< ciso
brief />
Tag Banner

All news with #authentication bypass tag

451 articles · page 7 of 23

Apple patches Beats Studio Buds eavesdropping flaw

🔒 Apple released a security update to fix a high-severity vulnerability in Beats Studio Buds that could let attackers within Bluetooth range listen through an unpaired device's microphone. The flaw (CVE-2025-20701) was found in Airoha SoC open-source code and disclosed by ERNW researchers at TROOPERS. Apple deployed Beats Firmware Update 1B211, which installs automatically when paired and in range; users can verify the firmware via Bluetooth settings. Chained with related CVEs, attackers could hijack HFP connections to issue phone commands or access contacts, though practical attacks are complex and require proximity.
read more →

Multiple authentication and crash issues in industrial historian

🔒 Rockwell Automation's FactoryTalk Historian Site Edition and related AVEVA PI Data Archive components contain vulnerabilities that can allow authentication bypass, denial of service, or crashes. Race conditions (CWE-362) and uncaught exceptions (CWE-248) are cited; repeated login requests may yield valid tokens. Vendors provide mitigations and patches; CISA urges network segmentation, restricted access, and defensive best practices.
read more →

AVer PTC Camera Remote Code Execution Advisory

🔒 AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras contain an input validation flaw that could permit unauthenticated remote arbitrary code execution via a crafted web request. Affected devices are rated CVSS v3 9.8 and relate to CWE-552 Files or Directories Accessible to External Parties. AVer has released firmware to address the issue and CISA advises minimizing network exposure, placing devices behind firewalls, and using secure remote access methods such as updated VPNs.
read more →

Rockwell FLEX I/O EtherNet/IP Adapter Flaws Fixed

🔒 Rockwell Automation FLEX I/O EtherNet/IP adapters (1794-AENTR) contain vulnerabilities that could enable unauthorized access, account takeover, and denial-of-service. A memory-handling flaw in CIP request processing may cause adapter faults and loss of I/O connectivity, while an embedded web server issue allows unauthenticated password changes via a crafted HTTP GET. Rockwell recommends updating to firmware 2.013 to remediate these issues.
read more →

Critical OIDC flaw lets attackers add SimpleHelp technicians

🔒 A critical vulnerability (CVE-2026-48558) in SimpleHelp allows unauthenticated actors to create privileged Technician accounts when OIDC authentication is enabled. Researchers at Horizon3.ai attribute the issue to improper validation of identity assertions from OIDC identity providers. The vendor released fixes in versions 5.5.16 and 6.0RC2 on June 9, and mitigations include IP allowlists and monitoring for suspicious technician registrations.
read more →

Palo Alto Warns of Active Exploitation of PAN‑OS Bug

🔒 Palo Alto Networks has observed active exploitation of CVE-2026-0257, an authentication bypass in PAN-OS affecting GlobalProtect portal and gateway components that can enable unauthorized VPN connections. Initial in-the-wild activity was seen on May 17, 2026, though the threat actor remains unidentified. The company provided IoCs and urges customers to search GlobalProtect logs for gateway-connected events and specific client configuration indicators.
read more →

phpBB fixes decade-old authentication bypass

🔒 Researchers discovered a 10-year-old authentication bypass in phpBB that allows logging in as any user, including administrators. The flaw affects versions 4.0.0-a2 and 3.3.16 and below and can be exploited with a single HTTP request on default configurations. Aikido reported the issue on June 2 and phpBB patched it in version 3.3.17 on June 6; 4.x users must await a safe release.
read more →

French Tchap breach exposed over 73,000 public sector accounts

🔒 DINUM disclosed that a breach of the Tchap encrypted messaging platform impacted over 73,000 French public sector accounts after a compromised user account was used to access the service. The attacker accessed data shared in public chat rooms, which are not encrypted, potentially exposing names, email addresses, avatars, and affiliated organizations. Private conversations remain encrypted and protected, and the malicious account has been blocked while an investigation continues. A threat actor has claimed responsibility and released samples of stolen files.
read more →

New GreatXML BitLocker Bypass Exploit Disclosed

🔒 Security researcher Chaotic Eclipse disclosed a new BitLocker bypass named GreatXML that leverages files placed on the recovery partition and booting into Windows Recovery Environment (WinRE). The researcher says the issue is tied to using Windows Defender Offline Scan and can result in a shell with unrestricted access to a BitLocker volume if specific XML files are copied to the recovery partition and WinRE is invoked. GreatXML follows other recent disclosures from the same researcher, including a Defender zero-day and the earlier YellowKey bypass.
read more →

Brickcom Camera Flaw Allows Unauthenticated Video Access

🔒 The advisory describes vulnerabilities in Brickcom cameras that permit unauthenticated attackers to access live snapshots via the /ONVIF endpoint and exploit default credentials to obtain administrative control. CISA reports vendor non-coordination and urges users to contact Brickcom for support while following defensive measures. Recommended mitigations include isolating devices behind firewalls, minimizing internet exposure, and using secure remote access methods such as updated VPNs.
read more →

