< ciso
brief />
Tag Banner

All news with #authentication bypass tag

451 articles · page 4 of 23

Signal adds automatic key verification feature

🔐 Signal introduced Automatic Key Verification, a new feature within a key transparency system that uses Cloudflare and Trail of Bits as independent auditors to confirm the integrity of encrypted chats. The feature enables users to verify contacts’ public keys automatically via Settings > Privacy > Advanced or by selecting "Verify Automatically" on the safety number screen, showing a green checkmark when successful. Users may disable it and continue with manual safety number checks if they prefer. Signal says this complements existing safety numbers and helps prevent undetected key swaps and man-in-the-middle attacks.
read more →

AI-assisted exploit lets attackers assume SharePoint users

🔒 Security researchers discovered an unauthenticated bypass in Microsoft SharePoint allowing an attacker to impersonate any user, including administrators. The flaw, CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, 2019, and 2016; SharePoint Online is not listed. Rapid7 chained the bypass to an RCE, CVE-2026-63520, to run code as the Windows service account, and published analysis and a proof-of-concept. Organizations should ensure the July update is applied and watch for August patches.
read more →

Research reveals practical weaknesses in passkey deployments

🔐 Three research teams disclosed attacks that bypass passkey protections without breaking FIDO cryptography. SpecterOps showed Windows-exposed signatures chained through Microsoft Entra ID to impersonate privileged users. Unit 42 demonstrated methods to recover synced passkey private keys in Chrome's Google Password Manager, and Dirk-jan Mollema showed malware in a signed-in Windows session could use a Windows Hello for Business key without a fresh PIN. Vendors issued patches and mitigations with differing impacts.
read more →

New CSS attack chains break webmail boundaries

🔒 New research shows HTML and CSS can escape email message boundaries to interfere with webmail UIs across major providers. PortSwigger researcher Gareth Heyes presented proof-of-concept chains at Black Hat USA 2026 targeting Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The techniques can capture passwords, leak tokens, hijack UI actions, and manipulate AI-connected tools; some PoCs remained public as of August 8.
read more →

Malware can abuse Windows Hello to gain cloud access

🔒 Entra ID researcher Dirk-jan Mollema demonstrated that malware running in a signed-in Windows session can silently invoke the victim's Windows Hello for Business key to authenticate to Microsoft Entra ID. The technique lets an attacker obtain tokens, register devices, and gain long-term cloud access without extracting private keys, recovering PINs, or prompting biometrics on TPM-backed systems. Mollema published PoC scripts and recommends hunting for Hello sign-ins with empty device IDs while noting potential false positives.
read more →

Cisco releases critical SD‑WAN and IOS XE fixes

🔒 Cisco issued patches for multiple critical vulnerabilities in Catalyst SD‑WAN and IOS XE Software discovered during an internal security review. The flaws—ranging from improper input validation and access control to command injection—affect many releases and have been fixed across several patched versions. Cisco noted these were found during testing, including use of frontier AI models, and are not known to be actively exploited, urging customers to update promptly.
read more →

Report: Passkey weaknesses expose account takeover risks

🔒 A Palo Alto Networks Unit 42 report details how attackers can exploit onboarding, recovery and device-trust workflows to bypass passkey protections after compromising an endpoint. Analysts stress the underlying cryptography remains intact but warn implementations, synced passkeys and support processes create practical risks. Experts advise enforcing user verification, preferring device-bound authenticators and improving incident response.
read more →

Amazon Cognito adds self-service provisioned limits

🔒 Today Amazon Cognito launches provisioned limits in the console to let teams self-service authentication rate adjustments in minutes. The feature separates an account-level maximum (managed via Service Quotas) from a provisioned limit you pay for and control in the Amazon Cognito console, enabling rapid scaling for events like Black Friday. It supports granular RPS adjustments, programmatic APIs, and cost optimization by billing only for provisioned capacity above defaults.
read more →

Critical patches issued for Veeam, HashiCorp, and Django

🔒 Vendors HashiCorp, Veeam, and the Django Software Foundation have released fixes for 11 vulnerabilities affecting Terraform MCP Server, Veeam Service Provider Console, and Django. The most severe include an unauthenticated credential-exposure bug in Veeam (9.5), a cross-tenant token-reuse issue in Terraform MCP (10.0), and a GeoDjango spatial lookup flaw that can write files or trigger code execution. Operators are advised to upgrade to Terraform MCP Server 1.1.0+, Veeam 9.3.0.35057, and Django 6.0.8 / 5.2.17; exposure depends on configuration and none of the flaws show public exploitation as of August 5, 2026.
read more →

Critical Gitea file-read flaw patched in 1.27.1

🔒 An unauthenticated attacker could read any file the Gitea service account can access in versions 1.22.1–1.27.0 by posting crafted Org-mode markup to the markup endpoint. The issue, tracked as CVE-2026-59774 and rated Critical (CVSS 9.8), was fixed in Gitea 1.27.1. Self-hosted admins should upgrade immediately and rotate exposed credentials if the endpoint was reached.
read more →

Researchers Find Major Flaw in Car Anti-Theft Systems

🔍 A UC San Diego research team discovered critical vulnerabilities in the aftermarket KARR Security System, which they estimate is installed in over two million US vehicles. The flaw allows any attacker within Bluetooth range to send radio commands that can silently unlock vehicles, disable alarms, honk horns, flash lights, or even prevent the ignition from starting. This poses risks to vehicle security and driver safety and highlights systemic issues in the design and testing of aftermarket telematics devices.
read more →

