< ciso
brief />
Tag Banner

All news with #privilege escalation tag

351 articles

Microsoft Exchange privilege escalation advisory

πŸ”’ Microsoft issued out-of-band updates for a high-severity flaw in Microsoft Exchange Server that can allow an authenticated attacker to elevate privileges and access other users' mailboxes within the same organization. Tracked as CVE-2026-96940 with a CVSS score of 8.8, Microsoft applied a service-side fix for Exchange Online, while on-premises customers must install provided updates for specified Exchange Server builds. The company named researcher Jan Mitchell as the reporter and rated exploitability as "Exploitation More Likely."
read more β†’

Critical Dell DSU Flaw Lets Attackers Gain Root

πŸ›‘οΈ Dell warned customers to update the System Update (DSU) CLI after a critical path traversal vulnerability (CVE-2026-86360) was disclosed that can allow unauthenticated attackers to execute code with root privileges. The company released DSU 2.3.0.0 to patch this and four other high-severity issues, and urged immediate upgrades. U.S. agencies previously warned vendors to eliminate path traversal weaknesses, and organizations should patch promptly to reduce risk.
read more β†’

Apple to Tighten macOS Full Disk Access Controls

πŸ”’ Apple is moving to strengthen controls around the macOS Full Disk Access (FDA) setting after concerns that AI agents and some apps may misuse it to access sensitive data. The company said FDA can expose files, mail, messages, browsing history and backups, and plans updates to require explicit user actions before granting such deep access. The change appears prompted by incidents involving agentic tools like Meta's Muse and proof-of-concept exploits that demonstrated token theft and broader privilege amplification risks. Apple did not announce a rollout date but emphasized clearer user consent and heightened safeguards.
read more β†’

Critical Dell CSM Flaws Allow Full Administrative Access

πŸ”’ Dell released updates to fix multiple critical flaws in Container Storage Modules (CSM) that allow unauthenticated attackers to gain administrative control, escalate privileges, or forge tokens. Affected versions are all prior to 1.17.0, and the fixes are included in 1.18.0. Dell urges immediate updating and rotation of JWT signing secrets, as no effective mitigations exist aside from upgrading.
read more β†’

DIVD Breached via Agentic AI Exploiting Zammad Zero-days

πŸ”’ The Dutch Institute for Vulnerability Disclosure (DIVD) disclosed it was compromised after attackers used two zero-day flaws in Zammad. Detected on September 24, the chained RCE (CVE-2026-102489) and privilege escalation (CVE-2026-102490) enabled rapid session hijack and root takeover, with a combined CVSS of 9.4. DIVD contained the intrusion through segmentation but reported volunteer contact data exposure. The group warns users to update to Zammad 7 or take instances offline immediately.
read more β†’

Cisco SD‑WAN Manager zero‑day allows admin access

πŸ”’ Cisco fixed a critical flaw in Cisco Catalyst SD‑WAN Manager that let attackers bypass authentication via improperly handled URI encoding in HTTP requests. The vulnerability, tracked as CVE-2026-76504 with a 9.8 CVSS score, could grant administrative API privileges without credentials. Cisco has patched cloud-managed systems and released fixes for affected on‑prem releases; there is no workaround, so restricting access until upgrades are applied is advised.
read more β†’

CloudSyncD macOS backdoor hidden in fake Zoom installer

πŸ›‘οΈ A new macOS backdoor, CloudSyncD, has been distributed inside a fake Zoom installer that prompts users for their login password before launching an embedded second-stage payload. Jamf Threat Labs first observed development builds on September 15 and identified samples targeting live C2 infrastructure two days later, indicating active deployment. The installer instructs users to bypass Gatekeeper, presents a bogus authorization prompt, and validates the entered password locally before using it to escalate the second-stage payload.
read more β†’

DIVD: Zammad zero-days enabled AI-driven breach

πŸ”’ The Dutch Institute for Vulnerability Disclosure (DIVD) reports its network was compromised via a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. The attacker used an autonomous AI agent to perform session hijacking, remote code execution, and privilege escalation to root in seconds. DIVD, working with Merlon Security, advised users to upgrade to version 7 or take instances offline while investigations continue.
read more β†’

TeamViewer urges immediate patch for severe flaws

πŸ”’ TeamViewer has issued an urgent advisory urging customers to update immediately after disclosing multiple high-severity vulnerabilities in its Full Client and Host software for Windows, macOS, and Linux. The most critical issue is a remote session access control bypass (CVE-2026-92370) that could allow unauthorized remote actions leading to remote code execution. Four other flaws include path traversal, heap overflow, TOCTOU race condition, and improper path validation, which can enable local or remote code execution and privilege escalation. TeamViewer recommends upgrading to version 15.82, noting no evidence of public exploits or active in-the-wild abuse so far.
read more β†’

New Spectre v2 Variant Leaks Linux Root Hash

πŸ›‘οΈ Researchers disclosed a new Spectre v2 variant called Branch Target Reuse (BTR) that can recover root password hashes from Intel-based Linux systems within minutes by exploiting stale branch predictor information after just-in-time (JIT) code reuse. The attack manipulates leftover predictions to trigger transient execution of attacker-controlled instructions, producing cache traces that reveal memory contents. VUSec and Scuola Superiore Sant'Anna reported practical exploits against Linux cBPF and evaluated exposure in SpiderMonkey and GraalVM, leading to CVE-2026-64507 and CVE-2026-64508 and kernel fixes.
read more β†’

