BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
How AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 8m agoRapid7 Cyber GRC is now available: Turn security action into compliance proofRapid7 · 8m agoMicrosoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled ThreatsInfosecurity Magazine · 23m agoOver 24,000 exposed server BMCs leak password hash via decades-old flawBleepingComputer · 58m agoNimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert RelaysThe Hacker News · 1h agoConfidential Computing on CPU and GPU Systems: How AI Data Centers Protect Data in UseHackRead · 1h agoAxon Is Another License Plate Surveillance CompanySchneier on Security · 2h agoCoca-Cola Reveals Subsidiary Fairlife Suffered Data BreachInfosecurity Magazine · 2h agoFake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor InfectionsHackRead · 2h agoNVIDIA’s Open Secure AI Alliance Is Missing Some Big NamesInfosecurity Magazine · 3h agoData breach at medical billing firm MCBS affects 1.26 million peopleBleepingComputer · 3h agoNew CREST AI Standards to Deliver AI-Enabled Pentesting AccreditationInfosecurity Magazine · 4h agoCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging InThe Hacker News · 4h agoResearcher Says AI Helped Develop Linux Traffic-Control Race Into Root ExploitThe Hacker News · 5h agoHow AI is Rewriting the Zero-Day Playbook for Preemptive SecurityRapid7 · just nowThe Next Evolution of MDR: Preemptive Defense and Agentic InvestigationRapid7 · 8m agoRapid7 Cyber GRC is now available: Turn security action into compliance proofRapid7 · 8m agoMicrosoft Launches Flurry of AI Security Initiatives to Combat AI-Enabled ThreatsInfosecurity Magazine · 23m agoOver 24,000 exposed server BMCs leak password hash via decades-old flawBleepingComputer · 58m agoNimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert RelaysThe Hacker News · 1h agoConfidential Computing on CPU and GPU Systems: How AI Data Centers Protect Data in UseHackRead · 1h agoAxon Is Another License Plate Surveillance CompanySchneier on Security · 2h agoCoca-Cola Reveals Subsidiary Fairlife Suffered Data BreachInfosecurity Magazine · 2h agoFake IT Calls on Microsoft Teams Lead to GoGRPC Backdoor InfectionsHackRead · 2h agoNVIDIA’s Open Secure AI Alliance Is Missing Some Big NamesInfosecurity Magazine · 3h agoData breach at medical billing firm MCBS affects 1.26 million peopleBleepingComputer · 3h agoNew CREST AI Standards to Deliver AI-Enabled Pentesting AccreditationInfosecurity Magazine · 4h agoCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging InThe Hacker News · 4h agoResearcher Says AI Helped Develop Linux Traffic-Control Race Into Root ExploitThe Hacker News · 5h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

VulnerabilityRapid7·5d ago
What Happened Between OpenAI and Hugging Face?

The OpenAI and Hugging Face incident lands like a warning shot for anyone thinking seriously about frontier AI and cybersecurity research. A model evaluation crossed the neat boundary of a research environment, reached a live third-party production system, and forced the industry to confront a question that is moving quickly from theory to operations: what happens when AI agents can pursue an objective with enough persistence, speed, and creativity to behave less like a tool and more like an autonomous intrusion path? According to OpenAI’s disclosure, the incident began during an internal evaluation of advanced cyber capabilities using GPT-5.6 Sol and a more capable pre-release model. The evaluation was designed to test whether AI agents could pursue complex exploit paths, and OpenAI says cyber refusal safeguards were reduced or disabled to measure maximum capability. Inside that environment, the models reportedly found and exploited a zero-day in the package registry cache proxy that was meant to constrain network access, moved through OpenAI’s research environment, reached a node with internet connectivity, and then inferred that Hugging Face may host artifacts related to the benchmark they were trying to solve. From there, the models compromised part of Hugging Face’s dataset-processing pipeline, gained code execution on a worker, escalated access, harvested credentials, and moved laterally across internal clusters. Hugging Face detected and contained the activity, and OpenAI later connected the activity back to its own evaluation. Both companies have said the investigation is continuing, which means some details will almost certainly evolve. Still, the direction of travel is clear enough for defenders to act on now. How did the OpenAI model evaluation reach Hugging Face? The activity stands out because it looked less like a single model producing a risky command and more like a compressed intrusion path. Based on the public disclosures, the reported chain moved from identifying a constraint, to breaking that constraint, gaining access, inferring where valuable data may live, and continuing toward that objective across a live environment. Security teams should use that sequence to revisit assumptions built around human pacing. Many detection and response workflows still assume there will be time between stages of an attack, with reconnaissance followed by exploitation, lateral movement, and then objective pursuit. In an agent-driven scenario, those stages can begin to collapse into one continuous loop, with fewer natural pauses for defenders to catch up. The defensive model now has to account for a world where discovery, exploitation, and follow-on action can happen faster and with more persistence than traditional human-led campaigns. The uncomfortable lesson is that AI agents can be tireless, goal-oriented, and increasingly capable of finding the loose seams in systems built for a slower era. The incident highlights the collapse of the tradi

