Search/tenable
Vendor

tenable

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
nessus network monitor
Connections
172 relationships
Automox Mitigation Worklets cut endpoint exposure to unpatchable flaws
Automox Mitigation Worklets cut endpoint exposure to unpatchable flaws Automox has announced its AI-speed Mitigation Worklet Pipeline, which automates mitigation to reduce risk from the increased volume and velocity of frontier-model AI vulnerabilities. Now the time from vulnerability disclosure to exposure mitigation is shortened from days or weeks to minutes or hours. Since 2019, Automox Worklets have mitigated risk across billions of policy runs and millions of endpoints. A Worklet is an automation that takes verifiable action on an endpoint, whether that’s enforcing a configuration, installing software, or mitigating a vulnerability. Since most frontier-model vulnerabilities are not immediately patchable, mitigation has become a critical lever for reducing cybersecurity risk. These additions give IT and security teams the speed and confidence to act on unpatchable vulnerabilities that require an endpoint configuration change or temporary workaround. AI-assisted research has enabled vulnerability tools to find more risk than ever before. Patch Tuesday proves it: this week’s release shipped a historic 973 CVEs, the largest on record. But finding isn’t fixing. Teams still lose hours interpreting advisories, writing their own scripts, and testing changes before anything reaches an endpoint. Automox Mitigation Worklets fix that. The automated Automox pipeline evaluates each unpatchable vulnerability and drafts each Worklet with AI, enabling a mitigation to reach the catalog within hours of disclosure. Critically, before anything reaches an Automox customer or the platform’s Worklet catalog, it runs through multiple quality and security checks, including human review and testing. Vetted and human-approved Worklets are published to the Automox Worklet Catalog and searchable by CVE or Mitigations category, but they stay fully under customer control: customers choose which to run, which endpoints to target, and when. “AI is increasing the speed of vulnerability discovery and exploitation, and Automox Mitigation Worklets are designed to close that gap,” said Justin Talerico, CEO of Automox. “AI tooling analyzes the disclosure and generates a fix within minutes or hours. Automox then reviews and tests before release. Customers can then confidently run the mitigation across every endpoint in scope, reducing their exposure faster than ever before.” What’s new AI-speed Automated Vulnerability Mitigation Pipeline Mitigation Worklets: ready-to-use, vulnerability-associated automation for unpatchable configuration changes and temporary workarounds Worklet discovery by CVE or Mitigations category: customers search for an applicable mitigation the same way they search for a vulnerability FixNow for urgent exposure: immediate evaluation and remediation when timing matters Verification through Activity Log and Policy Results: evidence that a mitigation actually executed The automated mitigation pipeline is the latest component of Automox’s full-flex endpoint management platform. As the company moves toward its vision of future-proofing IT and cybersecurity, AI-speed mitigation joins a summer of high-impact launches including its best-in-class MCP server, Canopy Jamf and Intune orchestration, and its Tenable integration. Automox combines patching with flexible endpoint automation, empowering IT and security teams to respond to both patchable and unpatchable vulnerabilities with speed and confidence. Mitigation Worklets are available now to customers with Worklet Catalog access.
helpnetsecurity.comSep 11, 2026extracted
September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor
September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor September 2026 Patch Tuesday is here, with Microsoft delivering another record-breaking number of patches, including those for two vulnerabilities that have been exploited as zero-days. Another “new normal” is the anonymous security researcher Nightmare Eclipse publishing a zero-day proof-of-concept exploit targeting Microsoft software mere hours after Microsoft drops its Patch Tuesday fixes. This time around it’s ShieldCrash, which ostensibly bypasses the patch for CVE-2026-69414 (aka ShieldBreak), a privilege escalation bug in Microsoft Defender (i.e., the Microsoft Malware Protection Engine). The flaws exploited in zero-day attacks CVE-2026-81963, in the Windows Update Stack (the component used for installing Windows updates), affects various Windows 11 versions and Windows Server 2025. Caused by improper link resolution before file access and improper access control, the flaw allows authenticated attackers (with low privileges) to gain SYSTEM privileges on a vulnerable system. Satnam Narang, senior staff research engineer at Tenable, noted that there have been seven privilege escalation flaws in Windows Update Stack since 2022, but this is the first zero-day and the first to be exploited. The flaw was reported by Microsoft’s Threat Intelligence Centre (MSTIC), but details about the attacks in which it was exploited are still not public. Dustin Childs, head of threat awareness at TrendAI’s Zero Day Initiative, says he doubts that the automatic update process itself is compromised, and that it’s more likely that CVE-2026-81963 is being combined with a code execution bug to spread malware or ransomware. CVE-2026-85880 is another privilege escalation (to SYSTEM) bug, in the Windows Advanced Local Procedure Call. It affects Windows 10 and older Windows Server versions (2012, 2016, 2019 and 2022). It was reported by Proofpoint threat researchers but, again, we don’t know how widely it’s been exploited. But, since both of these bugs are being leveraged by attackers, implementing these fixes should be a priority for all organizations. “This class of flaw has historically appeared in post-compromise tooling used by both commodity malware and targeted intrusion operators as a reliable final step from user-mode to kernel-mode control,” CrowdStrike noted. Other vulnerabilities of note According to Childs, organizations should also prioritize patching a cluster of 20 bugs that affect most supported Windows versions and could be classified as wormable. “In each of these cases, a remote, unauthenticated attacker could get arbitrary code execution on affected systems with no user interaction,” he pointed out. “We haven’t seen a global worm in years, but with a DNS flaw [CVE-2026-69730] acting as the spiritual successor to SigRed, that reality could change fast.” CVE-2026-69676, an authentication bypass flaw in Kerberos that could lead to remote code execution, is classified as Exploitation More Likely. “An authenticated attacker with low-level access sends a crafted request and executes code on the server, no user interaction,” Childs explained. “‘The server’ here means a domain controller, and any authenticated attacker means any domain user. So the realistic read is: one phished workstation account, one crafted request, code execution on the DC. That’s a domain-compromise primitive, and Microsoft expects to see it exploited.” Finally, among the more likely to be exploited flaws is also CVE-2026-80093, a privilege escalation vulnerability in Windows Cloud Files Mini Filter Driver. Though successful exploitation of this vulnerability requires an attacker to win a race condition, technical details are already public. The good news is that patches for all of these and the above mentioned actively exploited flaws are all bundled in the cumulative security updates and monthly rollups for the various Windows versions, so applying them fixes them all in one fell swoop. Setting Windows updates aside for a moment, Childs also advises prioritizing updating: Microsoft Exchange Server, to fix a RCE flaw that can be triggered by Exchange Server processing an email with a malicious Visio attachment (CVE-2026-55007) Microsoft SharePoint Server, to fix a variety of bugs Why prioritization matters more than patch counts “One of the most important things to recognize across the recent rise in Patch Tuesday releases is that while the number of vulnerabilities being patched is rising, the number of vulnerabilities that can and will affect most organizations remains quite low,” Narang told Help Net Security. AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles. It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context.” Tyler Reguly, Associate Director of Security R&D at Fortra, says that the huge number of vulnerabilities patched by Microsoft merely shows that the company is being proactive. “We need to remember that these large CVE counts are a good thing as we’re reducing attack surface before attackers get a chance to find and utilize the vulnerabilities. Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence. Until that happens, prioritization is key and gift cards for extra coffee for your admins would likely be appreciated,” he noted. Still, the number of one-off patches has also risen, and he advises organizations to consider whether their processes are designed to handle major changes and potential patching bottlenecks. “Right now, if you are in charge of teams managing patches, you are probably struggling with what to do. Support your team, be aware of the difficulties they face, and ask them how things can be improved,” he commented. “If you still prioritize based on CVSS, you are hurting your organization and your employees. If you are constantly flip-flopping as guidance changes, you are putting your organization at risk and jeopardizing employee happiness. You are essentially steering a ship through rough waters, and you need a steady hand to accomplish that. If you keep the ship on course, your team will be able to do the rest.” Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comSep 9, 2026extracted
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating. Three prominent vulnerability types, namely privilege escalation, remote code execution, and information disclosure, account for nearly 90% of the flaws patched this month. Along with Microsoft's fixes for 25 non-Microsoft CVEs, the update brings the total number of vulnerabilities resolved to 999. September's record-setting security updates come after Microsoft patched 457 vulnerabilities in August, 663 in July, 220 in June, and 161 in May. "At this scale, the challenge is not simply getting through the patch list but knowing what needs attention first," Jack Bicer, director of vulnerability research at Action1, said. "With hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle." The two vulnerabilities that have come under active exploitation are listed below - CVE-2026-85880 (CVSS score: 7.8) - A heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC) that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges CVE-2026-81963 (CVSS score: 7.8) - An improper link resolution vulnerability in the Windows Update Stack that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges "An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system," Microsoft said in an advisory for CVE-2026-85880. "No additional user interaction is required." Adam Barnett, lead software engineer at Rapid7, said all supported versions of Windows receive a patch for CVE-2026-81963, a move that "presumably tightens up controls to prevent the Windows Update Stack from following a malicious link and overwriting a system component with an attacker-controlled imposter." Cybersecurity companies Volexity and Proofpoint have been acknowledged for reporting CVE-2026-85880, while Romain Deperne, an offensive security researcher at Airbus Helicopters, and the Microsoft Threat Intelligence Center (MSTIC) have been credited with the second bug. The Windows maker said it has detected zero-day exploitation efforts targeting the flaws, but did not disclose any specifics as to who is behind them, the scale of such efforts, and if those attacks have successfully breached any victims. Per exposure management and vulnerability assessment platform Tenable, there have been seven privilege escalation flaws in the Windows Update Stack since 2022. However, CVE-2026-81963 is the first zero-day as well as the first to be exploited in the wild. As for CVE-2026-85880, it's the second to be weaponized as a zero-day since CVE-2023-21674, which was addressed in January 2023. The development has prompted the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to add both flaws to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 22, 2026. Some of the other notable flaws patched by Microsoft are as follows - CVE-2026-55007 (CVSS score: 8.1) - A double free vulnerability in Microsoft Exchange Server that allows an unauthorized attacker to execute code over a network CVE-2026-80097 (CVSS score: 8.6) - An improper authentication vulnerability in Microsoft Authenticator that allows an unauthorized attacker to elevate privileges locally CVE-2026-69465 (CVSS score: 8.8) - A missing authorization vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network CVE-2026-65669 (CVSS score: 9.6) - An injection vulnerability in SQL Server allows an unauthorized attacker to elevate privileges over a network CVE-2026-69525 (CVSS score: 9.8) - A use-after-free vulnerability in Windows Remote Desktop Services that allows an unauthorized attacker to execute code over a network CVE-2026-69595 (CVSS score: 9.8) - A use-after-free vulnerability in Windows Services for NFS ONCRPC XDR Driver that allows an unauthorized attacker to execute code over a network CVE-2026-69730 (CVSS score: 9.8) - A use-after-free vulnerability in Windows DNS server that allows an unauthorized attacker to execute code over a network CVE-2026-69829 (CVSS score: 9.8) - A heap-based buffer overflow vulnerability in Windows Shell that allows an unauthorized attacker to execute code over a network CVE-2026-72979 (CVSS score: 9.8) - A use-after-free vulnerability in Windows DHCP Server that allows an unauthorized attacker to execute code over a network According to TrendAI's Zero Day Initiative (ZDI), Microsoft has patched a total of 2,760 security flaws this year alone, indicating how artificial intelligence (AI)-assisted vulnerability discoveries are unlikely to slow down any time soon. "September's Patch Tuesday release marks another turning point in the history of Patch Tuesday, as nearly 1,000 CVEs were patched this month (964), another new record set in 2026," Satnam Narang, senior staff research engineer at Tenable, said in a statement shared with The Hacker News. "To put it into context, this month's Patch Tuesday is nearly a 70% increase over the previous record (569) in July, and it pushes this year's total to over 2,600, which is already more than double the previous record-setting year in 2020 (1,245) with three more months left to go." Despite the massive batch of patches, the number of vulnerabilities that are expected to impact most organizations remains quite low, not to mention the absence of a correlating spike in active exploits so far. Narang added that it's critical for organizations to understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable over the internet, and prioritize remediation based on this risk context. "I think it is safe to say that, as long as Microsoft is playing catch-up on patching vulnerabilities, numbers have lost all meaning," Tyler Reguly, associate director of Security R&D at Fortra, said. "This is not a Microsoft specific problem. We see the same issue with Oracle and other large vendors that are being proactive. We need to remember that these large CVE counts are a good thing as we're reducing the attack surface before attackers get a chance to find and utilize the vulnerabilities. Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence.
