< ciso
brief />
Tag Banner

All news with #authentication bypass tag

404 articles · page 2 of 21

Amazon Cognito adds self-service provisioned limits

🔒 Today Amazon Cognito launches provisioned limits in the console to let teams self-service authentication rate adjustments in minutes. The feature separates an account-level maximum (managed via Service Quotas) from a provisioned limit you pay for and control in the Amazon Cognito console, enabling rapid scaling for events like Black Friday. It supports granular RPS adjustments, programmatic APIs, and cost optimization by billing only for provisioned capacity above defaults.
read more →

Critical patches issued for Veeam, HashiCorp, and Django

🔒 Vendors HashiCorp, Veeam, and the Django Software Foundation have released fixes for 11 vulnerabilities affecting Terraform MCP Server, Veeam Service Provider Console, and Django. The most severe include an unauthenticated credential-exposure bug in Veeam (9.5), a cross-tenant token-reuse issue in Terraform MCP (10.0), and a GeoDjango spatial lookup flaw that can write files or trigger code execution. Operators are advised to upgrade to Terraform MCP Server 1.1.0+, Veeam 9.3.0.35057, and Django 6.0.8 / 5.2.17; exposure depends on configuration and none of the flaws show public exploitation as of August 5, 2026.
read more →

Critical Gitea file-read flaw patched in 1.27.1

🔒 An unauthenticated attacker could read any file the Gitea service account can access in versions 1.22.1–1.27.0 by posting crafted Org-mode markup to the markup endpoint. The issue, tracked as CVE-2026-59774 and rated Critical (CVSS 9.8), was fixed in Gitea 1.27.1. Self-hosted admins should upgrade immediately and rotate exposed credentials if the endpoint was reached.
read more →

Researchers Find Major Flaw in Car Anti-Theft Systems

🔍 A UC San Diego research team discovered critical vulnerabilities in the aftermarket KARR Security System, which they estimate is installed in over two million US vehicles. The flaw allows any attacker within Bluetooth range to send radio commands that can silently unlock vehicles, disable alarms, honk horns, flash lights, or even prevent the ignition from starting. This poses risks to vehicle security and driver safety and highlights systemic issues in the design and testing of aftermarket telematics devices.
read more →

CISA Adds N‑able N‑central Flaw to KEV Catalog

🔒 CISA added a high‑severity vulnerability affecting N‑able N‑central to its Known Exploited Vulnerabilities (KEV) list after reports of active exploitation. Tracked as CVE-2026-18577, the flaw is an incomplete patch for CVE-2026-18556 and permits authentication bypass and account takeover; it is fixed in version 2026.3 HF1. N‑able and researchers note indicators such as a malicious "svchost.exe" in user documents, a service named "Cloudflared," and inbound connections from several VPN exit node IPs linked to Mullvad and NordVPN.
read more →

New Pass-ta-key attacks target Google synced passkeys

🔒 Security researchers from Palo Alto Networks' Unit 42 disclosed three related attacks, collectively dubbed "Pass-ta-key," that let malware on compromised Windows devices abuse Google Password Manager's synced passkeys in Chrome on TPM-equipped machines. The techniques — Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key — exploit weaknesses in device trust, onboarding, recovery, and synced credential handling rather than breaking passkey cryptography. While the attacks require existing malware on the victim's device, they can bypass or subvert user verification and even extract the master key that encrypts synced passkeys, enabling account takeover and future key decryption. Unit 42 reported findings to Google and affected services; some issues, such as eBay's validation, have been fixed.
read more →

N‑able warns of N‑central auth bypass actively exploited

🔒 N‑able has issued a hotfix (2026.3.1.7) after detecting active exploitation of an authentication bypass vulnerability, CVE-2026-18577, affecting hosted and on-premises N-central servers. The vendor disclosed the issue on August 1 and released an update the following day, urging immediate upgrade to versions 2026.3 or later. Hosted deployments were updated automatically; on-premises customers must install the patch manually. Indicators of compromise and mitigation guidance are available on the hotfix download page.
read more →

Risks and Attacks Targeting Passkey Authentication

🔒 This Unit 42 analysis examines novel attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The research demonstrates how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to authenticate without user interaction, bypass user verification, and extract synced passkey private keys. The article outlines three attack variants—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—showing practical exploit paths on Windows Chrome with TPM-equipped devices and emphasizing mitigation via Palo Alto Networks products.
read more →

Adobe fixes CVSS 10.0 flaw in Campaign Classic

🛡️ Adobe released updates for Campaign Classic (ACC) to patch a maximum-severity authorization vulnerability (CVE-2026-48449, CVSS 10.0) that could enable arbitrary code execution without user interaction. The fixes, delivered in ACC v7.4.3 build 9398 for Windows and Linux, also address a high-severity SQL injection (CVE-2026-48448, CVSS 8.6) enabling arbitrary file reads. Adobe additionally remediated eight critical-rated flaws in Adobe Bridge that could lead to privilege escalation and code execution, crediting multiple external researchers. Users are urged to apply the updates promptly for protection.
read more →

Critical TeamCity RCE Patch Urged for On‑Prem Servers

🔒 JetBrains warned of a critical pre-authentication vulnerability in TeamCity On‑Premises that could allow unauthenticated HTTP(S) requests to bypass authentication and execute arbitrary OS commands. Tracked as CVE-2026-63077 and rated 9.8, the flaw affects all on‑prem deployments and has been fixed in versions 2025.11.7 and 2026.1.3. Customers unable to upgrade can apply a security patch plugin; TeamCity Cloud customers need take no action.
read more →