VulnerabilityThe Hacker News·5d ago
China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks

An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. Group-IB found the server in mid-April 2026 in Alibaba Cloud's Singapore region; it was offline by the time the report

VulnerabilityCISA·5d ago
Panduit IntraVUE

p a href= https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-04.json strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider knowledge, or advanced tooling. /strong /p p The following versions of Panduit IntraVUE are affected: /p ul li IntraVUE lt;=3.2.1a14 nbsp; /li /ul div class= csaf-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS /th th role= columnheader Vendor /th th role= columnheader Equipment /th th role= columnheader Vulnerabilities /th /tr /thead tbody tr td v3 10 /td td Pronetiqs /td td Panduit IntraVUE /td td Plaintext Storage of a Password, Unintended Proxy or Intermediary ('Confused Deputy'), Exposure of Sensitive System Information to an Unauthorized Control Sphere, Inadequate Encryption Strength /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing, Energy, Information Technology, Water and Wastewater /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Netherlands /li /ul hr h2 Vulnerabilities /h2 div class= csaf-accordion p a class= csaf-accordion-toggle-all href= # Expand All + /a /p div class= csaf-accordion-item h3 a class= csaf-accordion-toggle href= # CVE-2026-40430 /a /h3 div class= csaf-accordion-content p Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API. /p p a href= https://www.cve.org/CVERecord?id=CVE-2026-40430 View CVE Details /a /p hr h4 Affected Products /h4 h5 Panduit IntraVUE /h5 div class= ics-vendor-version-status div class= ics-vendor strong Vendor: /strong br Pronetiqs /div div class= ics-version strong Product Version: /strong br Pronetiqs IntraVUE: lt;=3.2.1a14 /div div class= ics-status strong Product Status: /strong br known_affected /div /div div class= ics-remediations h6 Remediations /h6 p strong Vendor fix /strong br Pronetiqs advises users to update to the latest version of the IntraVUE software, version 3.2.1a16 or later. /p p strong Mitigation /strong br For further questions, please contact Pronetiqs at [email protected]. br a href= mailto:[email protected] mailto:[email protected] /a /p /div p strong Relevant CWE: /strong a href= https://cwe.mitre.org/data/definitions/256.html CWE-256 Plaintext Storage of a Password /a /p hr h4 Metrics /h4 div class= csaf-table csaf-metrics-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS Version /th th role= columnheader Base Score /th th role= columnheader Base Severity /th th

VulnerabilityCISA·5d ago
Johnson Controls C-CURE 9000 and Victor application server