thehackernews.comSep 9, 2026extracted
Microsoft breaks Patch Tuesday record with 974-CVE deluge
The vulnpocalypse is upon us, dear reader. Microsoft delivered a record number of patches to address 974 CVEs in its own products this month, including two bugs that Redmond says are already under exploitation. September's record-breaking collection of security updates come after Microsoft served up 421 fixes in August, and 622 in July. We've seen the new normal and we are not impressed. Thanks, but no thanks, AI. In addition to Microsoft’s massive patch drop, Adobe on Tuesday issued 10 bulletins addressing 172 CVEs, including a max-severity vulnerability exploited as a zero day in Magento and its successor product Adobe Commerce. Adobe on Monday shipped a hotfix for this one, tracked as CVE-2026-75650 and named StyleSmuggler, that gives unauthenticated attackers remote code execution. StyleSmuggler If your organization has any type of online shop, prioritize this one first as it’s already being abused to compromise stores, according to e-commerce security shop Sansec. Sansec discovered StyleSmuggler, and reports that attacks started on September 4. Every version of Magento and Adobe Commerce, from 2.4.4 up to and including 2.4.9, has the flaw. The bug allows attackers to inject malicious PHP code inside Magento templates using the “styles” properties to evade safety detections. In confirmed attacks, the payload then installs a backdoor that connects to a command-and-control server and waits for instructions. “So far, we have no indication that the backdoor has been weaponized,” the Sansec Forensics Team wrote. Don’t wait to find out on this one. Put it at the top of your mitigation list. Microsoft's 974 CVEs On to Microsoft’s record-breaking 974 CVEs, which according to Tenable is not many fewer than the 1,130 CVEs Redmond issued in 2025. Two are already being exploited as zero-days. First up: CVE-2026-85880, a privilege escalation bug in Windows Advanced Local Procedure Call (ALPC). Successful exploitation can result in the attacker gaining SYSTEM privileges. “An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system,” Redmond warned. “No additional user interaction is required.” No word yet on who is exploiting this bug, and to what end. The US Cybersecurity and Infrastructure Security Agency on Tuesday added CVE-2026-85880 plus a second Microsoft security hole (and the Adobe Commerce and Magento zero-day) to its Known Exploited Vulnerabilities Catalog, and set a September 22 deadline for federal agencies to fix both new Microsoft bugs and a September 11 deadline to patch the Adobe flaw. The second Microsoft bug found and exploited as a zero-day is CVE-2026-81963, another privilege escalation vulnerability. This one affects the Windows Update Stack. We also have very little detail about this flaw, other than it also allows attackers to gain SYSTEM-level access. “More likely is that this bug is being combined with a code execution bug to spread malware or ransomware,” opined Zero Day Initiative’s Dustin Childs, who advised users to “Patch this one quickly.” While those are the only two (so far) under active exploitation, Childs rated CVE-2026-55007, one of nine Exchange Server flaws disclosed this month, as “the most important” patch for the messaging server. It allows a remote, unauthenticated attacker to execute code on a vulnerable Exchange server by sending an email with a malicious Visio attachment. No user interaction is required, and the code executes when the server processes the attachment during content indexing. Redmond says it’s “difficult to reliably trigger,” but as Childs points out: “The attacker only needs to get it right once. Schedule your downtime and update your Exchange servers with haste.” Childs also said he counts 20 patches for wormable bugs, so be sure to read his full Patch Tuesday review for those. “While some might be more exploitable than others, having 20 of them in a single release is something else.” The missing CVE While Redmond addressed nearly 1,000 security holes this month alone, it’s also worth pointing out one that isn’t this month’s Patch Tuesday roundup: CVE-2026-85046. Google patched this bug in Chrome on September 3, and at the time warned that it “is aware that an exploit for CVE-2026-85046 exists in the wild.” The high-severity, type confusion flaw exists in the V8 JavaScript engine used in both Google’s Chrome and Microsoft’s Edge browsers. And yet Microsoft still hasn’t published a security advisory for CVE-2026-85046. “If you’re patched, you are protected, but if you rely on advisories to know which vulns exist, you could miss this zero-day vulnerability altogether,” Adam Barnett, lead software engineer at Rapid7, told The Register. “A patch without an advisory is perhaps marginally better than an advisory without a patch, but keeping track of exposures without reliable advisory materials is not straightforward,” Barnett said. “Chrome patched 11 other vulnerabilities at the same time as CVE-2026-85046, but it’s not yet clear if those are patched in Edge. Until Microsoft sets the record straight, the only safe assumption is that these vulnerabilities (e.g. CVE-2026-85045) remain unpatched in Edge.” ®
theregister.comSep 9, 2026extracted
Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited Microsoft’s latest Patch Tuesday release broke another record this month, surpassing 900 vulnerabilities for the first time. The federal cyberdefense agency, CISA, confirmed that two of them — CVE-2026-81963 and CVE-2026-85880 — are being exploited by hackers. Federal agencies have until September 22 to patch them. Tenable’s Satnam Narang said CVE-2026-81963 relates to a component used to install Windows updates and CVE-2026-85880 affects a messaging system in Windows. More than 22,000 corporate Exchange servers are unpatched against weaponized exploit code, according to Nightwing cybersecurity expert Nick Carroll. Others explained that bugs like CVE-2026-81963 are the first step in a ransomware chain where hackers phish one user and use their access to gain escalated privileges. “The component makes it worse. An attacker who owns the update stack owns the thing you'd use to evict them,” Automox engineer Serena DiPenti said. “If you can't say when the update stack last ran, you can't say whether it's patched.” The two are among 973 bugs disclosed on Patch Tuesday by Microsoft. The company set a previous record in July with fixes for more than 600 security vulnerabilities — which itself was triple the size of the previous record set the month before. Cybersecurity researchers and defenders have warned for months that the use of artificial intelligence code-review tools would prompt an onslaught of minor vulnerabilities that could be chained together for dangerous attacks. Narang noted that the latest Patch Tuesday release pushes the year’s total bugs disclosed over 2,600, which is already more than double the previous record-setting year of 2020. Qualys cybersecurity expert Diksha Ojha added that another vulnerability announced by Adobe this month was a critical-severity bug in Adobe Commerce. Jonathan Greig is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
therecord.mediaSep 8, 2026extracted
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month. Image: Shutterstock.com, Kirill Makarov. This month’s patch bundle obliterates the software giant’s previous record set in July , when it released updates for at least 570 security vulnerabilities. September’s Patch Tuesday brings this year’s total to more than 2,600, more than twice Microsoft’s previous record-setting patch year in 2020 (1,245) and with three more months to go. There are two “zero-day” flaws fixed this month that are being actively exploited: both CVE-2026-81963 and CVE-2026-85880 allow an attacker to elevate their privileges on Windows system. Fully 113 of the bugs addressed today earned Microsoft’s “critical” rating, meaning they could be abused by malware or miscreants to seize control over a vulnerable Windows machine with little or no help from the user. Among the more serious critical flaws this month is CVE-2026-69730 , a DNS weakness present in Windows Server 2012 onward and on Windows 10. Microsoft warns that an unauthenticated attacker could leverage this weakness simply by sending a specially crafted packet to an affected system, and that it is likely to be exploited. Also scary is CVE-2026-69829 , a critical, remote code execution flaw in the Windows Shell. This vulnerability has a CVSS base score of 9.8 (10 is the most severe), and can be exploited with low attack complexity, no privileges, and no user interaction. Microsoft’s summary of the security updates released today. Image: msrc.microsoft.com. Microsoft is hardly alone in shipping monster patch bundles lately. Many other large software companies, including Adobe, Cisco, Google, Mozilla and Oracle, all have recently credited AI-assisted research with increasing their patch cadence and volume (Google said today it is now going to ship security updates every two weeks). Tyler Reguly , associate director of security research and development at Fortra , said one core challenge with deploying Windows updates is that they need to be tested before being installed across an organization because not all third-party software works seamlessly in the face of changes to the underlying operating system. “It’s time to put our CISOs and CSOs on notice,” Reguly said. “How are you helping your teams through these difficult times? Do you have your teams deploy after hours and on weekends to avoid disruption to the business environment? Do you reward them for that effort? Time to dig into your budget and buy dinner for your teams that are working on Saturday to get patches rolled out before users return to work on Monday.” Satnam Narang is senior staff research engineer at Tenable . Narang said it’s important to recognize that while the number of vulnerabilities being patched by Microsoft is rising, the number of flaws that can and will affect most organizations remains quite low. “AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles,” he said. “It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context.” Of course, regular Windows users don’t need to test patches before deploying them, but they still need to open Windows Update periodically or else assent to the program’s nag notices about pending updates. And at the rate these Windows patch releases are ballooning in size, it’s probably best not to let them pile up month after month. Enterprise Windows admins will want to keep an eye on askwoody.com for news of any updates that appear to be causing problems. As always, the SANS Internet Storm Center has a per-patch breakdown ordered by severity and urgency.
krebsonsecurity.comSep 8, 2026extracted
Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
Microsoft on Tuesday rolled out a record number of patches, fixing 974 CVEs across its products, including two vulnerabilities exploited in the wild as zero-days. The first exploited zero-day, CVE-2026-85880, is a heap buffer overflow issue in the Windows Advanced Local Procedure Call (ALPC) that could allow a local attacker to gain System privileges. “An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system. No additional user interaction is required,” Microsoft notes in its advisory. Microsoft has not patched an ALPC flaw since April 2023, and CVE-2026-85880 is the second zero-day in the component to be resolved in nearly four years, after CVE-2023-21674 in January 2023, Tenable senior staff research engineer Satnam Narang points out. The second zero-day, CVE-2026-81963, is an improper link resolution before file access (‘link following’) defect in Windows Update Stack, the components used for Windows update installation. The vulnerability also allows local attackers to elevate their privileges to System. As Narang notes, this is the first Update Stack security weakness to be flagged as a zero-day of the seven flaws resolved in the component over the past five years. Overall, Microsoft rolled out patches for 723 flaws in Windows and fixed 222 security bugs in its Office suite, including 111 in Office 2016 for this month’s Patch Tuesday. Multiple security issues were also addressed in SQL (62), Developer Tools (22), SharePoint Server (16), Azure (12), Skype for Business (10), and Exchange Server (9). Also as part of its September 2026 Patch Tuesday updates, Microsoft rolled out fresh Servicing Stack Updates (SSU), which are classified as critical updates. They apply to Windows Server 2012, Windows Server 2012 R2, and Windows 10 Version 1607/Server 2016. Some of the issues that deserve special attention include CVE-2026-55007 (remote code execution (RCE) in Exchange Server), CVE-2026-80097 (elevation of privilege (EoP) in Authenticator), CVE-2026-69465 (RCE in SharePoint, CVE-2026-65669 (EoP in SQL Server), and CVE-2026-69525 (RCE in Remote Desktop Services), ZDI’s Dustin Childs says. According to Childs, 20 of the newly resolved vulnerabilities could be considered wormable, as they enable RCE without authentication or user interaction. “One of the most important things to recognize across the recent rise in Patch Tuesday releases is that while the number of vulnerabilities being patched is rising, the number of vulnerabilities that can and will affect most organizations remains quite low,” Narang said. “AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isn’t finding more needles. It’s critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context,” he added. According to Fortra associate director Tyler Reguly, the large number of newly released patches, which is not a Microsoft-specific trend, shows that proactive vendors are keen on reducing the attack surface. “Eventually, all those long-standing, hard to find vulnerabilities will be fixed and Patch Tuesday will return to its typical cadence. Until that happens, prioritization is key and gift cards for extra coffee for your admins would likely be appreciated,” Reguly said. Related: Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day Related: The Hidden Instructions That Can Hijack AI Agents Related: SAP Patches Critical Extended Passport Processing Vulnerability Related: MikroTik Patches Critical Flaws Chained to Hack Routers
securityweek.comSep 8, 2026extracted