Agentic AI and Kubernetes Operator Risks Explained

πŸ” This Unit 42 report examines how Kubernetes operators’ reliance on highly privileged service accounts creates a critical security weak spot, and introduces OperTraitor, an open-source LLM-powered engine that analyzes operator RBAC configurations. The tool compares documented functionality to granted privileges and assigns a normalized risk score, revealing abandoned or overly permissive operators in registries like OperatorHub. Case studies include a High-severity CVE in IBM’s Turbonomic and an overly permissive Datadog operator configuration, and the article offers practical mitigation guidance such as verifying sources, enforcing namespace-scoped operators, and continuously auditing RBAC.
read more β†’

Autonomous agents destroy Azure resources using identities

πŸ›‘οΈ Microsoft warns that an autonomous attacker known as Jadepuffer (Storm-3168) has expanded into Azure, using compromised service principals to enumerate resources, delete cloud assets and harvest credentials. The campaign involved two service principals splitting reconnaissance and destructive duties, with rapid automated actions that deleted storage accounts, a Key Vault, Function App and other resources. After destruction the actors requested storage account keys, raising concerns about recovery and potential future exfiltration. Microsoft urges securing workload identities, enforcing least privilege and protecting backup and recovery controls.
read more β†’

Lunex Stealer abuse of AMD driver escalates threat

πŸ›‘οΈ Ontinue details a four-stage attack chain distributing Psychedelic (LunexStealer) via compromised Ukrainian sites using ClickFix-like CAPTCHA lures. The chain uses bogus MSI installers to deploy LunexLoader, bypass UAC, and leverage a vulnerable AMD Radeon driver (PDFWKRNL.sys, CVE-2023-20598) for BYOVD-based defense evasion before installing a PowerShell-backed native messaging host. The stealer harvests browser credentials, cookies, and desktop and extension cryptocurrency wallets while persisting via registry, scheduled tasks, and a malicious Chrome extension.
read more β†’

Elementor CSRF Flaw Lets Attackers Create Admins

πŸ”’ A CSRF vulnerability in the Elementor WordPress plugin could let an unauthenticated attacker create administrator accounts by tricking a logged-in admin into opening a crafted link. The flaw affects versions 4.3.0 and 4.3.1, which are active on up to 2 million sites. Patchstack reported the issue to Elementor on September 22 and a fix was issued in version 4.3.2 two days later. Users are advised to update immediately to prevent one-click admin account creation attacks.
read more β†’

Unpatched OnePlus flaws let installed apps gain root

πŸ”’ A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app that requests no special permissions. Researcher Rasmus Moorats chained two vendor services to gain root: one that accepts arbitrary calls and injects text into system commands, and another that executes shell instructions when invoked as root. OnePlus confirmed the flaws in May, claimed exclusive control over disclosure, and had not released a patch when Moorats published on September 24.
read more β†’

Critical VeloCloud Orchestrator vulnerability impacts on-prem

πŸ”’ Arista warned of a critical flaw in on-premises VeloCloud Orchestrator that allows remote attackers to access privileged internal functionality and potentially compromise the VSO host. The issue, tracked as CVE-2026-93952 with a CVSS score of 10.0, is actively exploited and affects multiple VCO release trains, though fixes are available only for some versions. Arista recommends immediate upgrades where patches exist and, for those that cannot upgrade, restricting web interface access and monitoring for suspicious indicators of compromise.
read more β†’

Kubernetes YAML can hand over a GCP organization

πŸ›‘οΈ When developers declare cloud resources via Kubernetes GitOps, controllers like Google Kubernetes Config Connector (KCC) act on their behalf using a platform service account. KCC authenticates with Google Cloud through a single service account that may have broad project, folder, or organization-level roles. If a user can create IAM-related resources in a namespace KCC watches, they can escalate privileges by having KCC apply bindings using its powerful account.
read more β†’

Critical cPanel flaws enable root and cross-account access

πŸ”’ cPanel disclosed three vulnerabilities affecting its CalDAV/CardDAV service and the WP Toolkit plugin on September 22. One flaw (CVE-2026-87899) allows any logged-in hosting account to execute code as root, while another (CVE-2026-87900) lets a cPanel user modify databases belonging to other accounts. A third issue (CVE-2026-68490) permits local users to read other accounts' calendars and contacts without altering them. Fixed versions for cPanel & WHM and WP Toolkit have been published, and cPanel provides update instructions but no temporary mitigations.
read more β†’

AI agents reshape identity and access risks

πŸ”’ AI agents change how we evaluate access by turning permissions into exploration paths that can discover credentials and combine identities across systems. Autonomous agents persistently test many actions, often using hard-coded credentials and exploiting trust boundaries, as seen in notable incidents like Hugging Face in July 2026. Security teams must map full access chains, assign ownership, and enforce continuous identity governance to constrain an agent's effective blast radius.
read more β†’

Zyxel and Veeam Flaws Under Active Exploitation

πŸ›‘οΈ CISA added a now-patched Zyxel GS1900 series switch vulnerability (CVE-2026-7273, CVSS 8.8) to its Known Exploited Vulnerabilities list after evidence of active exploitation. The stack-based buffer overflow in the device CGI could permit unauthenticated LAN attackers to execute OS commands; multiple GS1900 firmware versions have fixes. Simultaneously, Arctic Wolf reported active exploitation of a local privilege escalation in Veeam Agent for Windows (CVE-2026-32996, CVSS 7.3) allowing local users to attain SYSTEM privileges via a cached elevated session UID.
read more β†’