNA Hybrid using customer-managed instances, but not Citrix-managed cloud services. Administrators should verify configurations and apply updates for affected versions to mitigate risk.
read more β†’

Citrix issues urgent NetScaler security update advisory

πŸ”’ Citrix warned customers to immediately patch two NetScaler vulnerabilities impacting NetScaler Gateway and NetScaler ADC appliances. The most severe, CVE-2026-19490, can allow remote attackers to bypass authentication when SAML action is configured on certain AAA, Auth, or VPN virtual servers. The other, CVE-2026-19489, is a high-severity memory overflow that can enable remote DoS when SIP ALG is enabled on large-scale NAT group configurations. Citrix published recommended firmware builds and urged immediate upgrades for affected deployments.
read more β†’

Researchers Demonstrate 'Zombie Card' Revival Attack

πŸ”’ Researchers at UMass Amherst demonstrated the "Zombie Card" attack that can revive expired Visa contactless cards by rewriting the terminal-facing expiration date over NFC, without breaking cryptography. The technique requires proximity or possession of the card and a relay between card and POS; success depends on issuer and EMV kernel. Tests across multiple banks and kernels produced mixed outcomes, and the team presented the work at USENIX Security 2026.
read more β†’

AIT-GUI flaws could let unauthenticated actors command craft

πŸ”’ Security researchers at Cycode disclosed a critical chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's AMMOS Instrument Toolkit, allowing unauthenticated attackers to issue arbitrary commands to the instrument and spacecraft command bus. Tracked as GHSA-p9r8-2q67-fp86 and rated 9.4 (CVSS v3.1), the issues affect AIT-GUI ≀2.5.1 and were addressed in 2.5.2 on August 12, 2026. The defects include missing authentication, absent CSRF protection, and path traversal on state-changing routes, enabling POST-based command, script execution, and sequence abuse when reachable.
read more β†’

Critical AIT‑GUI Flaw Allows Remote Command Execution

πŸ”’ A critical vulnerability in NASA's open-source AIT-GUI ground control software could let unauthenticated actors issue spacecraft and instrument commands, execute server-side scripts, and run command sequences. Disclosed by Cycode researcher Yuval Elbar on August 18 and tracked as GHSA-p9r8-2q67-fp86 (CVSS 9.4), the flaw affects versions through 2.5.1 and was fixed in 2.5.2. The issue stems from an API that listens on all interfaces, lacks authentication/CSRF protection, and allows unsafe filesystem path construction on execution endpoints.
read more β†’

Critical GitLab GraphQL Flaw Allows Remote Project Changes

πŸ”’ GitLab released out-of-cycle security updates on August 17, 2026, to fix a critical GraphQL vulnerability (CVE-2026-19478) that could let unauthenticated attackers remotely modify or delete public projects and user data. The patches apply to self-managed instances in versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4; hosted GitLab.com and Dedicated are already patched. A second, High-severity issue (CVE-2026-19650) addresses a CSRF-related GraphQL multiplex handling flaw requiring user interaction.
read more β†’

Critical WordPress plugin flaw exposes admin accounts

πŸ”’ More than 40,000 WordPress sites were exposed by an authentication bypass in the User Profile Builder plugin. Tracked as CVE-2026-15826 with a 9.8 CVSS score, versions up to 3.16.4 are affected. Wordfence identified a type confusion in the registration/auto-login flow that can convert a failed registration into user ID 1, enabling generation of an admin authentication token. The vendor released version 3.16.5 on July 16; site owners should update immediately.
read more β†’

SafePal data breach exposes nearly 40,000 orders

πŸ”’ SafePal reports a data breach affecting about 39,798 customers after an authorization flaw in an order-tracking plug-in was exploited to steal order information. The exposed data includes names, emails, shipping addresses, phone numbers, and purchase details for orders placed between March 2, 2025, and April 11, 2026. SafePal says sensitive wallet credentials, payment card numbers, and government IDs were not exposed and that it has fixed the vulnerability, notified affected customers, and launched a verification tool. A threat actor is now claiming to sell the stolen data on a cybercrime forum, and the company warns of targeted phishing and social engineering attempts.
read more β†’

macOS Screen Sharing flaw exploited to install miner

πŸ”’ The Netherlands' NCSC warns that a macOS Screen Sharing authentication bypass (CVE-2026-65400) is being actively exploited after public exploit code appeared. The flaw affects the built-in VNC-based Screen Sharing service (TCP 5900) and allows network attackers to authenticate without valid credentials. Apple fixed the issue in macOS Tahoe 26.6.1, Sequoia 15.7.9 and Sonoma 14.8.9; affected users should update or disable Screen Sharing in System Settings.
read more β†’