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have kept up with the patches. Read the full recap for the week’s major developments, plus more research, attacks, and security news beyond what we covered last week. ⚡ Threat of the Week N-able Patches Critical N-central Flaws — N-able has released hotfixes to address two severe N-central flaws (CVE-2026-86206 and CVE-2026-86207) that could allow an unauthorized party to bypass authentication controls and gain full access to the platform. Also patched is a maximum-severity security flaw (CVE-2026-86218, CVSS score: 10.0) that could allow for pre-authenticated remote code execution on the N-central server. "At this time, we have no confirmation that these vulnerabilities have been exploited in production environments, but unpatched systems remain at risk," N-able said. However, Huntress said it observed signs that attackers are likely leveraging CVE-2026-86206 or/and CVE-2026-86207, after it launched an investigation on September 4 following the compromise of a customer's fully patched N-central production environment. "However, due to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities," it said. AI Spend Out of Control? There's a Path Forward Imagine you’ve received a water bill for 500,000,000 gallons. Now, you have to account for every teaspoon of that water. IT leaders face a similar task when managing AI budgets, and it’s not as simple as token caps or model limits. Learn how your team can optimize your company's AI spend. Learn More ➝ 🔔 Top News Google Warns of Chrome 0-Day Under Attack — Google released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," according to a description of the flaw in CVE.org. Security researcher Salvatore Gulizia (aka Serotav) has been credited with discovering and reporting the flaw on August 4, 2026. As is usual in these cases, Google acknowledged that an "exploit for CVE-2026-85046 exists in the wild," but did not reveal any details about the nature of the attacks or who is behind them. With the latest development, Google has addressed a total of six actively exploited Chrome zero-days since the start of the year. MikroTik RouterOS Flaws Exploited — The CERT Polska Team warned that bad actors are actively exploiting two zero-day flaws in MikroTik RouterOS that could be combined to take full control of the device without authentication if the device supports remote access using the SSH protocol. The exploit chain has been codenamed MikroTrick. A total of fix flaws (CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, and CVE-2026-86060) have been identified. The MikroTrick chain involves CVE-2026-67276 and CVE-2026-86060 (CVSS scores: 9.2), which can allow an attacker to bypass authentication and elevate their privileges. The issues have been fixed in versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable). "The successful attacks observed so far, including the creation of the 'ops' account, originated from the IP address 82.192.72.4 and have been occurring since at least 2 September," CERT Polska said. "In addition, the IP address 103.102.31.18 was used in attempts to exploit the described chain." Unpatched Magento and Adobe Commerce 0-Day Exploited to Backdoor Online Stores — E-commerce storefronts are being compromised to inject a backdoor by exploiting an unpatched Magento and Adobe Commerce zero-day dubbed StyleSmuggler, which gives unauthenticated attackers remote code execution. The attacks commenced on September 4, 2026. "StyleSmuggler injects malicious code into Magento's template system," Sansec said. "By using the styles properties, it can evade existing safeguards. It works in two stages: (1) Inject (poison) PHP code, for example by generating a failure report, and (2) Let Magento execute the poisoned code via a failed payment email." The backdoor is a Rust program that connects to the "99.84.67[.]186" C2 server and waits for further instructions. There are currently no indications that the backdoor has been weaponized. There are two different variants named fc-cache and chronyd. A separate attack cluster has been found to leverage the same weakness to drop a PHP web shell into the product image cache. RevStealer Spreads via Game Cheats and Fake Claude Desktop App — Elastic and Morphisec disclosed details of RevStealer (aka REF2859), a Windows information stealer that comes with an embedded sandbox scoring system and Polygon blockchain-based dead drop for resilience, a technique also called EtherHiding. "Beyond credential theft, REVSTEALER targets gaming platforms for additional monetization; the developer clearly understands that victim accounts on these platforms hold real monetary value in resale markets," Elastic said. The malware is distributed via social engineering attacks, using YouTube videos claiming to advertise hacks for the Albion Online game or rogue GitHub repositories for Anthropic's Claude Opus 5 Free Desktop project. Once installed, the stealer can receive additional executable content through C2 tasks, including additional executable content through (for wallet-file and browser-extension theft, phishing overlays, password-aware input capture, and payload delivery), WinUpdate (for cryptocurrency-address replacement and mnemonic-shaped clipboard theft), SoftManager (for reverse SOCKS5 proxy and backconnect access over an encrypted WebSocket protocol), and LockAppHost (for XMRig deployment, competitor suspension, and persistence). OpenAI Agents Keep Going Rogue — OpenAI is once again in hot water after a swarm of agents self-identifying as from the AI startup hijacked a German website as early as May and used it as a bulletin board for other AI agents. The agent swarm is said to have taken over the obscure German-language wiki in May and June to make around 18,000 posts, relying on it to coordinate on evaluations and swap methods to evade OpenAI’s own controls. The revelations come days after OpenAI published its own detailed account of July's Hugging Face breach in which another swarm of OpenAI agents worked together to escape their sandbox during a cybersecurity evaluation and break into Hugging Face's servers. A subsequent cluster used similar techniques to break into OpenAI's own infrastructure. In response to the wiki incident, OpenAI said it is working on a framework for reporting misalignment incidents during training, evaluation, and deployment. ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-78174, CVE-2026-19313, CVE-2026-19318, CVE-2026-19315, CVE-2026-57910, CVE-2026-57909, CVE-2026-13086 (WatchGuard), CVE-2026-80047 (Hugging Face Transformers), CVE-2026-9585, CVE-2026-9586, CVE-2026-9587, CVE-2026-9588 (Sangoma Switchvox SMB), CVE-2026-6881 (Ellucian Advance Web and Legacy Advance), CVE-2026-13381, CVE-2026-13380 (VSee Clinic), CVE-2026-63219, CVE-2026-58400 (GeoNetwork), CVE-2026-9637, CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625, CVE-2026-19471, CVE-2026-19472, CVE-2026-12663, CVE-2026-9633, CVE-2026-9634, CVE-2026-16675, CVE-2025-12768, CVE-2026-84235 (Rockwell Automation), CVE-2026-84115 (Cleo Harmony), CVE-2026-84117, CVE-2026-84118, CVE-2026-84119, CVE-2026-84120, CVE-2026-84121, CVE-2026-84122, CVE-2026-84123, CVE-2026-84124, CVE-2026-84125, CVE-2026-84126 (Mozilla Firefox), CVE-2026-84353, CVE-2026-84352, CVE-2026-85046 (Google Chrome), CVE-2026-19949 (All-in-One WP Migration and Backup), CVE-2026-20277, CVE-2026-20278, CVE-2026-20280, CVE-2026-20279, CVE-2026-20276, CVE-2026-20275, CVE-2026-20274, CVE-2026-20212 (Cisco), CVE-2026-15630 (Casdoor), CVE-2026-73749 (Hewlett Packard Enterprise ArubaOS-CX), CVE-2026-67394 (Plesk), CVE-2026-38577 (Tenda), CVE-2026-6471 aka PostGREShell (PostgreSQL), CVE-2026-42038 (Axios), CVE-2026-64532, CVE-2026-64533 (Linux Kernel), CVE-2026-58048 (cPanel and WHM), CVE-2026-14540 (Google mcp-toolbox), CVE-2026-84645, CVE-2026-84647, CVE-2026-84648, CVE-2026-84649, CVE-2026-84650, CVE-2026-84652, CVE-2026-84665, CVE-2026-84667, CVE-2026-84668, CVE-2026-84669, CVE-2026-84670, CVE-2026-84671, CVE-2026-84672, CVE-2026-84673 (Jenkins), GHSA-x7v6-xfx3-52j6, GHSA-r7jx-j9h7-j4xj, GHSA-9jcm-x588-gh26, GHSA-6mpx-c8rj-whj5, GHSA-q65v-4w7q-hx3r (FreeRDP), CVE-2026-59346, CVE-2026-59347 (Broadcom VMware Workstation and Fusion), CVE-2026-67276, CVE-2026-67277, CVE-2026-67278, CVE-2026-67279, CVE-2026-67281, CVE-2026-86060 (MikroTik RouterOS), CVE-2026-13181, CVE-2026-13182, CVE-2026-13183, CVE-2026-13184, CVE-2026-13185, CVE-2026-13186, CVE-2026-13190 (Telerik UI for ASP.NET AJAX), CVE-2026-86218, CVE-2026-86206, and CVE-2026-86207 (N-able N-central). 🎥 Cybersecurity Webinars A New Vulnerability Drops. Learn How to Find Out ”If You’re Exposed” Faster → Your security tools have the data. Getting an answer shouldn’t take days. See how Tines brings software, cloud, application, and vulnerability data into one dashboard—and learn how to give your team a faster, clearer view of what’s at risk. Find Which Vulnerabilities Attackers Can Actually Exploit—in Hours, Not Weeks → A vulnerability alert doesn’t tell you whether an attacker can break in. Learn how to test exploitability with real-world attack simulations, identify the gaps that matter, and focus remediation on proven risks—not just severity scores. 📰 Around the Cyber World New Knight Office Microsoft 365 AitM Phishing Kit — A new adversary-in-the-middle (AiTM) phishing toolkit called Knight Office has been spotted in the wild using Docusign-themed lures to direct victims to fake landing pages for AitM token theft and device code phishing attacks, joining the likes of EvilTokens and Kali365. The email "led the victim through a number of redirects (including a redirect via the Monday work management platform and a compromised Joomla website)," Huntress said. "The victim landed on a phishing page, where their valid session tokens were captured and fed to the Knight Office console. Session tokens allow attackers to access victim accounts as if they were logged in, without needing an actual password or a way to bypass multi-factor authentication (MFA)." At least nine total phishing attacks on identities have been linked to this kit over the past two weeks. The Blind Spot in SNMPv3 — SNMPv3 — the protocol widely regarded as the secure standard for managing routers, switches, and firewalls — leaks pre-authentication signals that can allow an unauthenticated remote actor to identify a device’s vendor, confirm valid usernames, and narrow its likely encryption settings before testing a single credential. Validated across approximately 470,000 internet-exposed endpoints, the findings show how these standards-compliant behaviors can collapse a multi-dimensional brute-force problem into a focused password-guessing exercise. "SNMPv3 was the industry's answer to insecure network management, and upgrading to it — as the CISA advisory urges — is necessary," said Kobi Ben-Naim, Co-Founder and CEO of Malanta. "But that answer is incomplete. The protocol does exactly what it was designed to do, and that design hands attackers a roadmap: even properly upgraded deployments, when exposed, leak enough through pre-authentication responses to help an attacker narrow their way in before a single credential is tested. The threat doesn't end with the upgrade." U.S. Announces Reward for Senior Iranian Official — A $10 million reward has been posted by the U.S. State Department for information on the whereabouts of senior Iranian official Amir Yaryab. Yaryab allegedly leads the Islamic Revolutionary Guard Corps' (IRGC) Cyber-Electronic Command (CEC). "Yaryab also oversees and controls operations conducted by IRGC-CEC-affiliated groups such as CyberAv3ngers, Dadeh Afzar Arman (DAA), and Mehrsam Andisheh Saz Nik (MASN). These malicious cyber groups have used malware to target civilian infrastructure worldwide," the State Department said. Attack on Coder — Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code to harvest environment variables, API keys, CI/CD credentials, configuration secrets, terminal history, OIDC tokens, SSH keys, external authentication tokens, and Coder database passwords. The data was then exfiltrated to the lookalike domain "coder-infra[.]com." "An unidentified malicious actor gained access to Coder’s Cloudflare infrastructure and added unauthorized IP addresses to the pool used for Coder’s module registry," Coder said. "These unauthorized IP addresses hosted a version of Coder's registry that contained artifacts which included malicious code." Users are advised to look for connections to the malicious domains before applying the latest patches (versions 2.37.0, 2.36.4, 2.35.7, and 2.34.9) U.S.-U.K. Team Up to Shut Down Scam Centers — The U.S. and the U.K. signed a Memorandum of Understanding (MoU) to work together on an initiative to shut down scam centers stealing billions of dollars through investment and romance fraud schemes. "Under the terms of the MOU, each will conduct parallel investigations into common targets, share information on targeting of organized crime syndicates, discuss which jurisdictions to bring specific cases of common interest, and generally prioritize cases on this threat to achieve mutual results," the U.S. Justice Department said. Tampered Exodus Installer Delivers Modular RAT — Victims are being tricked into running a fake PDF document or a software update that leads to the execution of an MSI installer that declares itself a "Background Service" by Apple. "The 'Background Service' installs a genuine Exodus 24.33.4 cryptocurrency wallet, missing one key function: any way for the user to interact with it," Huntress said. "Only 3 of its 1,973 files differ from the real thing. One of those three files stops the wallet from ever drawing a window. Another turns a legitimate Exodus source file into a PE loader that decrypts a 10 MB payload and maps it into memory by hand, where it never touches disk. That payload is the RAT: a hidden VNC and SOCKS proxy that enable remote access and browser credential theft. While the RAT stealthily beacons to Azure Table Storage rather than a domain of its own, it returns every hour through a scheduled task, leaving behind detectable artifacts." QR Phishing With No Image — In a new phishing attack detailed by Kaspersky, threat actors are building a QR code out of text characters and markup directly in the email body as opposed to rendering an image. "There is no attachment to open, no embedded picture to decode, and nothing for an image-based or optical-character-recognition (OCR) scanner to key off," PhishU said. "Because it is markup and not a remote image, an inbox with images turned off still paints it. The message shows a perfectly scannable QR to the human reading it, image-blocking and all." Apple Hit With $2.7 Billion Lawsuit Over App Tracking Rules — Apple is facing a £2 billion ($2.7 billion) lawsuit in the U.K. accusing it of imposing stricter App Tracking Transparency rules on third-party developers than on its own advertising services, thereby giving its ecosystem a competitive advantage, according to Reuters. Apple's App Tracking Transparency feature has been the subject of extensive investigations across Europe. Last month, Apple agreed to make changes to the feature across almost all European Union countries following a probe in Germany. Attackers Routinely Target Edge Devices — A joint analysis from SentinelOne and Tenable found that both nation-state and criminal threat actors are focusing on vendors and susceptible points in the attack surface more than specific CVEs. "Both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure," the companies said. "The exposure picture is flatter than the headlines suggest: Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack on container-grain exposure (25%) — well behind F5 (54%) and in a tight 10-point band with Check Point, Ivanti, and Citrix. 54% of customer environments running F5 products have at least one exposed, actively-exploited CVE; Citrix customers show the slowest remediation patterns at 461 days median time to patch." The disclosure comes as current attacker timelines are compressing and moving faster than standard patch cycles can address, driven by frontier AI models that narrow the window between vulnerability discovery and exploitation. The Threat of Indirect Prompt Injection — New research from Forcepoint revealed that an email summarizer running an unguarded LLM pipeline can be manipulated through indirect prompt injection (i.e., hidden instructions in an email) to silently hijack summarizer output and generate false and potentially dangerous summaries without signaling tampering to the recipient. It's the latest example of how attackers can use indirect prompt injections to undermine AI systems and get them to behave in unintended ways when processing external content. It's also a reminder of AI's fundamental limitations. Large language models (LLMs) cannot distinguish between authentic user instructions entered directly into a prompt and content they find on untrusted third-party sources, leading to prompt injections. "A regular Outlook email composer does strip styling that hides elements on copy/paste and does not provide any way to hide text other than white text on white background," Forcepoint said. "The hidden styling was not stripped when sent programmatically, or when the message is received and displayed. Hidden HTML tags like these have been commonly used by attackers to circumvent careful reading by victims." Conclusion Trusted sources and safer settings still have limits. This week’s attacks show why it matters to know exactly what each protection covers—and what it leaves exposed. Keep patching, but keep the logs needed to investigate, too. “Fully patched” tells you which fixes are installed. It doesn’t prove nobody got in.