CISA Adds N‑able N‑central Flaw to KEV Catalog

🔒 CISA added a high‑severity vulnerability affecting N‑able N‑central to its Known Exploited Vulnerabilities (KEV) list after reports of active exploitation. Tracked as CVE-2026-18577, the flaw is an incomplete patch for CVE-2026-18556 and permits authentication bypass and account takeover; it is fixed in version 2026.3 HF1. N‑able and researchers note indicators such as a malicious "svchost.exe" in user documents, a service named "Cloudflared," and inbound connections from several VPN exit node IPs linked to Mullvad and NordVPN.
read more →

New Pass-ta-key attacks target Google synced passkeys

🔒 Security researchers from Palo Alto Networks' Unit 42 disclosed three related attacks, collectively dubbed "Pass-ta-key," that let malware on compromised Windows devices abuse Google Password Manager's synced passkeys in Chrome on TPM-equipped machines. The techniques — Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key — exploit weaknesses in device trust, onboarding, recovery, and synced credential handling rather than breaking passkey cryptography. While the attacks require existing malware on the victim's device, they can bypass or subvert user verification and even extract the master key that encrypts synced passkeys, enabling account takeover and future key decryption. Unit 42 reported findings to Google and affected services; some issues, such as eBay's validation, have been fixed.
read more →

N‑able warns of N‑central auth bypass actively exploited

🔒 N‑able has issued a hotfix (2026.3.1.7) after detecting active exploitation of an authentication bypass vulnerability, CVE-2026-18577, affecting hosted and on-premises N-central servers. The vendor disclosed the issue on August 1 and released an update the following day, urging immediate upgrade to versions 2026.3 or later. Hosted deployments were updated automatically; on-premises customers must install the patch manually. Indicators of compromise and mitigation guidance are available on the hotfix download page.
read more →

Risks and Attacks Targeting Passkey Authentication

🔒 This Unit 42 analysis examines novel attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The research demonstrates how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to authenticate without user interaction, bypass user verification, and extract synced passkey private keys. The article outlines three attack variants—Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key—showing practical exploit paths on Windows Chrome with TPM-equipped devices and emphasizing mitigation via Palo Alto Networks products.
read more →

Adobe fixes CVSS 10.0 flaw in Campaign Classic

🛡️ Adobe released updates for Campaign Classic (ACC) to patch a maximum-severity authorization vulnerability (CVE-2026-48449, CVSS 10.0) that could enable arbitrary code execution without user interaction. The fixes, delivered in ACC v7.4.3 build 9398 for Windows and Linux, also address a high-severity SQL injection (CVE-2026-48448, CVSS 8.6) enabling arbitrary file reads. Adobe additionally remediated eight critical-rated flaws in Adobe Bridge that could lead to privilege escalation and code execution, crediting multiple external researchers. Users are urged to apply the updates promptly for protection.
read more →

Critical TeamCity RCE Patch Urged for On‑Prem Servers

🔒 JetBrains warned of a critical pre-authentication vulnerability in TeamCity On‑Premises that could allow unauthenticated HTTP(S) requests to bypass authentication and execute arbitrary OS commands. Tracked as CVE-2026-63077 and rated 9.8, the flaw affects all on‑prem deployments and has been fixed in versions 2025.11.7 and 2026.1.3. Customers unable to upgrade can apply a security patch plugin; TeamCity Cloud customers need take no action.
read more →

Critical TeamCity RCE Vulnerability Alert from JetBrains

🚨 JetBrains has disclosed a critical authentication bypass in TeamCity On-Premises tracked as CVE-2026-63077 that allows remote code execution via the agent polling protocol when an attacker has HTTPS access to the server. All on‑premises TeamCity versions are affected, while TeamCity Cloud customers are already protected. JetBrains released fixes in TeamCity 2025.11.7 and 2026.1.3 and provides a security patch plugin for 2017.1+ for those who cannot upgrade. Administrators are urged to apply patches immediately and follow recommended hardening practices such as limiting internet exposure and requiring VPN or other protective layers.
read more →

VMware patches critical auth bypass and VM escape flaws

🔒 Broadcom released emergency security updates for VMware vCenter, ESX, Workstation, and Fusion to address five vulnerabilities, including three critical flaws that allow authentication bypass, remote code execution, and VM escape. Affected products include VMware Cloud Foundation and various telco platform offerings; administrators should assume prepatched versions are vulnerable and apply fixes immediately. There are no effective workarounds, and some updates require service interruptions or host reboots.
read more →

Three critical VMware flaws permit authentication bypass

🔒 Broadcom issued security updates for multiple VMware products, including ESX, vCenter, Workstation, and Fusion, addressing three critical vulnerabilities. The highest-severity issues include an authentication bypass (CVE-2026-59309) and a directory traversal allowing code execution (CVE-2026-59310) in vCenter. Additional fixes cover VMXNET3 out-of-bounds write, out-of-bounds read, and insufficient logging flaws in ESX and related products. Broadcom reports no evidence of in-the-wild exploitation and has released patches across VMware Cloud Foundation, vSphere, Workstation, and Fusion versions.
read more →