PoC for SharePoint JWT Bypass Now Used in Attacks

πŸ”’ A Rapid7 proof-of-concept for a critical SharePoint JWT authentication bypass (CVE-2026-55040) is already being weaponized in attacks, researchers warn. Microsoft patched the flaw in its July 2026 updates for SharePoint Enterprise Server 2016 and SharePoint Server 2019 and cautioned that exploitation can disclose files and modify data. CISA has issued guidance urging teams to avoid exposing SharePoint servers and to apply hardening measures.
read more β†’

Signal adds automatic key verification feature

πŸ” Signal introduced Automatic Key Verification, a new feature within a key transparency system that uses Cloudflare and Trail of Bits as independent auditors to confirm the integrity of encrypted chats. The feature enables users to verify contacts’ public keys automatically via Settings > Privacy > Advanced or by selecting "Verify Automatically" on the safety number screen, showing a green checkmark when successful. Users may disable it and continue with manual safety number checks if they prefer. Signal says this complements existing safety numbers and helps prevent undetected key swaps and man-in-the-middle attacks.
read more β†’

AI-assisted exploit lets attackers assume SharePoint users

πŸ”’ Security researchers discovered an unauthenticated bypass in Microsoft SharePoint allowing an attacker to impersonate any user, including administrators. The flaw, CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, 2019, and 2016; SharePoint Online is not listed. Rapid7 chained the bypass to an RCE, CVE-2026-63520, to run code as the Windows service account, and published analysis and a proof-of-concept. Organizations should ensure the July update is applied and watch for August patches.
read more β†’

Research reveals practical weaknesses in passkey deployments

πŸ” Three research teams disclosed attacks that bypass passkey protections without breaking FIDO cryptography. SpecterOps showed Windows-exposed signatures chained through Microsoft Entra ID to impersonate privileged users. Unit 42 demonstrated methods to recover synced passkey private keys in Chrome's Google Password Manager, and Dirk-jan Mollema showed malware in a signed-in Windows session could use a Windows Hello for Business key without a fresh PIN. Vendors issued patches and mitigations with differing impacts.
read more β†’

New CSS attack chains break webmail boundaries

πŸ”’ New research shows HTML and CSS can escape email message boundaries to interfere with webmail UIs across major providers. PortSwigger researcher Gareth Heyes presented proof-of-concept chains at Black Hat USA 2026 targeting Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The techniques can capture passwords, leak tokens, hijack UI actions, and manipulate AI-connected tools; some PoCs remained public as of August 8.
read more β†’

Malware can abuse Windows Hello to gain cloud access

πŸ”’ Entra ID researcher Dirk-jan Mollema demonstrated that malware running in a signed-in Windows session can silently invoke the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The technique lets an attacker obtain tokens, register devices, and gain long-term cloud access without extracting private keys, recovering PINs, or prompting biometrics on TPM-backed systems. Mollema published PoC scripts and recommends hunting for Hello sign-ins with empty device IDs while noting potential false positives.
read more β†’

Cisco releases critical SD‑WAN and IOS XE fixes

πŸ”’ Cisco issued patches for multiple critical vulnerabilities in Catalyst SD‑WAN and IOS XE Software discovered during an internal security review. The flawsβ€”ranging from improper input validation and access control to command injectionβ€”affect many releases and have been fixed across several patched versions. Cisco noted these were found during testing, including use of frontier AI models, and are not known to be actively exploited, urging customers to update promptly.
read more β†’

Report: Passkey weaknesses expose account takeover risks

πŸ”’ A Palo Alto Networks Unit 42 report details how attackers can exploit onboarding, recovery and device-trust workflows to bypass passkey protections after compromising an endpoint. Analysts stress the underlying cryptography remains intact but warn implementations, synced passkeys and support processes create practical risks. Experts advise enforcing user verification, preferring device-bound authenticators and improving incident response.
read more β†’