thehackernews.comSep 7, 2026extracted
Server Exchange, cinque scudi per la posta elettronica
La diffusione delle email e dei server di posta elettronica sono funzionali alla comprensione della multidisciplinarietà della cyber security. Va preso in considerazione che la sicurezza di un server Exchange non è garantita da un solo prodotto o servizio e per quanto più tecnologie possano essere usate in sinergia, avranno un effetto ridotto se il server è obsoleto o amministrato senza una strategia coerente. Questo assunto vale per qualsiasi dispositivo o software di un’infrastruttura ICT. Un server Exchange installato nell’infrastruttura aziendale (on-premise) permette agli utenti di consultare la posta e dialoga con Active Directory, il sistema che gestisce identità e autorizzazioni nella rete Windows. Può quindi essere contemporaneamente un archivio di informazioni sensibili, un servizio esposto all’esterno e un punto di accesso ai sistemi interni, anche se il traffico proveniente da internet può essere instradato attraverso un gateway o un Edge Transport Server. Indice degli argomenti Un server Exchange on-premise, cioè installato e gestito direttamente dall’organizzazione, è bersaglio prezioso. Una vulnerabilità nell’interfaccia web, nei servizi di autenticazione o nei componenti che elaborano le richieste può consentire di leggere le caselle, sottrarre credenziali, installare una web shell – una porta di accesso nascosta nel server – oppure muoversi verso altre macchine della rete, il cosiddetto movimento laterale. Il problema non è soltanto teorico. Nel 2021 le vulnerabilità note come ProxyLogon hanno permesso di colpire migliaia di organizzazioni. A posteriori è stato ricostruito che gli aggressori hanno potuto accedere ai server locali, leggere le caselle e installare strumenti utili a mantenere nel tempo il controllo dell’infrastruttura. Altre vulnerabilità sono state indicate con i nomi ProxyShell e ProxyToken. ProxyShell era una catena di tre vulnerabilità che poteva portare all’esecuzione remota di codice e all’installazione di web shell. ProxyToken consentiva invece ad attaccanti non autenticati di aggirare alcuni controlli di autenticazione e ottenere accesso a funzionalità amministrative del server. Il dato più significativo arriva dal Data Breach Investigations Report 2026 di Verizon, report secondo il quale lo sfruttamento delle vulnerabilità software è all’origine del 31% delle violazioni prese in esame. La posta elettronica viene spesso trattata come uno strumento di comunicazione, ma nelle organizzazioni svolge almeno tre funzioni più profonde. È una memoria informale nella quale rimangono decisioni, contratti, pareri, fatture e negoziazioni. È un sistema di identità, perché molti servizi affidano proprio all’email il recupero delle password e la conferma delle operazioni. È, infine, una rete di fiducia, perché un messaggio proveniente da una casella conosciuta viene normalmente considerato più credibile di una comunicazione arrivata da uno sconosciuto. Questo al netto delle campagne di phishing che, però, sono discorso parallelo. Compromettere una mailbox va oltre l’entrare in possesso di documenti, è il contesto necessario per imitarne il legittimo proprietario. L’aggressore può ricostruire rapporti gerarchici, fornitori, abitudini linguistiche, scadenze e flussi di pagamento. Può attendere il momento più opportuno, inserirsi in una conversazione reale e chiedere di modificare un conto corrente o aprire un allegato apparentemente coerente con il lavoro in corso. Queste frodi, chiamate Business Email Compromise (BEC) hanno comportato un’esposizione economica dichiarata di circa 55,5 miliardi di dollari (48,15 miliardi di euro circa) nel periodo tra ottobre 2013 e dicembre 2023, come sottolinea il Federal Bureau of Investigation. (FBI) La fragilità dell’email nasce da un paradosso. L’attendibilità di un mittente dipende dalla fiducia accumulata nel tempo, ma la stessa fiducia può trasformarsi in un’arma quando la casella, il dominio o il server vengono compromessi. La sicurezza di Exchange non protegge soltanto i messaggi. Protegge la possibilità di attribuire una comunicazione alla persona che l’ha effettivamente inviata e, quindi, di continuare a fidarsi delle relazioni digitali su cui si basa il lavoro quotidiano. Nel 2026 non si può affrontare la sicurezza di Exchange ignorandone il ciclo di vita. Exchange Server 2016 e 2019 hanno raggiunto la fine del supporto il 14 ottobre 2025. Microsoft distribuisce ancora determinati aggiornamenti di sicurezza alle organizzazioni ammesse al programma Extended Security Update, ma si tratta di una soluzione transitoria. La versione on-premise corrente è Exchange Server Subscription Edition, pubblicata il primo luglio 2025 e gestita attraverso il Modern Lifecycle: per rimanere supportato, il sistema deve essere mantenuto costantemente aggiornato. Il 14 luglio 2026 Microsoft ha pubblicato nuovi aggiornamenti di sicurezza per Exchange, distinguendo Exchange Server Subscription Edition dalle vecchie versioni 2016 e 2019 coperte soltanto dal programma di aggiornamenti estesi. Non è un dettaglio di poco conto, perché un reverse proxy può filtrare alcune richieste, uno scanner può segnalare una vulnerabilità e un sistema Endpoint Detection and Response (EDR) può riconoscere un comportamento anomalo, ma nessuno di questi strumenti può correggere definitivamente il codice vulnerabile di un prodotto abbandonato. La guida congiunta pubblicata nel 2025 da NSA, CISA, FBI e altre agenzie internazionali raccomanda di mantenere aggiornati i sistemi supportati e di migrare da qualsiasi versione non più supportata a Exchange Server Subscription Edition o a un altro servizio di posta ancora mantenuto. Mettere in sicurezza Exchange non significa soltanto bloccare le richieste malevole, significa anzitutto diminuire il numero di componenti che possono essere interrogati dall’esterno. La porta 443, utilizzata dal traffico web cifrato, è necessaria per Outlook sul web e per diversi protocolli di accesso remoto. La porta 25 serve invece al trasporto dei messaggi mediante SMTP, il protocollo che instrada la posta tra i server. Non tutto ciò che funziona attraverso queste porte deve però essere pubblicamente disponibile. L’Exchange Admin Center, la console web di amministrazione, e PowerShell remoto non dovrebbero essere raggiungibili indiscriminatamente da internet. Microsoft documenta sia la possibilità di disabilitare l’accesso esterno alla console amministrativa, sia l’impiego delle Client Access Rules per limitare le connessioni in base all’indirizzo IP, al protocollo e al tipo di autenticazione. Un reverse proxy inserito tra internet ed Exchange può terminare la connessione esterna, verificare la richiesta e aprirne una nuova verso il server interno. Se dotato delle relative funzioni, può inoltre applicare autenticazione preventiva, limitazioni di frequenza, controlli geografici e regole di un Web Application Firewall, progettato per riconoscere richieste web anomale. Non è però una barriera assoluta. Deve essere configurato per lasciare passare soltanto i percorsi realmente necessari e deve essere aggiornato come qualsiasi altro apparato esposto a internet. Occorre anche verificare la compatibilità con Extended Protection, la funzione di Windows che lega l’autenticazione alla connessione cifrata per ostacolare gli attacchi di inoltro delle credenziali. La documentazione Microsoft avverte che il TLS offloading non è compatibile con Extended Protection e che il TLS bridging è supportato soltanto a precise condizioni, fra cui l’impiego dello stesso certificato sul proxy o bilanciatore e sul server Exchange. Un proxy installato senza comprenderne gli effetti può interrompere Extended Protection anziché rafforzarla. Un reverse proxy protegge principalmente le connessioni web. Non esamina necessariamente il contenuto della posta che arriva tramite SMTP. Per separare il filtraggio dei messaggi dal Mailbox Server si può utilizzare un email security gateway collocato davanti a Exchange, un servizio cloud di protezione della posta oppure un Edge Transport Server opportunamente configurato. Il gateway riceve i messaggi destinati al dominio, verifica mittente, allegati, collegamenti e reputazione degli indirizzi, poi consegna a Exchange soltanto ciò che supera i controlli. Può sottoporre i file sospetti a una sandbox, un ambiente isolato nel quale osservarne il comportamento, e riscrivere i collegamenti per verificarli anche quando l’utente prova ad aprirli. Il gateway deve lavorare insieme ai meccanismi di autenticazione del dominio. SPF specifica quali server sono autorizzati a inviare posta per conto di un dominio. DKIM applica ai messaggi una firma crittografica e DMARC verifica che almeno uno tra SPF e DKIM superi il controllo con un dominio allineato al mittente visibile e pubblica una politica che indica ai destinatari come trattare le comunicazioni che falliscono la verifica e permette di ricevere rapporti sugli abusi. Queste tecnologie non impediscono che una casella autentica venga violata, ma riducono la possibilità di falsificare il dominio dall’esterno. La difesa del server e la verifica dei messaggi rispondono a minacce diverse e nessuna può sostituire l’altra. La lezione più importante di ProxyLogon è che installare una patch e rimuovere un’intrusione sono due operazioni differenti. La patch chiude la vulnerabilità, ma non cancella automaticamente web shell, account creati dall’aggressore, regole di inoltro, processi pianificati o malware installati prima dell’aggiornamento. Il patching da solo ha dei limiti, se il server è rimasto esposto durante una campagna attiva, è imperativo cercare indicatori di compromissione, controllare le modifiche amministrative, verificare i file nelle directory web e ricostruire le connessioni avvenute nel periodo a rischio. Lo script PowerShell ufficiale Microsoft Exchange Health Checker consente di inventariare le installazioni, controllare aggiornamenti cumulativi e di sicurezza, configurazione TLS, Extended Protection e altre impostazioni rilevanti. È uno strumento diagnostico utile ma non è un sistema di rilevamento delle intrusioni. L’identità amministrativa non deve coincidere con la posta Exchange dipende strettamente da Active Directory. Per questa ragione un amministratore che utilizza lo stesso account privilegiato per leggere la posta, navigare e gestire il server concentra rischi diversi in una sola identità. Gli account amministrativi devono essere separati da quelli utilizzati nel lavoro quotidiano e autorizzati secondo il principio del privilegio minimo. Exchange offre un sistema di controllo basato sui ruoli, chiamato Role-Based Access Control, che consente di assegnare soltanto le operazioni necessarie. Gli accessi più delicati dovrebbero inoltre partire da workstation amministrative dedicate o da un jump server controllato e non da un qualsiasi computer aziendale. Dove l’architettura lo permette, l’accesso remoto deve richiedere un secondo fattore resistente al phishing, preferibilmente una chiave hardware o una passkey. L’autenticazione a più fattori non risolve una vulnerabilità del server, limitandosi a ridurre la possibilità che una password rubata diventi automaticamente un accesso valido. Un sistema EDR osserva ciò che avviene nel sistema operativo. Può rilevare la creazione di una web shell, l’avvio anomalo di PowerShell, l’accesso ai processi che conservano credenziali, il caricamento di file eseguibili e i tentativi di collegarsi ad altre macchine. Microsoft Defender include una regola di riduzione della superficie di attacco specificamente destinata a bloccare la creazione di web shell sui server Exchange. La protezione deve tuttavia essere configurata seguendo le esclusioni antivirus indicate per Exchange, poiché una scansione indiscriminata di database e processi critici può compromettere prestazioni e stabilità, mentre esclusioni troppo ampie creano zone nelle quali il malware può nascondersi. I log di Exchange, Internet Information Services, Windows, Active Directory, proxy, gateway ed EDR devono confluire in un sistema centrale di analisi, normalmente un SIEM, Security Information and Event Management. Conservare le sole registrazioni locali significa lasciare all’aggressore la possibilità di cancellarle insieme alle proprie tracce. Prevenzione e capacità di recupero rispondono a fasi diverse della sicurezza. Un’organizzazione deve potere ricostruire Exchange, recuperare le caselle e riprendere il servizio senza dipendere dalla macchina compromessa. I backup devono quindi essere separati dal dominio amministrativo ordinario, protetti da credenziali differenti e, quando possibile, resi immutabili per un periodo prestabilito. Devono essere verificate la possibilità di recuperare un database e quelle di ripristinare configurazione, certificati, connettori e dipendenze da Active Directory. Un backup mai sottoposto a una prova di recupero deve essere considerato come una speranza vana. La guida CISA contro il ransomware raccomanda copie frequenti, isolate o protette nel cloud, insieme alla centralizzazione dei log e alla preparazione delle procedure di risposta. Per Exchange questa pianificazione è importante: un ripristino tecnicamente riuscito ma privo delle informazioni necessarie a ricostruire la compromissione può riportare in produzione anche il problema che si voleva eliminare. Il mercato offre una quantità di tool per la protezione dei server di posta elettronica. Ne abbiamo scelti cinque che, per costi, garanzie offerte e praticità d’uso andrebbero prese in considerazione con il supporto di personale competente e di fornitori specchiati. Web Application Proxy è un ruolo di Windows Server che permette di pubblicare applicazioni interne senza esporre direttamente il server che le ospita. Microsoft fornisce una procedura specifica per la pubblicazione di Exchange e, per Outlook sul web in determinate configurazioni, consente di utilizzare Active Directory Federation Services per autenticare l’utente prima che la richiesta raggiunga l’applicazione. Altri servizi, tra cui Exchange Control Panel, Outlook Anywhere, Exchange Web Services e Autodiscover, prevedono invece nella documentazione citata la modalità pass-through. Web Application Proxy è utile per Outlook sul web e per gli altri servizi compatibili, ma non sostituisce il gateway SMTP, non corregge Exchange e deve essere progettato tenendo conto di certificati, protocolli e Extended Protection. Proofpoint Email Protection è un secure mail gateway che filtra i messaggi prima della consegna a Exchange. Analizza spam, phishing, malware, collegamenti, allegati e tentativi di BEC. Può essere collocato nel percorso della posta in entrata e in uscita, impedendo che Exchange riceva direttamente tutto il traffico SMTP proveniente da internet. Le funzionalità effettivamente disponibili dipendono dalla licenza e dalla configurazione. Le percentuali di rilevamento dichiarate nella documentazione commerciale di Proofpoint sono affermazioni del produttore, non garanzie applicabili indistintamente a ogni ambiente. Nessus permette di individuare versioni vulnerabili, aggiornamenti mancanti, servizi esposti e configurazioni deboli. Tenable mantiene controlli specifici per Exchange, compresi plugin capaci di riconoscere dall’esterno la presenza del servizio e plugin dedicati ai singoli aggiornamenti, come quello relativo alle vulnerabilità corrette nell’agosto 2025. Le scansioni autenticate offrono normalmente una visibilità maggiore, ma devono essere eseguite con account dedicati e privilegi controllati. Inoltre, alcuni plugin si limitano a confrontare la versione dichiarata dal sistema e non verificano realmente lo sfruttamento della falla. Questo rimanda alla necessità di interpretare il risultato e non limitarsi a condividerlo con i vertici aziendali. L’Exchange Emergency Mitigation Service viene installato automaticamente sui server con ruolo Mailbox a partire dagli aggiornamenti cumulativi di settembre 2021 per Exchange 2016 e 2019, ma non sugli Edge Transport Server. Controlla ogni ora il servizio cloud di Microsoft, scarica un file XML firmato, ne verifica l’integrità e può applicare regole di riscrittura degli indirizzi, disabilitare un servizio vulnerabile o fermare un application pool di Internet Information Services. Come abbiamo spiegato serve a ridurre rapidamente il rischio quando Microsoft conosce una minaccia e dispone già di una contromisura. Non è un sistema autonomo di hardening e, soprattutto, non sostituisce gli aggiornamenti di sicurezza. Microsoft Defender for Endpoint aggiunge rilevamento comportamentale, raccolta degli eventi, investigazione e risposta sul server. Può segnalare processi insoliti, attività di rete sospette, strumenti usati per sottrarre credenziali e comportamenti compatibili con una web shell. Le funzioni di live response permettono agli operatori autorizzati di raccogliere file e informazioni dalla macchina durante un’indagine. Non protegge però i messaggi come farebbe un gateway e non deve essere confuso con il solo antivirus, il suo valore nasce dalla correlazione dei comportamenti e dalla capacità di ricostruire la sequenza dell’attacco. I cinque componenti che abbiamo proposto coprono punti differenti. Web Application Proxy controlla l’accesso web, Proofpoint filtra la posta, Nessus individua esposizioni note, Emergency Mitigation applica contromisure provvisorie e Defender osserva il comportamento del server. La loro sovrapposizione costituisce una difesa stratificata, ma lascia aperte le questioni organizzative. Non stabilisce (né può farlo) chi controlla gli aggiornamenti, entro quanto tempo vengono installati, chi analizza gli avvisi, quali accessi amministrativi sono consentiti e come viene verificato un possibile incidente. Una vulnerabilità di Exchange non nasce il giorno in cui diventa nota. La qualità della gestione determina invece quanto a lungo e con quale esposizione la debolezza rimane sfruttabile: il rischio aumenta quando l’organizzazione non sa con precisione quale versione sta eseguendo, quali servizi espone, chi può amministrarlo e che cosa dovrebbe accadere se smettesse improvvisamente di funzionare. Gli strumenti possono rispondere a molte domande tecniche. Non possono sostituire le responsabilità.