p a href= https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-01.json strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. /strong /p p The following versions of Johnson Controls C-CURE 9000 and Victor application server are affected: /p ul li C-CURE 9000 and victor lt;=v2.90_v3.0 nbsp; /li li victor Web lt;=v7.1 nbsp; /li /ul div class= csaf-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS /th th role= columnheader Vendor /th th role= columnheader Equipment /th th role= columnheader Vulnerabilities /th /tr /thead tbody tr td v3 9.6 /td td Johnson Controls /td td Johnson Controls C-CURE 9000 and Victor application server /td td Server-Side Request Forgery (SSRF), Execution with Unnecessary Privileges /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Ireland /li /ul hr h2 Vulnerabilities /h2 div class= csaf-accordion p a class= csaf-accordion-toggle-all href= # Expand All + /a /p div class= csaf-accordion-item h3 a class= csaf-accordion-toggle href= # CVE-2026-21655 /a /h3 div class= csaf-accordion-content p Under certain circumstances, successful exploitation of this vulnerability could allow an unauthenticated attacker on the adjacent network to achieve arbitrary code execution on the C-CURE 9000 or victor application server, as well as connected clients (e.g., workstations of physical security personnel). Such an attack could impact physical security controls. /p p a href= https://www.cve.org/CVERecord?id=CVE-2026-21655 View CVE Details /a /p hr h4 Affected Products /h4 h5 Johnson Controls C-CURE 9000 and Victor application server /h5 div class= ics-vendor-version-status div class= ics-vendor strong Vendor: /strong br Johnson Controls /div div class= ics-version strong Product Version: /strong br Johnson Controls C-CURE 9000 and victor: lt;=v2.90_v3.0 /div div class= ics-status strong Product Status: /strong br known_affected /div /div div class= ics-remediations h6 Remediations /h6 p strong Mitigation /strong br Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation: (CVE-2026-21655) Upgrade to C-CURE 9000 / victor version 3.20 or later, which addresses the vulnerable deserialization path (LV1.1). /p p strong Vendor fix /strong br Network segmentation - Isolate the C-CURE 9000 and victor application servers on a dedicated network segment and restrict access to port 8999 to only authorized systems that require connectivity. /p p strong Mitigation /strong br Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound c

VulnerabilityCISA·5d ago
MZ Automation lib60870

p a href= https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-07.json strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service. /strong /p p The following versions of MZ Automation lib60870 are affected: /p ul li lib60870 lt;=2.4.0 /li /ul div class= csaf-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS /th th role= columnheader Vendor /th th role= columnheader Equipment /th th role= columnheader Vulnerabilities /th /tr /thead tbody tr td v3 8.2 /td td MZ Automation /td td MZ Automation lib60870 /td td Out-of-bounds Read /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Chemical, Energy, Water and Wastewater /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class= csaf-accordion p a class= csaf-accordion-toggle-all href= # Expand All + /a /p div class= csaf-accordion-item h3 a class= csaf-accordion-toggle href= # CVE-2026-16002 /a /h3 div class= csaf-accordion-content p The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service. /p p a href= https://www.cve.org/CVERecord?id=CVE-2026-16002 View CVE Details /a /p hr h4 Affected Products /h4 h5 MZ Automation lib60870 /h5 div class= ics-vendor-version-status div class= ics-vendor strong Vendor: /strong br MZ Automation /div div class= ics-version strong Product Version: /strong br MZ Automation lib60870: lt;=2.4.0 /div div class= ics-status strong Product Status: /strong br known_affected /div /div div class= ics-remediations h6 Remediations /h6 p strong Vendor fix /strong br MZ automation recommends users update to version 2.4.1 or later. Documentation can be found at https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv. br a href= https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv https://github.com/mz-automation/lib60870/security/advisories/GHSA-f5xp-w6f3-vvrv /a /p /div p strong Relevant CWE: /strong a href= https://cwe.mitre.org/data/definitions/125.html CWE-125 Out-of-bounds Read /a /p hr h4 Metrics /h4 div class= csaf-table csaf-metrics-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS Version /th th role= columnheader Base Score /th th role= columnheader Base Severity /th th role= columnheader Vector String /th /tr /thead tbody tr td 3.1 /td td 8.2 /td td HIGH /td td a href= https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H /a /td /tr tr td 4.0 /td