Ivanti patches critical Sentry gateway vulnerabilities

🔒 Ivanti patched two critical vulnerabilities in Ivanti Sentry, an in-line secure mobile gateway formerly called MobileIron Sentry, that could allow unauthenticated remote attackers to take full control of devices. One flaw, CVE-2026-10523, lets attackers bypass authentication to create administrative accounts and is rated 9.9/10. The second, CVE-2026-10520, is a command injection leading to root remote code execution and is rated 10/10. Customers should upgrade to versions 10.5.2, 10.6.2, or 10.7.1 immediately.
read more →

Ivanti Sentry critical root code execution patched

🔒 Ivanti has released patches for two critical vulnerabilities in its Sentry secure mobile gateway, including a maximum-severity OS command injection (CVE-2026-10520) that allows remote code execution as root and a critical authentication bypass (CVE-2026-10523) permitting creation of rogue admin accounts. Patches are available in Sentry R10.5.2, R10.6.2, and R10.7.1, and the vendor reports no evidence of active exploitation at disclosure. Administrators are urged to apply updates promptly to prevent potential compromises.
read more →

Critical phpBB authentication bypass risks accounts

🛡️ A critical authentication bypass in phpBB forum software allows an attacker to hijack any account, including administrators, with a single unauthenticated request and no password. Tracked as PTT-2026-004 and rated 9.4, the flaw affects all versions up to 3.3.16 (and 4.0.0 alpha) using default database authentication, while a second OAuth-related issue (PTT-2026-005, 8.3) can bind attacker credentials via CSRF and missing state checks. phpBB released 3.3.17 on June 6 to fix both issues and urged immediate upgrades; temporary mitigations include disabling OAuth and auditing OAuth bindings.
read more →

RADIUS Message Integrity Flaw in Modicon Switches

🔒 Schneider Electric disclosed a RADIUS protocol vulnerability (CVE-2024-3596) affecting Modicon Network Managed Switches when the RADIUS Server Message Authenticator option is disabled. The flaw can allow forged RADIUS responses, potentially causing denial of service and loss of confidentiality or integrity for devices connected to the switch. Default configurations are not vulnerable; vendors provide CLI and MIB guidance to ensure msgauth remains enabled. CISA republished the advisory to increase visibility and recommends standard ICS network hardening practices.
read more →

Check Point warns of IKEv1 VPN authentication flaw

🔒 Check Point released emergency hotfixes for IKEv1-related VPN vulnerabilities after confirming active exploitation of a critical authentication bypass. The primary flaw (CVE-2026-50571) can let unauthenticated attackers establish VPN sessions without valid passwords, providing a foothold for further intrusions. A second issue (CVE-2026-50752) risks MITM interference in site-to-site VPNs. Check Point urges immediate patching and migration to IKEv2 where possible.
read more →

Critical UniFi OS bug enables unauthenticated root access

🔒 Researchers found that three fixed flaws in UniFi OS Server (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910) can be chained to achieve remote code execution with root privileges on versions 5.0.6 and earlier. Bishop Fox validated the full attack path on a live instance, showing an authentication bypass via URI normalization differences and a subsequent command injection that escalates to root due to passwordless sudo. A detection script and guidance are available; upgrade to 5.0.8 or later.
read more →

Critical Check Point VPN Flaw Actively Exploited

🔒 Check Point has reported active exploitation of a critical logic flaw in certificate validation affecting Remote Access and Mobile Access VPNs configured to use deprecated IKEv1. The issue, tracked as CVE-2026-50751 (CVSS 9.3), lets unauthenticated attackers bypass user authentication and establish VPN sessions without valid passwords. Exploitation requires IKEv1 enabled, legacy clients accepted, and no machine certificate requirement; activity was first observed in early May 2026 and has targeted a few dozen organizations globally.
read more →

Check Point links VPN zero-day to Qilin gang

🔒 Check Point released security updates to address CVE-2026-50751, a critical authentication-bypass flaw impacting Remote Access VPN and Mobile Access deployments that use the deprecated IKEv1 key exchange. The vulnerability allowed unauthenticated, remote attackers to establish VPN connections and was actively exploited beginning in May, with a surge in early June affecting a few dozen organizations worldwide and one confirmed case tied to the Qilin ransomware affiliate. Check Point also identified a second related issue, CVE-2026-50752, affecting certificate validation in IKEv1 and recommended immediate updates and mitigations for customers unable to patch.
read more →

Meta: 20,225 Instagram Accounts Exposed by Bug

🔒 Meta disclosed that a bug in its AI-powered High Touch Support (HTS) tool allowed attackers to request password reset links to email addresses not associated with targeted Instagram accounts, enabling unauthorized access where two-factor authentication was not enabled. The issue was discovered on May 31, affecting 20,225 users and exposing contact details, profile data, posts, messages and activity history. Meta disabled the HTS tool, invalidated reset links, enforced mandatory security checkpoints on impacted accounts, and instructed users to reset passwords and enable 2FA while it reviews recovery flows.
read more →

Meta AI support flaw led to large Instagram account hijacks

🔒 Meta disclosed that a vulnerability in its AI-assisted High Touch Support (HTS) tool allowed threat actors to reset passwords and hijack over 20,000 Instagram accounts. Attackers exploited HTS by submitting email addresses not verified against target accounts, obtaining reset links for accounts without 2FA. Meta disabled the HTS system, invalidated generated reset links, secured impacted accounts, and required affected users to reset passwords and re-authenticate. The company said it will fix the verification check and review similar recovery flows across its platforms.
read more →