< ciso
brief />
Tag Banner

All news with #authentication bypass tag

451 articles · page 5 of 23

Critical Check Point Management Authentication Bypass

🔒 Rapid7 and other researchers disclosed technical details for CVE-2026-16232, a critical authentication bypass in Check Point Security Management Server and MDS. The flaw lets an unauthenticated attacker obtain an application login token and authenticate with full administrator privileges via SmartConsole. Exploitation requires network access to the Management Server and permissive Trusted Clients configuration. Check Point released Jumbo Hotfixes on July 22, 2026, and Rapid7 published a PoC for testing.
read more →

How attackers bypass multifactor authentication risks

🔒 This article examines prevalent methods attackers use to bypass multifactor authentication (MFA), from MFA fatigue and social engineering to cookie theft and targeting weak or non‑MFA accounts. It summarizes survey findings on uneven MFA adoption, highlights real-world incidents (Okta, Uber), and notes industry guidance favoring phishing‑resistant and passwordless approaches. The piece concludes with concrete defensive steps such as adaptive authentication, tightening access rights, and reviewing password reset workflows.
read more →

Old BMC Vulnerability Exposes Data Center Management

🔒 Lava researchers found tens of thousands of internet-exposed Baseboard Management Controllers (BMCs) vulnerable to a 2013 IPMI authentication flaw, allowing rapid access by guessing weak or factory-set passwords. BMCs provide out-of-band control of servers and often sit outside standard monitoring, enabling persistent, hard-to-detect compromises that can span shared data center and AI/GPU infrastructure. Vendors including Supermicro and HPE were among the most impacted.
read more →

Talos IR Q2 2026 Incident Response Trends

📊 Q2 2026 Talos Incident Response (IR) engagements showed phishing as the primary initial access vector, with attackers increasingly using QR code PDFs and cloud-hosted links to bypass defenses. Authentication abuse spiked to 65% of engagements, with adversaries employing AitM proxies, session-token theft, and MFA fatigue. Ransomware activity remained significant, with Sinobi, Nitrogen, and Warlock observed leveraging trojanized RMM tools like MeshAgent and Zoho Assist. Talos recommends phishing-resistant MFA, strict control of administrative binaries, robust centralized logging, and behavior-based monitoring to detect misuse of legitimate management tools.
read more →

Critical TeamCity RCE Patch Urged for On‑Premises

🛡️ JetBrains warns on-premises TeamCity users to update immediately after a critical RCE vulnerability, CVE-2026-63077 (CVSS 9.8), was disclosed on July 10, 2026. The flaw allows unauthenticated attackers via HTTP(S) to bypass authentication and execute OS commands through the agent polling protocol. Fixes are available in TeamCity 2025.11.7 and 2026.1.3, with a security patch plugin offered for older 2017.1+ releases; no evidence of active exploitation has been reported.
read more →

Arista patches VeloCloud Orchestrator zero-day exploit

🔒 Arista released fixes for a maximum-severity unauthenticated command injection in on-premises VeloCloud Orchestrator (CVE-2026-16812) that is being actively exploited. The flaw allows remote attackers network access to the VCO web interface to execute privileged commands without credentials, potentially impacting confidentiality, integrity, and availability. Affected on-premises versions include 5.2.x, 6.1.x, 6.4.x and early 7.0.x releases; hosted and dedicated deployments are already patched. Administrators are urged to apply the provided updates, restrict VCO web access, block listed malicious IPs, and review logs for signs of compromise.
read more →

Proof‑of‑Concept for Certighost AD CS Exploit

🔒 A proof-of-concept exploit for the “Certighost” Active Directory Certificate Services vulnerability (CVE-2026-54121) was released after Microsoft patched the issue in the July 2026 Patch Tuesday updates. Researchers showed how a low-privileged user can abuse the AD CS “chase” fallback to have a CA contact an attacker-controlled host and issue certificates for targeted machine accounts. The exploit automates PKINIT authentication as a domain controller to obtain Kerberos credentials and perform domain-level actions; Microsoft added validation to the chase process as a fix.
read more →

Certighost flaw in AD CS lets attackers spoof DCs

🛡️ Researchers disclosed "Certighost," a vulnerability in Microsoft Active Directory Certificate Services (AD CS) that lets a low‑privilege domain user trick the CA into issuing certificates impersonating a Domain Controller. The issue abuses a directory-object resolution fallback called a "chase," where attacker-controlled identity data supplied via attributes like cdc can be used by the CA during issuance. Microsoft patched the flaw in its July 2026 updates and researchers provided a temporary policy-based mitigation for environments that cannot immediately install the patch.
read more →

Redis fixes multiple authenticated RCE paths via RESTORE

🔒 Redis issued seven security releases on July 23 after published PoCs demonstrated authenticated remote code execution chains against stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All exploit chains require RESTORE; Streams chains also need EVAL and XGROUP, while the 8.8.0 chain needs EVAL plus the bundled RedisBloom module. Users should upgrade to the fixed branch and, until then, revoke RESTORE from unnecessary accounts and block untrusted network access.
read more →

Critical Check Point SmartConsole vulnerability exploited

🔒 Check Point confirmed a critical SmartConsole vulnerability (CVE-2026-16232, CVSS 9.3) is being exploited in the wild, allowing unauthenticated attackers to obtain login tokens and assume full admin privileges. The company released a patch and urged limiting Trusted Clients to trusted IPs/subnets while noting practical challenges with dynamic addressing. Check Point found ten impacted customers and recommends applying the hotfix rather than relying solely on mitigations.
read more →

