< ciso
brief />
Tag Banner

All news with #denial of service tag

124 articles

Citrix NetScaler zero-day prompts emergency guidance

πŸ”’ Citrix has disclosed a high-severity zero-day, CVE-2026-88779, affecting NetScaler ADC and NetScaler Gateway that can lead to denial of service when specific SAML-related configurations are present. The vendor urged customers on affected versions to review SAML authentication entries and install updates; temporary signatures and NetScaler Global Deny List rules are available to reduce exposure. Citrix stated customer data integrity was not impacted and is monitoring the situation while CISA added the flaw to its KEV catalog.
read more β†’

Citrix NetScaler memory-overflow DoS vulnerability alert

⚠️ Citrix has warned of a new high-severity memory-overflow vulnerability (CVE-2026-88779) affecting NetScaler ADC and NetScaler Gateway appliances, rating it 8.7 under CVSS 4.0 and reporting observed targeted exploitation. The flaw can cause repeated denial-of-service conditions when SAML authentication is configured and used with Gateway or AAA virtual servers. Citrix provided fixed build numbers and a temporary virtual-patching mitigation via Global Deny List signatures, and warned that affected customers who already patched earlier in the week may need to upgrade again. CISA added the vulnerability to its KEV catalog with an October 7 remediation deadline for US federal agencies.
read more β†’

Citrix NetScaler zero-day patched after active exploitation

πŸ”’ Citrix released security updates for a high-severity NetScaler ADC and NetScaler Gateway vulnerability, tracked as CVE-2026-88779, with a CVSS score of 8.7. The memory overflow bug can cause denial-of-service when NetScaler is configured as a SAML service provider or identity provider; customers should check for add authentication samlAction or add authentication samlIdPProfile entries. Patches are available in specified 13.1 and 14.1 releases, and CISA added the flaw to its KEV catalog with a federal remediation deadline of October 7, 2026.
read more β†’

Citrix issues emergency NetScaler SAML patch

πŸ”’ Citrix has released emergency updates for a NetScaler SAML vulnerability, CVE-2026-88779, which has been exploited in active attacks and causes denial-of-service conditions. The flaw affects NetScaler ADC and Gateway appliances using SAML authentication and carries a CVSS score of 8.7. Citrix published fixes for 14.1 and 13.1 branches and supplied Global Deny Lists while urging immediate upgrades. Administrators are urged to verify SAML configuration to determine exposure and apply the new releases promptly.
read more β†’

Proof-of-Concept Fills Disk to Block Defender Updates

πŸ›‘οΈ A proof-of-concept named BigDiskBuster was published on GitHub on September 19 and prevents Microsoft Defender from installing platform and signature updates by filling all available disk space. The tool's author, former Microsoft researcher Abdelhamid Naceri, previously disclosed other Defender exploits that were used in live attacks. No patch, CVE, or official Microsoft advisory exists for this technique; administrators should monitor update failures, free space, and hidden temporary files while restricting execution of unknown binaries.
read more β†’

Critical Unbound DNSSEC Validator Heap Overflow Fix

πŸ›‘οΈ NLnet Labs released Unbound 1.26.1 to address a critical heap overflow in the DNSSEC validator affecting every release prior to 1.26.1. The overflow (CVE-2026-81642) can be triggered by an attacker controlling a malicious zone and may allow denial of service or remote code execution; eight additional flaws were also patched. Source, binaries, and Windows installers are available, and the advisory provides standalone and combined patches for those unable to upgrade.
read more β†’

ISC issues BIND 9.20.29 and 9.21.26 fixes

πŸ›‘οΈ The Internet Systems Consortium (ISC) released BIND 9.20.29 and 9.21.26 to remediate fourteen vulnerabilities disclosed on 16 September, including a DoH-related crash triggered by an invalid SIG(0) when the client closes a connection early. ISC reports no known active exploitation of these flaws and provides no workarounds; twelve of the issues also affect the unsupported 9.18 branch. The advisories detail affected versions, CVSS scores, conditions to exploit each flaw, and that public test reproductions exist to confirm fixes.
read more β†’

