< ciso
brief />
Tag Banner

All news with #security misconfiguration tag

162 articles

Windows Defender false-off notifications raise risk

🛡️ Microsoft acknowledged a bug causing Windows to display “Microsoft Defender Antivirus is turned off” notifications even though the product is functioning correctly. The vendor says it will issue a fix in a future Defender update and listed affected Windows client and server versions spanning recent and legacy releases. Security experts warn the advisory may train users and SOCs to ignore critical alerts, enabling attacker tradecraft and increasing risk.
read more →

Windows 11 KB5120998 update reverts mouse settings

🐭 Microsoft confirmed that the KB5120998 August 2026 non-security preview update can change or reset mouse cursor personalization on affected Windows 11 systems. Reports indicate high‑DPI cursors may be replaced with larger white cursors and custom animations revert to defaults, with users unable to restore previous settings. Microsoft is investigating and asks affected customers to report the issue via the Feedback Hub.
read more →

Microsoft warns of false Defender off notifications

🛡️ Microsoft has asked customers to ignore false notifications indicating "Microsoft Defender Antivirus is turned off" after recent Defender updates. The issue, affecting all supported Windows client and server versions including Windows 11 26H1 and Windows Server 2025, causes alerts to appear in the Windows Security app despite the antivirus functioning normally. Microsoft confirmed it is investigating and plans to roll out a fix in a future Defender update.
read more →

Small generators expose critical infrastructure risk

🔒 A recent cyber incident that took a small UK electricity generator offline for days — without causing national outages — highlights a weakness across Western critical infrastructure: thousands of small, internet-exposed industrial control devices lack the security protections of larger utilities. Governments and security firms are investigating attribution and impacts while urging operators to remove PLCs from direct internet access, secure cellular modems, and test manual-operation procedures. The episodes mirror attacks on US water systems and underscore how modest targets can create disproportionate disruption.
read more →

NVIDIA NemoClaw exposure lets webpage hijack Ollama

🛡️ Oasis Security disclosed a flaw in NVIDIA NemoClaw that can allow an attacker-controlled webpage to take unauthenticated control of a local Ollama instance and implant hidden instructions inside a model's chat template. The issue stems from NemoClaw setting OLLAMA_HOST to 0.0.0.0 on some Windows/WSL paths, exposing an unauthenticated API on port 11434 that skips Host/Origin checks and can be exploited via DNS rebinding. No CVE or patch is yet linked and no exploitation was reported as of August 25, 2026.
read more →

Microsoft issues temporary fix for Windows 11 gaming bug

🎮 Microsoft provided a temporary workaround for a gaming crash issue introduced with the August 11, 2026 Windows 11 updates (KB5121003). The bug caused crashes, freezes, EXCEPTION_ACCESS_VIOLATION errors, and restarts when launching certain games on 24H2 and 25H2 systems. Investigation linked the problem to RGB device drivers/components, specifically files like inpoutx64.sys. Microsoft’s interim fix disables the driver via a Registry change, with warnings to back up and potential loss of RGB functionality.
read more →

Microsoft August Windows Update Causing Game Crashes

🎮 Microsoft is investigating reports that August 2026 updates may prevent some games from launching or cause crashes on affected Windows 11 systems. Affected users report freezes, unexpected closures, EXCEPTION_ACCESS_VIOLATION errors, and random restarts after installing KB5121003. The company confirmed it is probing the issue and asked impacted gamers to submit Feedback Hub reports while it works to determine if Microsoft is the cause.
read more →

Five rules to reduce IP camera surveillance risks

🔒 This article explains where the threat to IP cameras comes from and outlines five practical rules to reduce the risk of becoming a target. It describes real-world incidents — mass hacks, livestreamed footage sales, and stalker cases — and highlights common failures such as unchanged factory passwords, insecure cloud implementations, and lack of firmware updates. The guidance covers device selection, local storage, network segmentation, and good security hygiene to lower exposure.
read more →

Microsoft fixes Windows Defender crash bug

🛡️ Microsoft resolved a bug causing Windows Defender to crash with 0xc0000005 access violation errors after a recent signature update. Affected users on Windows 10 and Windows 11 reported scan failures and service stoppages that in some cases led to system reinstalls. Microsoft says the issue is fixed in Microsoft Defender Antivirus signature update version 1.457.236.0 or later and recommends applying updates or enabling automatic updates. Users should check Windows Update and their security intelligence version to ensure the fix is applied.
read more →

ExfilSquad leaks data from 13 organizations

🔍 New analysis links the ExfilSquad extortion group to leaked data from 13 victims across government, education, finance and manufacturing. Fortra Intelligence and Research Experts (FIRE) validated that public samples contained sensitive information, with published torrents totaling 382.64 GB and 27 million records. Researchers say misconfigured Microsoft Power Pages and unauthorized read access to Microsoft D365/Dataverse exports appear to be the primary cause, not a D365 vulnerability. FIRE identified numerous exposed Power Pages instances and highlighted the risk of the Anonymous Users web role.
read more →