cybersecurity360.itSep 4, 2026extracted
Usa, l’Amministrazione Trump lancia un nuovo programma per rafforzare la cybersicurezza dei sistemi idrici
L’obiettivo è fornire ai sistemi idrici strumenti di cybersicurezza e AI per migliorare tutta la rete di infrastrutture. Project Watershed 250 , questo il nome del nuovo programma sulla cybersicurezza dei sistemi idrici che ha elaborato l’ Amministrazione Trump . Il piano punta “ a fornire gratuitamente strumenti di cybersecurity e intelligenza artificiale ai sistemi statunitensi che dispongono di risorse limitate “. Il progetto parte dal Texas e punta a rafforzare la sicurezza di una delle infrastrutture critiche considerate più vulnerabili del Paese e rappresenta un primo test di un modello più ampio. Quello di mettere a disposizione delle infrastrutture critiche meno finanziate le tecnologie e le competenze di alcune delle maggiori aziende americane. L’ obiettivo , aumentare la resilienza informatica prima che una vulnerabilità possa trasformarsi in un’emergenza. Negli ultimi tempi si sono infatti moltiplicati gli attacchi informatici contro questi sistemi. La Cybersecurity and Infrastructure Security Agency ( CISA ) ha in tale ottica rilevato un aumento significativo delle intrusioni informatiche. Per questo, ha invitato gli operatori del settore “ a scollegare il prima possibile da Internet i sistemi di controllo industriale “. Perché è importante ripensa la sicurezza dei sistemi I sistemi idrici, rimarca Axios , sono da tempo considerati tra gli obiettivi più esposti alle minacce informatiche contro le infrastrutture critiche americane. Il lancio del programma è arrivato nel momento in cui 12 Stati stanno reagendo a sospetti attacchi informatici , proprio attribuiti all’ Iran . Il nuovo progetto, denominato Project Watershed 250 , collegherà gli operatori idrici del Texas con alcune delle principali aziende statunitensi di cybersecurity e tecnologia. L’obiettivo è individuare le vulnerabilità presenti nelle reti e rafforzarne le difese nel corso di un programma pilota della durata di sei mesi. Uno dei principali problemi affrontati dal progetto riguarda la forte disparità di risorse tra i grandi operatori delle infrastrutture critiche e le piccole aziende idriche. Molti sistemi idrici, soprattutto quelli di piccole dimensioni e situati nelle aree rurali, non dispongono infatti dei fondi necessari né di personale interno specializzato in sicurezza informatica . Questa carenza li rende particolarmente vulnerabili agli attacchi informatici. L’accesso gratuito a strumenti avanzati di sicurezza e di intelligenza artificiale mira proprio a colmare, almeno in parte, questo divario . Big Tech al centro Dal punto di vista delle realtà coinvolte, sono state numerose le aziende che hanno deciso di mettere a disposizione gratuitamente servizi e competenze per il progetto. Tra queste figurano Microsoft, Google, AWS, Cloudflare, Palo Alto Networks, Reflection AI, Abnormal AI, Parsons, Fortinet, Forescout, Tenable, Zscaler e Dragos . Sul fronte istituzionale, l’iniziativa vede coinvolte l’ Environmental Protection Agency (EPA) e la stessa Cybersecurity and Infrastructure Security Agency (CISA) come enti federali. L’attuazione del programma in Texas sarà invece supervisionata dal Texas Cyber Command . Durante l’evento di lancio a San Antonio, il Governatore del Texas Greg Abbott ha sottolineato la gravità della situazione. In questi termini: “ Il Texas è sottoposto ad attacchi informatici continui . Tra questi, anche gli attacchi contro i nostri sistemi idrici. La necessità di resilienza informatica è enorme ”. La base del progetto Il programma per la sicurezza delle infrastrutture idriche era in realtà in fase di sviluppo alla Casa Bianca già da diversi mesi, prima dei recenti sospetti attacchi informatici di matrice iraniana. L’Amministrazione in carica, per altro, sta inoltre valutando iniziative analoghe per altri settori delle infrastrutture critiche. Durante il lancio del progetto, il National Cyber Director Sean Cairncross ha evidenziato come la protezione delle infrastrutture riguardi direttamente la sicurezza quotidiana dei cittadini americani. “ L’ infrastruttura che stiamo mettendo in sicurezza non è ipotetica. È concreta ”, ha rimarcato Cairncross . “ La sicurezza delle nostre infrastrutture è importante per ogni americano. In tutto il Paese ”. Seguici anche sul nostro canale WhatsApp Vai al sito di Cybersecurity Italia. L'articolo Usa, l’Amministrazione Trump lancia un nuovo programma per rafforzare la cybersicurezza dei sistemi idrici sembra essere il primo su CyberSecurity Italia .
cybersecitalia.itSep 2, 2026extracted
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
Microsoft on Tuesday announced patches for 421 CVEs, including a high-severity vulnerability that has been exploited in the wild as a zero-day. The exploited flaw, tracked as CVE-2026-68820, is described as a use-after-free issue in Ancillary Function Driver for WinSock (afd.sys), the kernel-mode driver functioning as the backbone for the Windows Sockets API. Microsoft says threat actors have been exploiting the security defect to elevate their privileges to System, without sharing details on the observed attacks. “A locally authenticated attacker could run a specially crafted application on an affected system to trigger a race condition. Successful exploitation could allow the attacker to gain SYSTEM privileges. User interaction is not required,” the tech giant explains. According to Tenable senior staff research engineer Satnam Narang, based on historical tradecraft targeting afd.sys flaws, the CVE might have been exploited by nation-state threat actors. “Since 2022, there have been three other afd.sys zero-days exploited in the wild, including CVE-2025-32709, CVE-2025-21418, and CVE-2024-38193. CVE-2024-38193 was reportedly exploited by North Korean hackers linked to the Lazarus group,” Narang said. As part of the August 2026 Patch Tuesday release, Microsoft also drew attention to CVE-2026-62832, an improper link resolution before file access (link following) bug in Windows’s User Profile Service, which could allow attackers to elevate their privileges locally. “An authenticated attacker who has credentials for another local account could run a specially crafted application to load another user’s registry hive. Successful exploitation could allow the attacker to access or modify another user’s data and gain administrator privileges. User interaction is not required,” Microsoft says. The tech giant flagged the security defect as publicly disclosed and believes that threat actors are likely to start exploiting it in attacks. CVE-2026-72971, a link following in the Windows Container Isolation FS Filter Driver (unionfs.sys) that could lead to local tampering, was also flagged as publicly disclosed, but Microsoft believes it is unlikely to be exploited in the wild. Other flaws that defenders should pay attention to include CVE-2026-62878, CVE-2026-62893, CVE-2026-62815, and CVE-2026-59124, which are remote code execution (RCE) bugs in Windows DNS server, Windows Deployment Services TFTP server, Microsoft QUIC, and Microsoft HPC Pack, as well as CVE-2026-62911, an EoP in Exchange Server, ZDI’s Dustin Childs notes. In total, Microsoft’s August 2026 security updates resolve 236 vulnerabilities in Windows, 98 in Office, 98 in Office 2016, 30 in SharePoint Server, 26 in Developer Tools, 17 in Azure, 7 in Exchange Server, 1 in Defender, and 6 in other products. The updates also include fixes for two non-Microsoft CVEs, namely a spoofing bug (CVE-2026-6726) and an information disclosure issue (CVE-2026-6727) in the TPM 2.0 reference implementation. Related: Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws Related: Zoom Patches Zero-Click Code Execution Vulnerability Related: SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities Related: Microsoft, Apple Release Fresh Security Updates
securityweek.comAug 11, 2026extracted
Black Hat USA 2026 – Summary of Vendor Announcements (Part 3)
Many companies are showcasing their cybersecurity products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. To help cut through the clutter, the SecurityWeek team is publishing a digest summarizing vendor announcements at Black Hat USA 2026, including new products and services, updates to existing offerings, reports, and other initiatives. This is the third part of the series. You can also read Part 1 and Part 2 if you haven’t already. Above Security’s strategic investment from CrowdStrike Falcon Fund Above Security announced a strategic investment from the CrowdStrike Falcon Fund and integration with the CrowdStrike Falcon platform. Through the partnership, CrowdStrike customers will be able to extend their Falcon deployment, powering ready-made insider risk investigations with Falcon Next-Gen SIEM telemetry. Above correlates Next-Gen SIEM endpoint, identity, and third-party data into investigation-ready cases and streams completed investigations back into Falcon. ArmorCode launches vulnerability remediation agents ArmorCode announced four new Anya agents designed to help security teams analyze cloud risks, assess vulnerability exploitability, identify mitigation strategies, and coordinate patch orchestration. The company also added new Context Risk Graph capabilities for expanded attack path analysis, network reachability, and patch management. Commvault integrates Threat Scan with Google Threat Intelligence Enterprise cyber resilience company Commvault announced a new integration that will incorporate Google Threat Intelligence into Commvault Threat Scan workflows. This capability can help organizations identify clean recovery points faster, as well as reduce downtime and speed up recovery following cyberattacks. This announcement adds to Commvault’s ongoing collaboration with Google Cloud, including expanded cyber resilience capabilities for Google Cloud environments via Clumio, and support for Google Cloud workloads. CrowdStrike announces $100,000 international AI security challenge CrowdStrike announced AI Unlocked: Agents of Chaos, a global AI red teaming competition created with AWS that challenges participants to exploit rogue AI agents using prompt injection and other techniques to better understand emerging agentic AI security risks. The virtual competition, which begins on August 31 and features a $100,000 prize pool, is designed to give defenders hands-on experience securing AI agents as they become a growing enterprise attack surface. Dataminr threat landscape report Dataminr has published its 2026 Mid-Year Threat Landscape Report, finding that the average patch window in H1 2026 got 11 days longer. Meanwhile, attackers can break out in less than 30 minutes, and Dataminr tracked a 69.2% jump in alerts from the second half of 2025. DataBahn launches Federated Search and Orchestration DataBahn launched Federated Search and Orchestration, an expansion of its agentic data control plane that moves companies from applying intelligence after data has moved through pipelines to orchestrating it as the data moves. Enterprises can ask one question across every store they own without needing to copy any of the data, and hand it off to an AI agent to complete the investigation. FireMon integrates with Palo Alto Networks FireMon announced it has completed its product integration with Palo Alto Networks Strata Cloud Manager to deliver intelligent and interoperable solutions that enable joint customers to innovate faster and solve their most complex cybersecurity challenges. Intel 471 unveils new AI capabilities Intel 471 announced two new AI capabilities in the Verity471 platform: MCP471 and Agent471. With the addition of MCP471 and Agent471, Verity471 makes its pre-attack and threat-hunt intelligence more accessible and operationalizes it to help organizations detect and respond rapidly. Menlo Security extends platform to secure AI assistants and coding agents Menlo Security expanded its cloud-based Menlo Agent Runtime Security platform to protect AI assistants and coding agents from prompt injection attacks and data exfiltration. The platform routes agent web traffic through a cloud environment to sanitize files and strip hidden instructions before an agent receives the content. Adaptive data loss prevention controls mask sensitive information, while token-based authentication assigns per-agent session identity to enforce specific web access policies. Mimecast unveils Agent Risk Center and Managed Threat Response Mimecast announced a new expansion of its Incydr technology that discovers every AI agent and tool operating across an organization and ties each one back to the human who deployed it. The platform will also include a relaunched Managed Threat Response (MTR) service and expanded Google Workspace integrations. Palo Alto Networks introduces evolution of PAN-OS and publishes research Palo Alto Networks announced a new PAN-OS purpose-built for the Frontier AI era. PAN-OS 12.2 Ceres introduces Advanced Virtual Patching, automated blocking for direct-to-IP attacks, six AI security agents, and expanded hardware for securing AI data centers and critical infrastructure. Palo Alto Networks Unit 42 has also released new threat research detailing how an AI system built by its researchers uncovered more than 14,000 previously unknown vulnerabilities across nearly 4,000 widely used open source projects; and how analysis of more than 4 million reports found that 45.32% of malware with C&C activity communicates directly with IP addresses. Prophet Security research on AI in Security Operations Prophet Security has released its second annual State of AI in Security Operations report. An independent survey of 250 IT and cybersecurity professionals finds that security operations teams are reaching a breaking point as alert overload, AI-powered attacks and staffing shortages force organizations to rethink how SOCs operate. According to the report, 96% of organizations are already using AI or actively evaluating AI for security operations, organizations leave an average of 28% of security alerts uninvestigated, and 56% report an increase in AI-driven attacks over the past year. Proofpoint announces OEM Program Proofpoint announced an OEM Program: a portfolio of OEM-ready threat intelligence and detection capabilities available for technology providers, cybersecurity vendors, managed service providers, and platform companies. The program cuts the time, cost, and operational lift of building threat intelligence capabilities from scratch, helping partners accelerate product roadmaps and bring differentiated offerings to market faster. Rubrik adds agent identity controls to Agent Cloud Rubrik expanded its Agent Cloud platform with Rubrik Agent Identity to manage autonomous AI agent access permissions at runtime. The solution eliminates standing credentials by generating short-lived, scoped tokens for individual tool calls and integrating with identity providers (including Okta and Microsoft Entra ID). Before execution, tool requests pass through a gateway that conducts semantic behavioral analysis, verifies infrastructure access policies, and authenticates session identities. ServiceNow announces new security solutions and AI Center for Cyber Defense ServiceNow launched six unified solutions that deliver prevention-first, AI-native cyber defense across unified exposure management, identity and access security, cyber-physical security, cyber risk and compliance, and agentic incident response. ServiceNow also unveiled its newly formed AI Center for Cyber Defense, a global hub for security innovation. SOCRadar launches Human Identity Exposure Threat intelligence company SOCRadar announced the launch of Human Identity Exposure, a new Identity & Access layer for its Extended Threat Intelligence (XTI) platform that gives analysts an instant, comprehensive snapshot of an individual’s identity risk. SOCRadar Human Identity Exposure unifies fragmented identity exposure data, including breach repositories, stealer infections, attacker telemetry, PII, data leaks, and CTI signals into a single, decision-ready record. Surf AI announces new integration and platform expansion Surf AI announced an integration with Claude’s Compliance API, alongside the general availability of Exposure Reduction Operations, extending the platform to govern AI model connectivity alongside identity, cloud, and SaaS exposures. The integration pulls activity logs from the Claude environment, maps the connection and access path to an accountable owner inside the Context Graph, and operationalizes remediation, including disabling unsanctioned MCP integrations and lingering Claude access after offboarding. Tenable debuts open source AI agent exchange and expands AI risk coverage Tenable launched CyberAgents Exchange, a free, open source AI agent exchange built for cybersecurity teams. It is a vendor-agnostic community where security professionals can discover, share and build trusted AI agents, skills, MCP servers and multi-agent playbooks, backed by code-level transparency into who built what and how it works. Founding members also include SentinelOne and Recorded Future. The company also unveiled new Tenable One AI Exposure capabilities that expand coverage across every major AI platform and key developer tools. Thales releases Luna 8 Thales released Luna 8, its first in-house designed hardware security module made to secure, store, protect, and manage cryptographic keys against quantum threats. The system features an upgradeable architecture to integrate future cryptographic algorithms while maintaining backward compatibility with existing interfaces and ancillaries. Delivered on a unified hardware platform, the appliance is undergoing independent evaluation for FIPS 140-3 Level 3 and EU Common Criteria standards. Trustmi announces new AI investigation agent and new payment fraud threats Trustmi unveiled an AI Investigation Agent that is purpose-built for B2B fraud detection. It introduces agentic workflows that investigate suspicious activity, reasons across business workflows, and connects evidence across systems. The company also announced the discovery of two emerging payment fraud threats: Ghost Executive, an attack in which fraudsters fabricate an executive’s approval so the payment looks like a decision has already been made; and Deadline Deception, which pairs fraudulent paperwork with a false deadline to pressure employees into releasing funds. VanishID adds AI exploitability management and external identity protection control VanishID announced AI Exploitability Management and External Identity Protection. Operating externally without internal system credentials or installations, AI Exploitability Management breaks down over 40 attack scenarios to calculate individual risk scores based on public data availability. Complementing this tool, External Identity Protection deploys four categories of autonomous agents (detection, analyst, remediation, and residual risk) to scan data brokers, dark web repositories, and public records. Automated remediation agents submit and verify opt-out requests to erase public profiles.