Zero-day Flaws Found in TP-Link Home Security Cameras

πŸ”’ Security researchers disclosed two zero-day vulnerabilities in TP-Link Tapo C200 cameras used for home and SOHO monitoring. Vendor firmware V5_1.4.6, released 18 August, addresses CVE-2026-15315 (auth bypass via replay) and CVE-2026-15316 (onboarding DoS). OPSWAT warns the auth bypass can expose live video and recordings, while the DoS crashes the HTTPS service. A third, still-unpatched bug is considered critical and may allow full device compromise.
read more β†’

GPUThor: Amplified Rowhammer Risk to GPUs

πŸ” A University of Toronto paper describes GPUThor, an advanced Rowhammer-style attack targeting GDDR6 video memory on Nvidia Ampere accelerators. The researchers show a novel access pattern that defeats TRR mitigation by exploiting its refresh cadence, producing far more bit flips than prior GPU attacks. Results include large numbers of multi-bit errors and observed denial-of-service effects, though arbitrary code execution remains unproven. The work highlights ongoing risks to shared GPU infrastructure used in cloud and AI workloads.
read more β†’

OpenAI confirms ChatGPT outage ahead of Astra launch

πŸ› οΈ OpenAI confirmed a widespread ChatGPT and Codex outage that began around 10:58 AM ET on Thursday, September 3. The disruption affects Conversations, Login, ChatGPT Work, GPTs, image generation, Voice mode, file uploads, Deep Research, Agents and other components; at least 15 services are listed as impacted. OpenAI acknowledged the issue on its status page and says it is investigating while continuing to monitor elevated errors.
read more β†’

GPUThor Rowhammer Breaks ECC on NVIDIA Ampere GPUs

πŸ›‘οΈ Academic researchers disclosed GPUThor, a Rowhammer attack that induces widespread bit flips on NVIDIA Ampere-class workstation GPUs with GDDR6, defeating recommended ECC mitigations and enabling denial-of-service and host privilege escalation. The University of Toronto team hammered DRAM banks for extended periods on multiple RTX A-series cards, producing up to 377,552 flips per gigabyte on an A5000. The exploit requires running an unprivileged CUDA kernel and the researchers advise avoiding cross-tenant GPU sharing, monitoring ECC counters, and restricting untrusted CUDA workloads.
read more β†’

Citrix issues critical patches for NetScaler gateways

πŸ”’ Citrix has released critical updates for customer-managed NetScaler ADC and NetScaler Gateway to address two serious vulnerabilities: a memory overflow that can cause unpredictable behavior or denial of service, and an authentication bypass that permits pre-authentication access. Supported on-premises builds and certain deployments are affected while Citrix-managed services have been updated; cloud marketplace images may still need manual replacement. Security experts urge immediate emergency patching, credential rotation, session termination, and active hunting due to the high risk of rapid weaponization against internet-facing gateways.
read more β†’

Cisco ASA and FTD HTTP DoS Flaw Exploited

πŸ›‘οΈ Cisco has disclosed a high-severity vulnerability (CVE-2026-20349, CVSS 8.6) in Secure Firewall ASA and Secure Firewall FTD that allows unauthenticated remote attackers to trigger a denial-of-service by sending crafted HTTP requests to the Remote Access SSL VPN service. The flaw affects multiple ASA and FTD versions and configurations (IKEv2 Remote Access VPN, SSL-VPN, Zero Trust Network Access). Cisco released fixes across affected ASA and FTD releases and said it found active exploitation earlier this month; no viable workarounds exist.
read more β†’