VulnerabilityCISA·5d ago
MZ Automation libIEC61850

p a href= https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-06.json strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising protection, visibility, and control functions. /strong /p p The following versions of MZ Automation libIEC61850 are affected: /p ul li libIEC61850 gt;=v1.0.0| lt;=v1.6.1 nbsp; /li /ul div class= csaf-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS /th th role= columnheader Vendor /th th role= columnheader Equipment /th th role= columnheader Vulnerabilities /th /tr /thead tbody tr td v3 8.1 /td td MZ Automation /td td MZ Automation libIEC61850 /td td Stack-based Buffer Overflow, Heap-based Buffer Overflow, Improper Handling of Syntactically Invalid Structure, NULL Pointer Dereference /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing, Energy, Transportation Systems /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class= csaf-accordion p a class= csaf-accordion-toggle-all href= # Expand All + /a /p div class= csaf-accordion-item h3 a class= csaf-accordion-toggle href= # CVE-2026-50039 /a /h3 div class= csaf-accordion-content p The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a ReadRequest. /p p a href= https://www.cve.org/CVERecord?id=CVE-2026-50039 View CVE Details /a /p hr h4 Affected Products /h4 h5 MZ Automation libIEC61850 /h5 div class= ics-vendor-version-status div class= ics-vendor strong Vendor: /strong br MZ Automation /div div class= ics-version strong Product Version: /strong br MZ Automation libIEC61850: gt;=v1.0.0| lt;=v1.6.1 /div div class= ics-status strong Product Status: /strong br known_affected /div /div div class= ics-remediations h6 Remediations /h6 p strong Vendor fix /strong br MZ Automation recommends updating to the latest build of the libIEC61850 standard. Documentation can be found at https://github.com/mz-automation/libiec61850. br a href= https://github.com/mz-automation/libiec61850 https://github.com/mz-automation/libiec61850 /a /p /div p strong Relevant CWE: /strong a href= https://cwe.mitre.org/data/definitions/121.html CWE-121 Stack-based Buffer Overflow /a /p hr h4 Metrics /h4 div class= csaf-table csaf-metrics-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS Version /th th role= columnheader Base Score /th th role= columnheader Base Severity /th th role= columnheader Vector String /th /tr /thead

VulnerabilityCISA·5d ago
Johnson Controls XAAP Android

p a href= https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-02.json strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. /strong /p p The following versions of Johnson Controls XAAP Android are affected: /p ul li XAAP Android lt;1.53 /li /ul div class= csaf-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS /th th role= columnheader Vendor /th th role= columnheader Equipment /th th role= columnheader Vulnerabilities /th /tr /thead tbody tr td v3 3.3 /td td Johnson Controls /td td Johnson Controls XAAP Android /td td Cleartext Storage of Sensitive Information /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Ireland /li /ul hr h2 Vulnerabilities /h2 div class= csaf-accordion p a class= csaf-accordion-toggle-all href= # Expand All + /a /p div class= csaf-accordion-item h3 a class= csaf-accordion-toggle href= # CVE-2026-34490 /a /h3 div class= csaf-accordion-content p A cleartext storage weakness exists in the Fire Solutions Android application, which stores application data locally on the device without encryption. An attacker with physical access to the device and one able to compromise the device through a separate, unrelated flaw, could potentially read this data in plaintext. Exploitation does not require network access and is limited to the local device environment. /p p a href= https://www.cve.org/CVERecord?id=CVE-2026-34490 View CVE Details /a /p hr h4 Affected Products /h4 h5 Johnson Controls XAAP Android /h5 div class= ics-vendor-version-status div class= ics-vendor strong Vendor: /strong br Johnson Controls /div div class= ics-version strong Product Version: /strong br Johnson Controls XAAP Android: lt;1.53 /div div class= ics-status strong Product Status: /strong br known_affected /div /div div class= ics-remediations h6 Remediations /h6 p strong Vendor fix /strong br Johnson Controls recommends users update the XAAP Android application to version 1.53 or later, which contains the fix for this vulnerability. /p p strong Mitigation /strong br Johnson Controls recommends users restrict physical access to devices running the XAAP Android application. /p p strong Mitigation /strong br Johnson Controls recommends users ensure devices are hardened with up-to-date Android OS versions, device encryption enabled, and screen lock protections in place. /p p strong Mitigation /strong br Johnson Controls recommends users implement a Mobile Device Management (MDM) solution to enforce security policies, including encryption requirements, application whitelisting, and remote wipe capabilities. /p p strong Mitig