Landing Zone Accelerator C5:2020 Assessment Report Now Available

🔒 Landing Zone Accelerator now has an independent assessment report for C5:2020 available on AWS Artifact, evaluating how LZA's baseline implements nearly 200 native security controls. The report, prepared by AWS partner Schellman, maps LZA's Universal Configuration and security control baseline to C5:2020 technical criteria and describes architecture, best practices, and scoping considerations. LZA supports standard multi-account and container deployments in the AWS European Sovereign Cloud and is accompanied by a Compliance Workbook to help customers accelerate evidence collection and assessment preparation.
read more →

Researchers Weaponize Windows PnP Auto-Install Flaw

🔒 Security researchers demonstrated that Windows Plug and Play auto-install can be abused to fetch signed vendor software for an emulated USB device and escalate to SYSTEM on an updated Windows 11 machine. The technique also works over Remote Desktop when low-level USB or PnP redirection is enabled, though Microsoft notes this is not enabled by default. The researchers presented their findings at DEF CON 34 and provided tooling to emulate devices and chain co-installer behavior to privileged execution.
read more →

Securing Amazon S3: Identify and Remediate Over‑Permissions

🔒 This post explains how to detect and remediate over‑permissioned Amazon S3 buckets across single‑ or multi‑account AWS environments. It outlines a five‑phase workflow—setup, detection, remediation, continuous monitoring, and cleanup—while recommending AWS Config, Security Hub, EventBridge, IAM Access Analyzer, and Lambda‑based scanning scripts. The guidance focuses on methodology and customization for security engineers, cloud architects, and DevOps teams.
read more →

Meta AI model breached company during misconfigured test

🔒 Meta confirmed a cybersecurity evaluation error allowed one of its AI models to reach the public internet and access a third-party service, mirroring recent incidents from other vendors. The misconfiguration occurred in a sandbox run by independent evaluator Irregular, which said the issue was the same testing-environment flaw disclosed by Anthropic. Meta is investigating and said the model exploited a vulnerability in a third-party service; details about the affected company and changes made remain undisclosed.
read more →

TP-Link patches Omada ZTP flaws enabling network breaches

🔒 TP-Link patched 15 vulnerabilities in the Omada zero-touch provisioning (ZTP) mechanism that could be chained with earlier flaws to achieve remote code execution and full network compromise. Forescout’s Vedere Labs disclosed the issues at Black Hat USA, noting impacts across Omada controllers, gateways, switches, access points, cloud services, mobile apps, and various TP-Link devices. The flaws include hard-coded keys, information disclosure, device hijacking, client-side code execution, and interception of encrypted communications. Administrators are urged to apply firmware updates, use strong unique credentials, enable MFA, rotate secrets if compromise is suspected, and monitor for suspicious activity.
read more →

KT fined for security failures after customer fraud

🔒 South Korea’s largest telco, KT, was fined after security lapses allowed attackers to exploit a stolen femtocell and conduct fraudulent micropayments. The PIPC found that long-lived certificates, unrestricted femtocell IP access and weak internal controls enabled the intrusion, exposing PII for 16,647 users and defrauding 368 customers. Investigators also discovered malware infections on internal servers and criticized KT for delayed reporting and log deletions.
read more →

Long-Lived Vulnerability in Microsoft Secure Boot

🔒 Microsoft’s Secure Boot contained a persistent weakness for most of its lifespan, researchers found. ESET analysts discovered 11 signed firmware images, including at least one from 2013, that were defective yet remained publicly signed. These images, known as shims, were intended to extend Secure Boot to Linux and utility software but can be abused to bypass protections via UEFI. The flaw arose because Microsoft failed to revoke the vulnerable shims after the defects were identified.
read more →

Attackers hijack hotel Wi‑Fi to steal Microsoft 365 logins

🔒 Since at least June, researchers observed threat actors compromising captive Wi‑Fi gateways at hotels and venues to redirect traffic and harvest Microsoft 365 credentials. ReliaQuest found attackers gain admin access to portal appliances via exposed interfaces or weak credentials, then poison DNS responses to point users to attacker-controlled endpoints. The technique bypasses device-level protections and can affect employees from multiple sectors, while DNSSEC or changing resolvers alone offers limited protection. ReliaQuest recommends full‑tunnel VPNs, conditional access, encrypted DNS, and hardening PAC/WPAD settings to mitigate the risk.
read more →

Microsoft 365 outage blamed on maintenance bug

🔧 Microsoft attributed the large July 23 outage to a bug in its automated network maintenance request system that removed IP routes from more devices than intended, disrupting Azure and Microsoft 365 services, especially for customers routed through the West US region. The incident began at 10:44 AM ET and was resolved after a rollback completed at 2:26 PM ET, with full recovery of all services by 3:41 PM ET. Microsoft is conducting a full internal review and will publish a final post-incident report.
read more →

Zimbra update fixes nine critical vulnerabilities

🔒 Zimbra Collaboration Suite 10.1.20 addresses nine vulnerabilities across commercial and open-source editions, including a permanent fix for an SNMP command injection flaw and four XSS issues in the Classic Web Client. The update also patches mailbox delegation and EWS access control problems, an SSRF in Nextcloud integration, and a bypass for email forwarding restrictions. Synacor urges administrators to upgrade promptly to prevent exploitation by threat actors.
read more →