Critical TeamCity RCE Vulnerability Alert from JetBrains

🚨 JetBrains has disclosed a critical authentication bypass in TeamCity On-Premises tracked as CVE-2026-63077 that allows remote code execution via the agent polling protocol when an attacker has HTTPS access to the server. All on‑premises TeamCity versions are affected, while TeamCity Cloud customers are already protected. JetBrains released fixes in TeamCity 2025.11.7 and 2026.1.3 and provides a security patch plugin for 2017.1+ for those who cannot upgrade. Administrators are urged to apply patches immediately and follow recommended hardening practices such as limiting internet exposure and requiring VPN or other protective layers.
read more →

VMware patches critical auth bypass and VM escape flaws

🔒 Broadcom released emergency security updates for VMware vCenter, ESX, Workstation, and Fusion to address five vulnerabilities, including three critical flaws that allow authentication bypass, remote code execution, and VM escape. Affected products include VMware Cloud Foundation and various telco platform offerings; administrators should assume prepatched versions are vulnerable and apply fixes immediately. There are no effective workarounds, and some updates require service interruptions or host reboots.
read more →

Three critical VMware flaws permit authentication bypass

🔒 Broadcom issued security updates for multiple VMware products, including ESX, vCenter, Workstation, and Fusion, addressing three critical vulnerabilities. The highest-severity issues include an authentication bypass (CVE-2026-59309) and a directory traversal allowing code execution (CVE-2026-59310) in vCenter. Additional fixes cover VMXNET3 out-of-bounds write, out-of-bounds read, and insufficient logging flaws in ESX and related products. Broadcom reports no evidence of in-the-wild exploitation and has released patches across VMware Cloud Foundation, vSphere, Workstation, and Fusion versions.
read more →

Critical Check Point Management Authentication Bypass

🔒 Rapid7 and other researchers disclosed technical details for CVE-2026-16232, a critical authentication bypass in Check Point Security Management Server and MDS. The flaw lets an unauthenticated attacker obtain an application login token and authenticate with full administrator privileges via SmartConsole. Exploitation requires network access to the Management Server and permissive Trusted Clients configuration. Check Point released Jumbo Hotfixes on July 22, 2026, and Rapid7 published a PoC for testing.
read more →

How attackers bypass multifactor authentication risks

🔒 This article examines prevalent methods attackers use to bypass multifactor authentication (MFA), from MFA fatigue and social engineering to cookie theft and targeting weak or non‑MFA accounts. It summarizes survey findings on uneven MFA adoption, highlights real-world incidents (Okta, Uber), and notes industry guidance favoring phishing‑resistant and passwordless approaches. The piece concludes with concrete defensive steps such as adaptive authentication, tightening access rights, and reviewing password reset workflows.
read more →

Old BMC Vulnerability Exposes Data Center Management

🔒 Lava researchers found tens of thousands of internet-exposed Baseboard Management Controllers (BMCs) vulnerable to a 2013 IPMI authentication flaw, allowing rapid access by guessing weak or factory-set passwords. BMCs provide out-of-band control of servers and often sit outside standard monitoring, enabling persistent, hard-to-detect compromises that can span shared data center and AI/GPU infrastructure. Vendors including Supermicro and HPE were among the most impacted.
read more →

Talos IR Q2 2026 Incident Response Trends

📊 Q2 2026 Talos Incident Response (IR) engagements showed phishing as the primary initial access vector, with attackers increasingly using QR code PDFs and cloud-hosted links to bypass defenses. Authentication abuse spiked to 65% of engagements, with adversaries employing AitM proxies, session-token theft, and MFA fatigue. Ransomware activity remained significant, with Sinobi, Nitrogen, and Warlock observed leveraging trojanized RMM tools like MeshAgent and Zoho Assist. Talos recommends phishing-resistant MFA, strict control of administrative binaries, robust centralized logging, and behavior-based monitoring to detect misuse of legitimate management tools.
read more →

Critical TeamCity RCE Patch Urged for On‑Premises

🛡️ JetBrains warns on-premises TeamCity users to update immediately after a critical RCE vulnerability, CVE-2026-63077 (CVSS 9.8), was disclosed on July 10, 2026. The flaw allows unauthenticated attackers via HTTP(S) to bypass authentication and execute OS commands through the agent polling protocol. Fixes are available in TeamCity 2025.11.7 and 2026.1.3, with a security patch plugin offered for older 2017.1+ releases; no evidence of active exploitation has been reported.
read more →

Arista patches VeloCloud Orchestrator zero-day exploit

🔒 Arista released fixes for a maximum-severity unauthenticated command injection in on-premises VeloCloud Orchestrator (CVE-2026-16812) that is being actively exploited. The flaw allows remote attackers network access to the VCO web interface to execute privileged commands without credentials, potentially impacting confidentiality, integrity, and availability. Affected on-premises versions include 5.2.x, 6.1.x, 6.4.x and early 7.0.x releases; hosted and dedicated deployments are already patched. Administrators are urged to apply the provided updates, restrict VCO web access, block listed malicious IPs, and review logs for signs of compromise.
read more →

Proof‑of‑Concept for Certighost AD CS Exploit

🔒 A proof-of-concept exploit for the “Certighost” Active Directory Certificate Services vulnerability (CVE-2026-54121) was released after Microsoft patched the issue in the July 2026 Patch Tuesday updates. Researchers showed how a low-privileged user can abuse the AD CS “chase” fallback to have a CA contact an attacker-controlled host and issue certificates for targeted machine accounts. The exploit automates PKINIT authentication as a domain controller to obtain Kerberos credentials and perform domain-level actions; Microsoft added validation to the chase process as a fix.
read more →