Google introduces selfie video sign-in option

📸 Selfie video sign-in provides a new option to access your Google Account when you’re locked out or lack your usual device. Setup involves a short guided head-movement video captured and stored securely with your consent; you can delete it anytime. The system compares a fresh selfie video to the stored one and requires live movements to prevent spoofing. Encryption at rest and existing security measures are applied to protect against impersonation and suspicious sign-in attempts.
read more →

Check Point patches SmartConsole zero-day exploit

🔒 Check Point has released a patch for an actively exploited SmartConsole zero-day (CVE-2026-16232) that permits unauthenticated attackers to obtain an application login token and authenticate with administrator privileges. Successful exploitation requires the Management Server to be reachable from the Internet and Trusted Clients not being restricted, allowing attackers to alter security configurations and policies. The vendor urged affected customers to apply updates and recommended mitigations, while CISA has added the flaw to its known exploited vulnerabilities catalog and ordered federal agencies to patch by July 25.
read more →

Check Point issues fixes for actively exploited flaw

🛡️ Check Point released security updates for Security Management and Multi-Domain Management products to address multiple vulnerabilities, including a critical authentication bypass (CVE-2026-16232) actively exploited in the wild. The flaw enables unauthenticated attackers to obtain a SmartConsole login token and gain full administrative privileges if Management is exposed to the internet without Trusted Client or firewall restrictions. Additional patches cover two other high-severity issues (CVE-2026-62144 and CVE-2026-62145). Customers are urged to apply the July 22 Jumbo hotfix, restrict Trusted Clients to trusted IPs, and secure Management access with firewall protections.
read more →

Critical Check Point SmartConsole Authentication Bypass

🔒 Check Point released a jumbo hotfix (July 22, 2026) addressing multiple security hardening issues across firewall and management products. The advisory details several CVEs, including CVE-2026-16232, an authentication bypass affecting Management when exposed to the internet without IP restrictions, which was observed in the wild. The update provides mitigation guidance, IoCs, and installation instructions for the hotfix; customers are urged to apply it and follow best practices.
read more →

Qilin ransomware leverages PAN‑OS VPN flaw

🛡️ Arctic Wolf Labs investigated June 2026 intrusions where actors exploited CVE-2026-0257, a patched authentication bypass in Palo Alto Networks PAN-OS, to establish SSL VPN sessions and deploy Qilin (aka Agenda) ransomware. Post-exploitation activity varied from rapid encryption to full double-extortion, but shared tactics included staging payloads in C:\PerfLogs\, using PsExec for lateral movement, harvesting credentials, disabling Defender real-time protection, and clearing event logs.
read more →

Critical GlobalProtect VPN Bug Now Used in Ransomware

🔒 Palo Alto Networks patched a critical PAN-OS GlobalProtect authentication bypass (CVE-2026-0257) on May 13 after Rapid7 observed active exploitation from May 17. Arctic Wolf reports the Qilin ransomware gang is leveraging the flaw to gain unauthorized VPN access and deploy ransomware, with incidents in June resulting in domain-wide encryption. CISA added the vulnerability to its Known Exploited Vulnerability catalog and ordered federal agencies to remediate within three days.
read more →

Gemini lock-screen flaw lets messages be sent

🔒 Google is fixing a vulnerability that lets an attacker with physical access to a locked Android 16 device use Gemini to send SMS and WhatsApp messages without entering a PIN. Reports since May show the bypass exploits Gemini's Deep Research and a specific multi-touch gesture to circumvent authentication. Google says a patch is imminent; meanwhile, users should restrict Gemini's lock-screen access to limit exposure.
read more →

Zoom fixes critical account-takeover vulnerability

🔒 Zoom disclosed and patched a critical vulnerability that could allow an unauthenticated attacker to perform an account takeover via network access, affecting several Windows clients and VDI branches. The company also fixed three privilege-escalation bugs across Zoom Workplace, Zoom Rooms, and related VDI plugins. Security experts warned the flaw is highly dangerous due to low complexity and no user interaction required, while praising Zoom for discovering and patching the issues.
read more →

n8n token-exchange identity binding flaw fixed

🔒 n8n's Enterprise token-exchange feature matched incoming JWTs to local users using only the sub claim and ignored the iss value, allowing a valid token from one issuer to authenticate as a user belonging to another issuer. The bug (CVE-2026-59208) was fixed on June 24 and credited to GitHub user bearsyankees. It only affects Enterprise instances with token exchange enabled and trusting multiple issuers; the recommended mitigations are upgrade to 2.27.4/2.28.1+ or restrict trusted issuers.
read more →

New Claude for Chrome bugs let extensions abuse privileges

🔒 Researchers at Manifold Security found two vulnerabilities in Anthropic’s Claude for Chrome extension that let a malicious extension trigger privileged AI actions, including reading Gmail, Google Docs, and Calendar data. The flaws are reproducible in version 1.0.80 and persist eight releases after initial reporting. One issue allows synthetic clicks to bypass user verification due to missing event.isTrusted checks; the other places the extension into an elevated mode via a URL parameter. Manifold urges fixes to validate genuine user interactions and to avoid URL-driven privilege transitions.
read more →