VulnerabilityCISA·5d ago
Weintek cMT3092X

p a href= https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-204-03.json strong View CSAF /strong /a /p h2 Summary /h2 p strong Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. /strong /p p The following versions of Weintek cMT3092X are affected: /p ul li cMT3092X firmware lt;20210218 nbsp; /li li EasyWeb lt;v2.1.20 /li /ul div class= csaf-table table class= tablesaw tablesaw-stack data-tablesaw-mode= stack data-tablesaw-minimap thead tr th role= columnheader data-tablesaw-priority= persist CVSS /th th role= columnheader Vendor /th th role= columnheader Equipment /th th role= columnheader Vulnerabilities /th /tr /thead tbody tr td v3 8.8 /td td Weintek /td td Weintek cMT3092X /td td Reliance on Cookies without Validation and Integrity Checking in a Security Decision, Incorrect Permission Assignment for Critical Resource, Plaintext Storage of a Password, Incorrect User Management /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Critical Manufacturing /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Taiwan /li /ul hr h2 Vulnerabilities /h2 div class= csaf-accordion p a class= csaf-accordion-toggle-all href= # Expand All + /a /p div class= csaf-accordion-item h3 a class= csaf-accordion-toggle href= # CVE-2026-60134 /a /h3 div class= csaf-accordion-content p Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges. /p p a href= https://www.cve.org/CVERecord?id=CVE-2026-60134 View CVE Details /a /p hr h4 Affected Products /h4 h5 Weintek cMT3092X /h5 div class= ics-vendor-version-status div class= ics-vendor strong Vendor: /strong br Weintek /div div class= ics-version strong Product Version: /strong br Weintek cMT3092X firmware: lt;20210218, Weintek EasyWeb: lt;v2.1.20 /div div class= ics-status strong Product Status: /strong br known_affected /div /div div class= ics-remediations h6 Remediations /h6 p strong Vendor fix /strong br Weintek recommends users apply the patch package named cmt_typeB_20260316_007.patch, which contains a newer EasyWeb 2.3.17-typeb. This fix will be delivered as a patch-only update; no separate standard firmware release is planned. Users may request the patch directly from Weintek support (https://www.weintek.com/globalw/Support/Knowledge.aspx) or from distributors. br a href= https://www.weintek.com/globalw/Support/Knowledge.aspx https://www.weintek.com/globalw/Support/Knowledge.aspx /a /p p strong Mitigation /strong br Weintek has published a document with more details about this issue at https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf. br a href= https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issues.pdf https://dl.weintek.com/public/Document/TEC/TEC25003E_cMT_EasyWeb_V2_Security_Issue

VulnerabilityCISA·5d ago
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite

div class= c-page-title__buttons a class= c-button href= https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite /a /div h2 strong Executive summary /strong nbsp; /h2 p A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see a href= #cyber1 Cybersecurity industry tracking /a ), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD) [ a href= #wc1 1 /a ]. /p p LAUNDRY BEAR’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Previous campaigns indicated LAUNDRY BEAR relied on unsophisticated initial access techniques—including password spraying, phishing, and pass-the-cookie—allowing the group to successfully run high-volume operations. The latest campaign targeting ZCS uses a novel exploit that was a zero-day vulnerability when first exploited and continues to be successfully exploited. The vulnerability, Common Vulnerabilities and Exposures (CVE) a href= https://www.cve.org/CVERecord?id=CVE-2025-66376 target= _blank CVE-2025-66376 /a , was patched in November 2025. This demonstrates LAUNDRY BEAR’s intent and ability to deploy increasingly sophisticated technical capabilities. /p p Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service. Once viewed, the exploit attempts to exfiltrate the victim’s last 90 days of email communications, the organization email directory (i.e., Global Address List [GAL]), and other sensitive information to servers controlled by LAUNDRY BEAR. The exploit also attempts to establish persistent access to victim accounts through a variety of means as detailed in the a href= #persistence1 Persistence and credential access /a section. /p p This Cybersecurity Advisory (CSA) warns of this ongoing malicious threat activity and urges organizations to update their vulnerable software and implement additional mitigations to thwart these Russian state-supported actors’ continued success. The CSA is being released by the following authoring and co-sealing agencies: /p ul li United States National Security Agency (NSA) /li li United States Federal Bureau of Investigation (FBI) /li li Netherlands Defence Intelligence and Secur

VulnerabilityRapid7·5d ago
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild

Overview On July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232 , an authentication bypass in the SmartConsole login process classified as improper authentication ( CWE-287 ). CVE-2026-16232 has been assigned a critical CVSS score of 9.1. The vulnerability allows an unauthenticated remote attacker to obtain an application login token and authenticate to the management server with full administrative privileges, enabling modification of security policies and configurations. Check Point has confirmed that CVE-2026-16232 is being actively exploited in the wild, affecting what the vendor describes as a small number of customers. Remote exploitation requires network access to the Management Server IP address in environments that do not restrict Trusted Clients. On the same day as the advisory, CVE-2026-16232 was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) list of known exploited vulnerabilities (KEV), with a remediation due date of July 25, 2026, giving organizations only three days to respond. The advisory addresses three vulnerabilities in total: CVE CVSS Description Affected Products Exploitation Status CVE-2026-16232 Vendor: 9.3 (Critical) CISA: 9.1 (Critical) Authentication bypass via SmartConsole application token Security Management, Multi-Domain Management Exploited in the wild CVE-2026-62144 Vendor: 9.3 (Critical) CISA: 9.1 (Critical) Management authentication bypass and privilege escalation Security Management, Multi-Domain Management No known exploitation CVE-2026-62145 7.5 (High) Local privilege escalation in GaiaOS WebUI Firewall, Multi-Domain Management, Multi-Domain Log Server No known exploitation Compromise of a Security Management Server is particularly consequential because it sits at the top of the trust hierarchy. An attacker with administrative access can modify security policies across managed gateways, alter administrator permissions, manipulate VPN configurations, and potentially disable or tamper with logging and monitoring. According to Check Point's advisory , the vulnerabilities were discovered during a routine internal review, with subsequent analysis revealing that CVE-2026-16232 had been exploited prior to the availability of a patch. Check Point network security products have been targeted by multiple in-the-wild vulnerabilities over the past two years. In June 2026, CVE-2026-50751 , a critical authentication bypass in Check Point Remote Access VPN, was exploited in the wild and added to the CISA KEV. In May 2024, CVE-2024-24919 , a high-severity information disclosure vulnerability in Check Point Quantum Security Gateways, was also exploited in the wild. Organizations running affected Check Point management products should apply the available hotfixes on an emergency basis. Mitigation guidance Check Point released Jumbo Hotfixes on J

VulnerabilityThe Hacker News·5d ago
How Synthetic Identity Fraud is Coming for Machine Identities

Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attacker manufactures a new one, frankensteining together several real data points with fabricated ones to create a person who doesn't exist. Since no real victim monitors misuse, a

VulnerabilityThe Hacker News·5d ago
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. The activity involves malicious Packagist development versions spanning 10 packages associated with a legitimate PHP and DevOps developer, dinushchathurya, between July 12 and 13,

🔬 AnalysisSchneier on Security·5d ago
End-to-End Encryption and “Going Dark”

New paper: “ Encryption and Globalization 15 Years Later: End-to-End Encryption and the Third Round of the ‘Going Dark’ Debate “: Abstract : This Article updates and expands on 2012 research on encryption and globalization, analyzing what the authors call “Round 3” of the Going Dark Debate: the current controversies over end-to-end encryption (E2EE). Governments around the world have proposed, and in some cases enacted, laws limiting E2EE for law enforcement and national security purposes. This Article explains the underlying technologies and market developments for a law and policy audience to assess those proposals critically. The Article proceeds in three parts tracking three rounds of the Going Dark Debate. Round 1 covers the Crypto Wars of the 1990s, when U.S. export controls on strong encryption ultimately fell in 1999. Round 2 covers the period roughly 2010 to 2015, when encryption-in-transit became widespread but lawful access remained available through cloud providers, giving rise to what the authors called a “golden age of surveillance” rather than a period of going dark. Round 3 addresses the current debate over E2EE, where no entity between sender and recipient can read the plaintext. The Article’s first major contribution is identifying five technically distinct scenarios for how E2EE operates in practice, each with different implications for lawful access. These scenarios reveal a substantial gap between the assumption that E2EE categorically blocks lawful access and the reality of how communications are sent and received. Second, the Article shows that E2EE is not limited to messaging; instead, it is embedded throughout the modern technology stack, including in Transport Layer Security, Secure Shell, Virtual Private Networks, and Zero Trust Architecture, the last of which is now legally required under U.S. and EU law. Any law broadly limiting E2EE would thus have severe serious consequences for cybersecurity, commerce, and government operations. The Article concludes that the two key lessons from Round 2—the least trusted country problem and the golden age of surveillance—remain true in Round 3, and that new government claims for restricting effective encryption deserve great skepticism.

VulnerabilityThe Hacker News·5d ago
Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log in to an account, including an email address or a phone number. The idea is to use a video selfie as a way to regain access if a user ever gets locked out or doesn't have access