securityweek.comAug 5, 2026extracted
Tenable broadens AI visibility across major LLMs and AI tools
Tenable broadens AI visibility across major LLMs and AI tools Tenable has announced enhanced AI security capabilities within the Tenable One Exposure Management Platform. Tenable One AI Exposure now delivers expanded platform coverage with support for Google Gemini, extending its coverage across major LLMs: Google Gemini, Anthropic Claude, OpenAI ChatGPT Enterprise and Microsoft Copilot. The release also extends discovery to all major Model Context Protocol (MCP) deployments and AI-native Integrated Development Environment (IDE) tools. Together, these capabilities give security teams a more complete view of where AI is being used, what risk it creates and where action is needed. The adoption of AI across the enterprise has created a critical AI exposure gap, a largely invisible risk that emerges across interconnected applications, infrastructure, identities and data. Underscoring this risk, Tenable detected 457 million AI-related security issues across more than 7,000 organizations, averaging 62,000 exposures per organization over a 30-day period. Traditional security tools leave security teams blind to high-impact attack paths, forcing them into a reactive loop rather than preemptively reducing AI risk. Tenable One continuously discovers AI across endpoints, cloud and LLM applications, including both authorized and shadow AI. It inventories AI assets with the Tenable Exposure Graph, Tenable’s data lake that aggregates massive volumes of security data to help organizations map, analyze and prevent cyber risks. Tenable One reduces real-world AI risk by securing the environments where AI runs and hardening AI workloads before they can be exploited. With these new advancements, Tenable One enables organizations to gain better visibility, context and control to manage AI risk while being able to govern AI use, enforce policies and prevent cyber exposures. New AI security capabilities within Tenable One include: Google Gemini coverage: Tenable One now delivers visibility and governance for Google Gemini including monitoring of user interactions and prompt responses, policy enforcement, and detection of malicious activity and inappropriate usage. Enhanced AI visibility: Tenable One now doubles its coverage of sanctioned and shadow AI, supporting MCPs, AI-native IDEs (such as Cursor, Windsurf and Trae) and AI-enabled browser extensions. Operationalized remediation: Organizations can remediate faster by creating tickets directly in Jira and ServiceNow or alerting users on policy violations by sending automated email notifications, Slack or Teams messages. “The massive volume of AI exposures confirms the operational reality that authorized and unauthorized AI is deployed faster than security teams can govern it,” said Eric Doerr, Chief Product Officer, Tenable. “There’s no denying that AI attack surfaces are making defenders’ jobs even harder, and legacy or siloed cybersecurity tools simply don’t cut it. With today’s expansion to include Google Gemini, MCP and AI-native IDE deployments, Tenable is the only exposure management platform delivering unified AI visibility and governance across all major LLMs, software, and tools.” Tenable One brings together two distinct AI capabilities. Tenable AI Exposure helps organizations discover, assess and secure how AI is being used across their environments. Tenable Hexa AI is the platform’s agentic engine, using AI to coordinate agents, automate security tasks and accelerate remediation. AI Exposure helps organizations secure their use of AI, while Hexa helps them use AI to improve security operations. Together, they advance Tenable’s preemptive security strategy by helping organizations reduce AI-related risk and act on cyber exposure more efficiently.
helpnetsecurity.comAug 5, 2026extracted
Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)
Many companies are showcasing their cybersecurity products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. To help cut through the clutter, the SecurityWeek team is publishing a digest summarizing vendor announcements at Black Hat USA 2026, including new products and services, updates to existing offerings, reports, and other initiatives. The first part of this roundup was published on August 3. Astelia unveils agentic AI exposure management capabilities Astelia launched its new agentic AI capabilities for its exposure management platform, automating reachability analysis and remediation workflows across the entire vulnerability lifecycle. By adding this new agentic layer, the platform now evaluates newly disclosed vulnerabilities and their reachability, assesses operational impact, coordinates remediation across security and IT teams, and helps drive each issue toward resolution. Human approval remains built into key decision points, with every action logged and auditable. AvePoint adds continuous data sensitivity classification to Confidence Platform AvePoint has introduced Kinetic Classification, a capability that continuously re-evaluates data sensitivity across Microsoft 365, Google Workspace, and other business applications, replacing static, one-time labeling. AvePoint also added new tools to its Rapid Recovery system, including a Rapid Recovery Wizard and Express Recovery for Entra ID, meant to help teams prioritize restoration of critical data after an incident. CrowdStrike publishes 2026 Threat Hunting Report CrowdStrike’s 2026 Threat Hunting Report finds that AI is now embedded across modern adversary operations, with threat actors using AI to accelerate attacks, exploit vulnerabilities within hours of public disclosure, and target enterprise AI systems and software supply chains. The report also highlights a sharp rise in cloud-focused attacks, AI supply chain compromises, and abuse of trusted authentication workflows, underscoring the need for organizations to secure AI environments while using AI to defend against increasingly automated threats. Cisco Talos research shows how threat actors are weaponizing AI Cisco Talos released new research detailing how threat actors are using AI and LLMs in real-world cyberattacks. Drawing on recovered prompt logs, attack tooling and threat actor conversations, the research documents how AI is being used to develop malicious code, build fraud infrastructure, and accelerate vulnerability research and exploitation. The research found that threat actors rarely need sophisticated jailbreaks; sophisticated threat groups are leveraging AI as a development assistant to rapidly build exploits; and that adversaries use AI across various steps of the attack lifecycle and operations. Drata extends trust management platform to AI agents Drata has extended its Trust Management Platform, announcing the limited availability of AI Agent Governance, which is designed to help enterprises discover, monitor, govern, and prove traceability of the AI agents running inside the organization. The product ships first for Anthropic, with early access customers already running it end-to-end in production. Horizon3 extends production-safe autonomous pentesting to web applications Horizon3.ai announced NodeZero WebApp Pentesting, an expansion that enables the NodeZero platform to autonomously and safely test web applications the way attackers operate. It proves what is actually exploitable, quantifies the business consequence of each attack path, and maps those paths to the tactics of known threat actors. The announcement comes just as the company raised $250 million in funding. Huntress expands Managed ESPM with free RMM Guard Huntress announced that its RMM Guard is now available for free to all customers with an agent deployed, as part of its broader Managed ESPM effort. This release is focused on detecting and blocking rogue remote monitoring and management tools that attackers increasingly abuse to gain and maintain access. RMM Guard identifies and blocks unauthorized RMM software on endpoints before it can be used for persistence or remote control, lets teams define which RMM tools are approved and which should be blocked, and adds extra protection for isolated machines so approved remote access tools do not get blanket access. The announcement comes in light of a new N-central RMM vulnerability being exploited in the wild. Legit Security releases VibeGuard 2.0 for coding agent endpoint security Legit Security has released VibeGuard 2.0, an endpoint-based tool that discovers and secures AI coding agents such as Claude Code, Cursor, and GitHub Copilot. It operates at the endpoint level, applying policy enforcement and granular controls over specific agent commands and tools. New features include guardrails for skill discovery, blocking of risky operations, MCP security controls, command monitoring against built-in or custom policies, and anti-tampering protections meant to stop agents or users from disabling the tool. Netskope announces DataSec Command Center Netskope announced its Netskope One DataSec Command Center, a unified control plane that discovers, understands, tracks, and protects sensitive data of any kind wherever it lives and moves, from AI environments to the network. With Netskope One DataSec Command Center, security teams gain full visibility into their sensitive data and a seamless path from discovery to remediation across their entire data landscape. ProjectDiscovery announces general availability of Neo ProjectDiscovery announced the general availability of Neo v1, and a new Pay-as-you-go model. After six months of private beta testing with enterprise customers, ProjectDiscovery is making Neo available to everyone to help teams move from periodic, manual testing toward continuous security that runs alongside development. Teams of all sizes can access autonomous security testing across code, applications, APIs, cloud and networks with this new pay-as-you-go model, without traditional procurement and budget barriers. Qualys adds scanless vulnerability detection to ETM platform Qualys has introduced InstaScan, a scanless detection capability inside its Enterprise TruRisk Management (ETM) platform. The feature is powered by Agent Insta, an AI agent that continuously matches newly published vendor advisories against an organization’s existing asset inventory and telemetry rather than relying on scheduled scans. It normalizes software identities into standard identifiers (such as CPEs and PURLs) to build a consolidated inventory, then flags affected assets and issues confidence-scored findings. SailPoint unveils SailPoint Identity Security SailPoint has unveiled SailPoint Identity Security, a combination of SailPoint Agentic Fabric and SailPoint Human Fabric designed to deliver a continuous, real-time loop to discover, govern, and protect digital environments across human, non-human and agentic identities. Sectigo launches automation gateway for certificate lifecycle management Sectigo has released Sectigo Orchestration Gateway (SOG), a new automation layer inside its Sectigo Certificate Manager (SCM) platform. The gateway lets IT teams automate certificate discovery, issuance, renewal, and deployment across servers, load balancers, CDNs, WAFs, and access systems from a single install. It includes native support for platforms such as IIS, Apache, F5, NGINX, and Citrix, along with direct integrations with credential managers CyberArk, Delinea, HashiCorp, and BeyondTrust for just-in-time credential retrieval. Sevii expands ADR platform with autonomous preemptive security module Sevii announced a major expansion of the Sevii Autonomous Defense & Remediation (ADR) platform with the general availability of an Autonomous Preemptive Security (APS) module. The new module extends the platform to continuously transform external global and internal environmental cyber intelligence into autonomous hypothesis hunting, exposure validation, compromise detection, and autonomous remediation. Sysdig launches AI-native offering for cloud runtime defense Sysdig has launched Sysdig Secure AI, an AI-native addition to its Sysdig Secure cloud-native application protection platform (CNAPP). The offering provides three ways to apply AI to cloud defense: autonomous agents that prioritize risks and issue remediations, a “headless” mode that integrates with AI coding agents such as Claude, Cursor, and Codex, and a GenAI assistant (formerly Sysdig Sage) that explains risks and recommends fixes in plain language. Tanium expands Autonomous IT Platform with new agentic and exposure tools Tanium added new capabilities across its Autonomous IT Platform in three areas. Tanium Atlas now includes Agentic Performance Analysis for root-cause tracing, Background AI Agents that run alert-to-resolution workflows autonomously, and an MCP Server that exposes Tanium data to clients like Claude and Microsoft Security Copilot. New exposure management tools add External Attack Surface Management and Attack Path Mapping, while a new Agent-Guided Threat Hunting feature runs hypothesis-driven hunts mapped to MITRE ATT&CK, paired with a private-preview integration with Google Threat Intelligence. Torq unveils SOC Brain Torq has introduced Torq SOC Brain, a new self-learning layer of its AI SOC Platform that continuously learns from historical investigations, analyst decisions, and organization-specific security operations to create a personalized intelligence engine. By utilizing its Recall, Reflex, and Retrospect capabilities, the system reasons from precedent and organizational history to adapt to each team’s unique risk logic and deliver increasingly accurate threat classifications over time. Viakoo adds configuration drift remediation module for OT and IoT devices Viakoo has introduced Device Configuration Manager (DXM), a new module for its Viakoo Action Platform aimed at correcting configuration drift in OT and IoT environments. The agentless tool continuously audits device settings against defined baselines, flags unauthorized changes, and automatically restores devices to a compliant state. Viakoo also expanded its integrations to include Armis, Forescout, Nozomi Networks, Claroty, and Tenable. DXM is expected to become available in Q4 2026. Vicarius publishes state of vulnerability remediation report Vicarius released its “Exposed and Unfixed: The 2026 State of Vulnerability Remediation” report, which shows that siloed workflows and manual administrative handoffs leave 79% of organizations vulnerable to known exploits they already knew about. The report data found that 75% of critical vulnerability responses simply trigger an administrative workflow rather than actually resolving the threat, 50% of organizations consider a vulnerability “closed” based on pure risk acceptance or ticket generation rather than running a verified rescan to ensure the patch worked, and 79% of organizations experienced a security incident in the past 12 months involving a vulnerability that was already sitting in their inventory. Zimperium releases automated mobile forensic investigation tool Zimperium has introduced Deep Insights, a mobile forensic investigation tool built to automate analysis of mobile device attacks. The tool reconstructs full attack timelines from collected evidence, allowing tier-one SOC analysts to investigate incidents without specialized mobile forensics expertise. It also runs automated pre- and post-travel comparisons to flag suspicious changes in device state. Deep Insights is expected to become generally available in September 2026.