Cisco warns of ASA and FTD VPN flaw causing DoS

πŸ”’ Cisco warns of a high-severity DoS vulnerability, CVE-2026-20349, affecting Secure Firewall ASA and Threat Defense (FTD) devices when certain remote access services are enabled. The flaw stems from insufficient error checking in HTTP request processing and can be exploited remotely without authentication to crash affected devices. Cisco has released hotfixes for multiple ASA and FTD releases and urges customers to upgrade, noting no available workarounds. The company reports active exploitation since August 2026 but has not shared exploit details or indicators of compromise.
read more β†’

Cisco warns of high-severity ClamAV flaws with PoC exploits

πŸ”’ Cisco alerted customers to two high-severity vulnerabilities in the ClamAV ZIP archive parser used by its Secure Endpoint Connector, tracked as CVE-2026-20337 and CVE-2026-20338. The flaws, caused by improper boundary checks and memory handling, allow unauthenticated remote attackers to crash the ClamAV scanning process, resulting in denial-of-service (DoS). Proof-of-concept exploit code is publicly available, and Cisco plans updates later this month to address the issues across Windows, Linux, and macOS.
read more β†’

NatJack at Black Hat: NAT trust model under test

πŸ›‘οΈ At Black Hat USA 2026, researcher Malcolm Stagg disclosed NatJack, a class of attacks that manipulates NAT connection tracking tables to hijack TCP connections, poison DNS, and cause DoS without needing IP spoofing or Layer 2 access. Testing across 32 products revealed vulnerabilities in every implementation examined. Vendor responses varied from patches and CVEs to arguments that the issues reflect design limitations rather than security flaws. Stagg recommended monitoring NAT tables, enabling source IP protections, segmenting untrusted traffic, and disabling loose connection tracking modes as mitigations.
read more β†’

Bit2Watt: GPU workloads can threaten power grids

⚠️ Three Zhejiang University researchers describe "Bit2Watt," a technique showing that ordinary GPU workloads can be modulated to produce fast, controllable power oscillations. They demonstrate two methods: a synthetic kernel (SWMA) that toggles compute intensity and an LLM-training modulation (LTMA) that embeds oscillations into real training runs. Experiments measured kHz-range power components on GPUs and simulations showed that synchronized modulation across many devices could destabilize local grids and create denial-of-service or covert channels. The work highlights a visibility gap between compute and power operators and suggests combined hardware and monitoring defenses.
read more β†’

OpenSSL HollowByte memory-exhaustion flaw analysis

πŸ›‘οΈ OpenSSL received a silent June fix for a denial-of-service issue Okta branded "HollowByte," which causes servers to allocate up to 131 KB per TLS ClientHello before the body arrives. The bug lets attackers exhaust connections and, on glibc systems, fragment the heap so freed memory remains resident until process restart. Fixed releases are 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21 dated June 9, but OpenSSL chose to treat the change as a "bug or hardening" without a CVE, advisory, or changelog note.
read more β†’

HollowByte DoS in OpenSSL bloats server memory

πŸ›‘οΈ Okta researchers disclosed a DoS flaw named HollowByte that lets unauthenticated attackers bloat OpenSSL server memory by sending an 11-byte payload with a forged header. Vulnerable OpenSSL versions allocate memory based on the claimed message length before receiving the payload, then block waiting for data that never arrives, causing heavy heap fragmentation and long-lived RSS growth. The OpenSSL team silently fixed the issue and backported the patch to multiple release lines; administrators are urged to upgrade to the patched versions immediately.
read more β†’

Unpatched XRING bug in XQUIC allows remote crash

πŸ›‘οΈ A single wrong variable in Alibaba's XQUIC library lets any remote client crash servers using default QPACK settings with ordinary HTTP/3 traffic. FoxIO researcher SΓ©bastien FΓ©ry disclosed the XRING flaw on July 8 and showed a crash triggered by about 260 bytes of legal QPACK frames. All XQUIC releases through v1.9.4 are affected; no patch or CVE was available as of July 10. Operators can mitigate by setting SETTINGS_QPACK_MAX_TABLE_CAPACITY to 0 or disabling HTTP/3 until a fix ships.
read more β†’