securityweek.comAug 4, 2026extracted
Coordinated cyberattack hits more than 30 Minnesota water utilities
Coordinated cyberattack hits more than 30 Minnesota water utilities A coordinated cyberattack on July 26 and 27 hit operational technology (OT) systems at more than 30 community water utilities across Minnesota, prompting an immediate response from Minnesota IT Services (MNIT) to contain the threat. MNIT confirmed the attack in a statement published July 28 and said it activated its cybersecurity incident response capabilities as soon as it learned of the intrusion. The agency has since been working with a broad set of partners to investigate the attack, support the affected communities, and shore up the security of the state’s infrastructure. “Cyberattacks against critical infrastructure require a coordinated, whole-of-government response,” said John Israel, MNIT Assistant Commissioner and Minnesota’s CISO. “MNIT is working side by side with our partners to share intelligence, support affected communities, and help utilities restore operations safely while strengthening defenses against future attacks.” The investigation remains active, and responders continue to assess which systems were affected. The Minnesota Department of Health is working directly with the impacted water systems to help protect public health, and so far no Minnesota city has asked its residents to change how they use their drinking water. Four cities have come forward publicly about the attack, Braham, Plymouth, South St. Paul, and Maple Plain. The City of Maple Plain noted in a statement that some details about the incident and the response cannot be shared right now, since releasing them could raise risks to infrastructure or interfere with the cybersecurity work underway. Officials added that more information would follow once it is safe to share. “At this time, there has been no disruption to water or wastewater service, and there is no indication that the safety or quality of the City’s drinking water has been affected,” city officials said. New federal guidance and a suspected Iranian link On July 28, CISA, with Australia’s Signals Directorate, the UK’s National Cyber Security Centre, and Canada’s Centre for Cyber Security, published CI Fortify – Advice for Isolating Vital Systems, guidance advising infrastructure operators to isolate essential OT systems from the rest of their networks, a step meant to keep services running even if a breach occurs. “CISA urges OT owners and operators to maintain robust isolation and recovery plans so that essential services can continue under degraded conditions, enabled through either manual or alternative SCADA paths. Through proactive planning and practice, we can strengthen critical infrastructure defenses against state-sponsored threat actors,” noted Chris Butera, CISA’s Executive Assistant Director for Cybersecurity. Although officials have not publicly attributed the attack to any actor, security researchers at Tenable suspect the Iran-linked group CyberAv3ngers, based on patterns consistent with its past targeting of small water utilities. “The timing of the Minnesota attacks is significant,” researchers said. “CISA updated Advisory AA26-097A on July 22, just four days before the attacks began, warning that Iranian-affiliated actors had been compromising internet-connected PLCs across U.S. water, energy, and government sectors.” According to Tenable, CyberAv3ngers has repeatedly compromised small water utilities and municipal facilities, a pattern the firm calls structural rather than coincidental, tracing it to organizations that run OT environments through consumer remote-access tools such as TeamViewer and AnyDesk, or expose PLC interfaces directly to the internet. “Small utilities typically lack dedicated OT security staff and operate under constrained budgets that make comprehensive security architecture difficult to implement,” Tenable noted. Help Net Security wrote about a separate but related problem facing the broader OT sector, a shortage of engineers who understand both control systems and networks deeply enough to secure them, with much of that expertise aging into retirement faster than utilities can replace it.
helpnetsecurity.comJul 30, 2026extracted
Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls. Braham's water plant went offline, and the city asked residents to minimize water use until treatment resumed. Plymouth reported cellular communications problems at two water towers and multiple wastewater lift stations but continued operating manually. South St. Paul and Maple Plain maintained services after automated utility controls were affected, with Maple Plain declaring a local state of emergency to support its response. Minnesota IT Services (MNIT) said on July 28 that it was not aware of any active requests for residents to change their drinking-water use. Officials have not publicly identified the attacker, affected products, exploited vulnerability, or whether data was stolen. "At this point, we can confirm that more than 30 water systems throughout the state were impacted," MNIT told The Hacker News. "The nature and extent of the impact varied by system, and the investigation is still determining how many experienced operational disruptions." MNIT said the incidents shared common characteristics, including their timing, methods of access and the type of infrastructure targeted. Those similarities supported the state's description of the activity as coordinated. The agency said the similarities were consistent with activity observed by federal partners in other states and industries, but investigators could not yet determine whether a single actor was responsible for all the incidents. Investigators have also identified similarities in how the systems were accessed, MNIT said, but the agency is not sharing specific technical details while the investigation continues. Attribution has not been finalized. MNIT said it is coordinating containment, investigation, recovery and threat-intelligence sharing with state agencies, the Cybersecurity and Infrastructure Security Agency (CISA), the Environmental Protection Agency, the Federal Bureau of Investigation and affected utilities. "Cyberattacks against critical infrastructure require a coordinated, whole-of-government response," said John Israel, MNIT assistant commissioner and Minnesota chief information security officer. MNIT said the response enabled agencies to contain the incident and help prevent more serious impacts to critical services. In a separate development four days before the Minnesota attacks, U.S. agencies expanded a warning about Iranian-affiliated actors targeting internet-facing programmable logic controllers made by Rockwell Automation, Schneider Electric, Siemens and potentially other manufacturers. Investigators in that campaign observed attackers exfiltrate and modify project files, manipulate data shown through human-machine interfaces and supervisory control and data acquisition systems, and disable shutdown and alarm logic. State and federal officials have not publicly connected the Minnesota attacks to that campaign. Tenable said the timing and operational pattern were consistent with the broader CyberAv3ngers threat ecosystem, while noting that the incident has not been officially attributed. "While MNIT did not provide attribution, these tactics remain consistent with the tradecraft attributed to CyberAv3ngers and other IRGC-CEC affiliated groups, who have been known to target critical infrastructure since at least 2023," Scott Caveza, senior staff research engineer at Tenable, told The Hacker News. Caveza said U.S. agencies have previously warned that CyberAv3ngers and other groups affiliated with Iran's Islamic Revolutionary Guard Corps Cyber-Electronic Command have targeted water and wastewater systems through programmable logic controllers and human-machine interfaces, in some cases causing operational interruptions. In a July 30 warning, the FBI and EPA said water and wastewater utilities in at least seven states had reported incidents since July 27 involving internet-facing Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs. The FBI said it had only observed the activity with those models, although operators of other PLC brands should apply similar protections. The actors remotely changed PLC IP addresses and passwords, causing loss of monitoring and control. Some incidents degraded water operations, with reported effects including loss of pressure and flooding. At least one organization also found modified PLC project files after identifying ladder-logic discrepancies across several sites. The agencies did not identify the affected states, connect the activity to the Minnesota incidents, or attribute it to CyberAv3ngers or another actor. CISA's advisory provides sector-wide defensive guidance. Minnesota officials have not publicly identified a programmable logic controller family, specific access method, or vulnerability used in the attacks. CISA also recommends logging cellular modem connections, restricting controller access to authorized systems and inspecting running project files for unauthorized changes. Operators should validate backups before restoration and, where a controller has a physical mode switch, place it in run mode only after validating its project files. As of July 29, 2026, MNIT said the investigation remained active and responders were continuing to assess affected systems. Update: This article was updated after publication to include comments from MNIT and Tenable. Update, July 31, 2026: Added the FBI and EPA's separate warning about internet-facing PLC attacks reported across at least seven states.
thehackernews.comJul 29, 2026extracted
Mythos Asks the Right Question. It Doesn't Answer It.
AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in security circles right now goes something like this: Mythos is here. Exploit timelines are collapsing. Does the vulnerability management playbook need to change? The honest answer is yes. But not the part most people are focused on. The discussion around Mythos, Anthropic's frontier model and its implications for offensive security, tends to center on discovery. AI accelerates reconnaissance. It helps attackers identify exposures faster, chain techniques more efficiently, and move at machine speed through environments that were previously protected, in part, by the attacker's own time constraints. That's real. And it matters. But here's the part getting less attention: most security teams weren't winning the prioritization battle before Mythos arrived. The compressed timeline doesn't create a new problem. It raises the cost of an existing one. "A CVSS 9.8 with no path to a critical asset is less urgent than a CVSS 5.5 sitting one hop from your customer database. That was true before Mythos. It's just more expensive to get wrong now." The Prioritization Problem Didn't Start with AI We've spent the past year talking to security architects, heads of detection and response, and CISOs across midmarket and growth enterprise organizations. When we ask how they prioritize vulnerabilities, the answers are remarkably consistent: "A large proportion of the vulns we uncover aren't actually exploitable but we don't know that unless we research each one heavily, which we lack the time and headcount to do." "Currently by CVSS score... and not well." "We use Tenable and external security exercises which provide severity ratings, and that's how we prioritize. It's all very slow and we can do better." These aren't small shops with immature programs. These are organizations running Qualys, Tenable, Rapid7, CrowdStrike, Wiz, Okta, and Splunk simultaneously. Serious tools. Serious budgets. Still working from a CVSS-sorted backlog. The root cause isn't scanner quality or coverage. It's context. Specifically, the absence of three things that CVSS scores don't include: Identity context. Which accounts have access to the vulnerable system, and are they overprivileged? Reachability. Is this asset internet-exposed? Is it one hop from a crown-jewel system? Path continuity. Does a confirmed exploit chain exist that connects this CVE to something that actually matters to the business? Without those three inputs, 50,000 findings is not a prioritized list. It's a backlog with no compass. What Mythos Actually Changes, and What It Doesn't Mythos and models like it compress the time between vulnerability disclosure and exploitation. A security team that used to have three weeks to patch after a CVE dropped might now have three days. In some cases, hours. That's a meaningful shift in operating conditions. But it doesn't change the underlying architecture problem, it just makes the cost of that problem much higher. If your team is working from a CVSS-sorted list of 50,000 findings, faster exploit timelines don't help you. You're still starting from the wrong list. "Mythos accelerates the attacker. The question is whether your prioritization is fast enough to keep up, and right now, for most organizations, it isn't." The question of whether Mythos demands a new vulnerability management playbook is worth asking. But the answer isn't a faster scanner or a more aggressive patching cadence. The playbook that needs to change is this one: stop treating vulnerability management as a standalone function that produces a sorted list of CVEs. Start asking which exposures, combined with which identity context, which network reachability, and which business criticality, create a confirmed path to a crown-jewel asset. That's not a detection problem. That's an architecture problem. The Architecture Gap Nobody Is Talking About Here's what a typical enterprise security stack looks like today: Identity: Okta or Entra Cloud security: Wiz or Orca Vulnerability management: Qualys, Tenable, or Rapid7 Endpoint: CrowdStrike or SentinelOne Network: Zscaler or Palo Alto SIEM: Splunk or Sentinel Each of these tools does exactly what it was built to do. Wiz sees the misconfiguration. Okta sees the overprivileged service account. CrowdStrike sees the endpoint state. Qualys sees the CVE. None of them see the chain that connects all four into a viable attack path to your customer database. Every one of those tools can hand you a risk score. None of them can hand you a decision you can defend to your board. That's not a gap in any one tool. It's a gap in the architecture. We talked to a security architect whose team runs exactly this stack. Their description of the situation: "We have good signals from all our tools, but correlating identity + cloud + endpoint into one attack path still takes manual work." That manual work, the tab-switching, the cross-referencing, the analyst hours spent building a picture that should already exist, is exactly what Mythos exploits. An attacker operating at machine speed doesn't give you the two hours it takes to manually correlate your tools. What Attack-Path-Driven Prioritization Actually Looks Like The alternative isn't a new scanner or a faster patching process. It's a fundamentally different question: Not "what is the CVSS score of this CVE?" But "can this CVE reach a crown-jewel asset, through which identity, across which trust boundary, with what blast radius?" The math changes significantly when you add identity context. An overprivileged service account adjacent to an unpatched CVE isn't a medium-severity finding. It's a critical attack path. A CVSS 5.5 on an internet-facing system with a direct route to your customer database is more urgent than a CVSS 9.8 on an isolated test environment. CVSS alone can't tell you that. Your individual tools can't tell you that. Only a system that correlates across them can. "The security teams that respond effectively to AI-compressed exploit timelines aren't the ones with the fastest patching processes. They're the ones who know which 12 findings out of 50,000 actually matter." This is what Mesh was built to deliver. It ingests your existing vulnerability management tools and adds the context they're missing: Identity context from Okta or Entra: Is an overprivileged account adjacent to this vulnerability? Network reachability from Zscaler or Palo Alto: Is this asset internet-exposed? Crown-jewel mapping: Does a confirmed path exist from this exposure to a critical asset? Attack simulation validation via Horizon3.ai: Is this path actually exploitable today, not just theoretical? The output isn't 50,000 findings sorted by severity. It's 12 prioritized, evidence-backed exposures that have a confirmed path to something that matters. That's not more data. That's a decision. That's the list that's defensible in front of your board. That's the list that lets you operate at the speed Mythos demands. The Playbook That Actually Needs to Change The old playbook: run your scanners, sort by CVSS, assign tickets, track remediation rates. The new one: 1. Connect your tools. Not replace them. Sit a unified intelligence layer above your existing stack that correlates across identity, cloud, endpoint, and vulnerability data simultaneously. 2. Prioritize by path, not by score. Ask which exposures have a confirmed route to a crown-jewel asset, through which identity, with what blast radius. 3. Validate before you remediate. Confirm a path is actually exploitable before committing remediation resources. Prioritize confirmed paths over theoretical ones. 4. Operate continuously, not periodically. Mythos means the window between exposure and exploitation can close in hours. Point-in-time assessments aren't a baseline anymore; they're a liability. None of this requires replacing the tools you've already deployed. Qualys still finds your CVEs. Okta still governs your identities. Wiz still flags your cloud misconfigs. The gap isn't in what those tools see individually, it's that nothing connects what they see collectively into one picture. That's the architecture problem. And Mythos just made it a lot more expensive to ignore. Mythos doesn't invalidate vulnerability management. It invalidates vulnerability management that operates without context. AI won't punish organizations because they patch too slowly. It will punish them because they're patching the wrong things. That's the playbook that actually needs to change. See what your real attack paths look like in your own environment. Mesh is the unified intelligence layer for enterprise security teams operating across fragmented security stacks with no shared context. Connecting agentlessly to your existing tools, Mesh correlates signals across identity, cloud, SaaS, endpoint, and AI environments to reveal viable attack paths to your most critical assets. By providing enterprise-wide context that no individual tool can deliver alone, Mesh helps security teams prioritize what matters most and eliminate risk faster through guided or autonomous remediation workflows. Your Tools, Unified. Your Risks, Eliminated. https://mesh.security
thehackernews.comJul 29, 2026extracted
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch. Here is the full recap of what broke, what was exploited, and what needs attention now. ⚡ Threat of the Week New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code - Searchlight Cyber disclosed a pre-authenticated remote code execution vulnerability in WordPress Core that can be exploited anonymously on a standard WordPress installation, without requiring any plugins or other special conditions. It is a combination of CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection in WordPress core) that can be chained to turn an anonymous request into code execution. watchTowr said it's already seeing proof-of-concept (PoC) exploits in circulation and that it's beginning to see the first signs of in-the-wild exploitation. "This is going to hurt," watchTowr CEO Benjamin Harris said. "WordPress runs on hundreds of millions of websites globally. Some of those will be auto-patched by their hosting providers, but plenty will not, and that is where the damage will be done. Our advice is simple: patch as fast as you possibly can, and do not stop there. Put the controls and investigations in place to determine whether an attacker got there first and to detect and remove any backdoors that may already have been dropped before you patched." The cybersecurity company said it's the latest example of vulnerabilities being surfaced by AI-assisted tooling and how the technology is being abused by attackers to weaponize them. AI Broke Vulnerability Management. Here Is the CISO Case The AI security job market is no longer theoretical. SANS tracked hiring across 10 specific roles and mapped verified job data, salary ranges, and the skills required to get there. The three-tier framework gives your team a clear view of which roles to prioritize now and which to develop toward. Download Now ➝ 🔔 Top News SonicWall SMA Zero-Days Exploited as 0-Days - A previously undocumented threat actor codenamed UTA0533 has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior to their public disclosure since June 22, 2026. The discovery was made following an incident response investigation initiated earlier this month. The impacted organization has not been identified. "This threat actor was observed using multiple zero-day exploits, malware designed specifically for SonicWall SMA VPN appliances, as well as other attacker tradecraft," Volexity said. The vulnerabilities in question are CVE-2026-15409 (CVSS score: 10.0) and CVE-2026-15410 (CVSS score: 7.2), both of which could be chained to facilitate arbitrary command execution and take over susceptible devices. Patches for both vulnerabilities were released by SonicWall last week. DoS Flaw in OpenSSL - The Okta Red Team disclosed details of HollowByte, a denial-of-service (DoS) flaw in OpenSSL. "By sending a malicious payload of just 11 bytes, a remote, unauthenticated attacker can force a server to allocate disproportionate chunks of memory before any security handshake even begins," Okta said. Put differently, an unauthenticated attacker -- through 11 bytes of carefully crafted data -- can convince OpenSSL to reserve up to 128 KB of heap memory for a handshake message that never actually arrives, causing a server to exhaust available RAM and trigger a DoS condition. The OpenSSL team resolved the issue in versions 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21. "Instead of trusting the header outright, OpenSSL now grows the buffer only as bytes actually land on the wire. A claim with no follow-through now costs the server nothing," Okta said. CISA Adds New SharePoint RCE Zero-Day to KEV Catalog - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026. The vulnerability, CVE-2026-58644 (CVSS score: 9.8), is a critical deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute arbitrary code. Patches for the flaw have been released as part of the Patch Tuesday updates released on July 14, 2026. Microsoft revised its bulletin to clarify that CVE-2026-58644 has been exploited in the wild, meaning the shortcoming was weaponized as a zero-day prior to the fixes becoming available. The development came as Microsoft shipped its largest Patch Tuesday on record, addressing 622 vulnerabilities. OkoBot Malware Framework Infects Windows to Phish Crypto Seed Phrases - A new malware framework called OkoBot is designed to capture the contents of cryptocurrency wallet windows. OkoBot is an updated version of TookPS, which is a downloader for retrieving malicious commands and scripts from attacker-controlled servers to further propagate attacks, including a Python-based infostealer and a remote access trojan called TeviRAT. "This campaign differs from previous activity in that it uses a new framework to deliver all malicious modules and orchestrate them via an SSH tunnel," Kaspersky said. "In total, the framework includes more than 20 malicious payloads and implants, covering a wide variety of functions. At the time of writing, the threat remains active." The infection chain makes use of ClickFix and malware distributed through GitHub that masquerades as legitimate software for initial access. It also comes with a web browser extensions loader to deliver Rilide, a browser-based stealer, as well as inject an implant into Trezor Suite, Ledger Wallet, and Ledger Live processes to collect seed phrases, log keystrokes and clipboard content, take screenshots, and capture keystrokes and the video stream of the target application's window using the OkoSpyware module. Hundreds of victims of the OkoBot campaign have been detected in more than 25 countries, with the highest concentration in Brazil, Vietnam, Canada, Mexico, and Türkiye. The activity remains unattributed. NadMesh Scans Exposed AI Services for Cloud Keys and Kubernetes Tokens - A new Go botnet called NadMesh has been observed hunting for exposed AI services related to ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio to steal AWS keys and Kubernetes tokens. "It folds scanning, exploitation, and credential/AI-service intelligence harvesting into a single autonomous platform," QiAnXin XLab said. "On the victim, the bot agent establishes persistence along three independent paths: an SSH public-key backdoor (.ssh/authorized_keys), persistence files in multiple locations (/dev/shm/.a, /var/tmp/.a, /tmp/.a), and hidden cron watchdogs (/etc/cron.d/.sys_monitor, /etc/cron.d/.s)." ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first - CVE-2026-63030, CVE-2026-60137 (WordPress Core), CVE-2026-58644, CVE-2026-56164 (Microsoft SharePoint Server), CVE-2026-56155 (Microsoft Active Directory Federation Services), CVE-2026-53412 (Zoom Desktop Client for Windows and Zoom VDI Client for Windows), CVE-2026-44747, CVE-2026-27690, CVE-2026-44761 (SAP), CVE-2026-57219, CVE-2026-57221 (RabbitMQ), CVE-2026-59208, CVE-2026-54305 (n8n), CVE-2026-60105 (Monsta FTP), CVE-2026-14960, CVE-2026-14961 (tdeio64.sys driver), CVE-2026-33894, CVE-2026-33895 (Digital Bazaar node-forge), CVE-2026-6875 (ServiceNow AI Platform), CVE-2026-42533, CVE-2026-60005, CVE-2026-56434 (F5 NGINX Plus and NGINX Open Source), CVE-2026-20296, CVE-2026-20297 (Splunk Enterprise), CVE-2026-15265 (Tenable Agent), CVE-2026-6423 (ESET Inspect Connector), CVE-2026-15053 (Tanium Server), CVE-2026-44909, CVE-2026-59173, CVE-2026-59762 (HTTP/2 server implementations), CVE-2026-14890 (SGLang), CVE-2026-14266 (7-Zip), CVE-2026-59084 (Apache Tomcat), CVE-2026-15682 (AnyDesk), and CVE-2026-54523 (Kyverno). 🎥 Cybersecurity Webinars Your AI Agent Has Credentials. Can You Stop It When It Goes Rogue? Hands-on testing of OpenClaw shows how agentic AI can expose secrets, bypass safety controls, and create a powerful new attack surface. Join Okta Threat Intelligence Director Jeremy Kirk to examine how attackers are abusing AI agents and learn practical ways to control access, enforce least privilege, detect shadow AI, and shut down risky agents before they cause damage. When AI Ships 50× More Code, Human Review Stops Scaling → AI-assisted development is pushing code production beyond what traditional security reviews and CVE-driven remediation can handle. This webinar gives security leaders a practical framework for governing the expanding attack surface, building secure-by-default controls, and enabling teams to develop at machine speed without surrendering control of software risk. 📰 Around the Cyber World New Campaign Delivers Remcos RAT - A new malware distribution campaign has abused the credibility of government institutions to increase the likelihood of infection success. The activity targets Indian businesses and taxpayers using Goods and Services Tax (GST)-related themes to distribute malware. "The threat actors impersonated legitimate government departments and distributed malicious emails disguised as official notifications related to taxation, refunds, compliance requirements, and regulatory matters," Seqrite Labs said. "The threat actors employ convincing documents and filenames that closely resemble official GST notifications, making it difficult for recipients to distinguish malicious content from legitimate government correspondence." The end goal is to deploy Remcos RAT and steal sensitive information. India's Kudankulam Nuclear Power Plant Suffers a Data Leak - The Kudankulam Nuclear Power Plant located in the Indian state of Tamil Nadu suffered an accidental exposure after Reliance Infra (RPOWER) got hit by a ransomware group called World Leaks, a spin-off of Hunters International, which, in turn, is another variant of the Hive ransomware family. The leak consists of 18,997 files, totalling 14.3GB of data, per security researcher Rakesh Krishnan. They contain purported blueprints for the ventilation and cooling systems used in Unit 3 and Unit 4, along with a complete floor layout of a "common control room". It's assessed that Reliance Infra was not impacted directly, but rather through a third-party vendor named Yotta. In a statement shared on X, the Nuclear Power Corporation of India Limited said: "The scope of the contract includes Engineering, Procurement/supply, Construction and Commissioning of Common service facilities. These facilities are of conventional nature and are typically found in thermal power plants as well as other process industries. They are not related to nuclear safety or nuclear security systems." It also noted that "the information claimed to be available in the public domain pertains only to conventional Balance of Plant (BoP) common service facilities and does not relate to any nuclear safety - or nuclear security-related systems or information." Blind Eagle Shows No Signs of Stopping - Nearly a year after Blind Eagle's activities were documented, a new report from LevelBlue has found the threat actor to be active, moving part of its VBScript delivery infrastructure onto the Russian bulletproof hosting provider Proton66 as of June 2025. The group has also devised a bespoke string-obfuscation scheme, a RunPE loader built entirely on a bare AutoIt3 interpreter, and an upgraded version of AsyncRAT that introduces Windows Notification Facility (WNF) process injection, a custom Base28 payload encoding, a full Hidden VNC (HVNC) banking-fraud module with browser profile cloning, and a Chrome App-Bound Encryption (ABE) bypass, per LevelBlue. Qilin Ransomware Use of EDR Killer - Qilin ransomware operations have been observed adopting aggressive, kernel-level defense evasion to blind and disable endpoint security products before its main ransomware payload is executed on a victim's network. The EDR killer, packed via the Shanya packer, is sold on illicit marketplaces for $2,000. "The EDR killer compares the returned locale to a known locale blacklist to avoid attacking any Commonwealth of Independent States (CIS) countries such as Russia and Belarus," Flashpoint said. "The EDR killer then writes a vulnerable driver to disk and loads this driver via Service Manager. This driver is the ThrottleStop driver from TechPowerUp LLC's free and legitimate application of the same name, used to bypass CPU throttling. However, the driver suffers from a vulnerability, allowing the malware to map physical memory to kernel-mode virtual memory to perform direct kernel read and write operations." Also put to use is a custom Rust-written loader that performs reflective Portable Executable (PE) loading of the ransomware payload. DefiTuna Suffers a Security Incident - DeFiTuna, an Automated Market Maker (AMM) on the Solana blockchain, was exploited on July 16, 2026, for $569,601 USDC. "The attackers created a highly illiquid TUNA/USDC pool and used it as the destination for borrowed USDC routed through Jupiter," CertiK said. "Because the swap returned only a negligible amount of TUNA, DeFiTuna's value calculation rounded the position's total assets down to zero. The protocol then incorrectly treated the position as healthy, allowing the attackers to bypass the solvency check and withdraw the USDC through attacker-controlled liquidity positions." Next.js Opts for Scheduled Security Releases - Vercel announced that Next.js is adopting a formal security release program, replacing ad-hoc patches for security fixes following a surge in AI-assisted vulnerability discovery. "This kind of scheduled, pre-announced security release has become standard practice for major open source projects, and we think it's the right model for Next.js at its current scale," Vercel said. "Here's what you can expect going forward: roughly once a month, we'll publish advance notice of upcoming security releases. Each announcement will include the expected release timeline and the highest anticipated severity among the vulnerabilities it covers. This lead time lets you plan your upgrades, and it lets us coordinate with hosting providers and other platform partners to deploy mitigations, such as firewall rules, that help protect applications that haven't been patched yet." Disguised Gambling Apps Target Brazil - A new analysis from 9to5Mac has revealed more than 60 "jacket apps" on the App Store that are disguised as simple games and utilities that become online betting platforms when accessed from Brazilian IP addresses. Most of the apps are published by developer accounts with only a single App Store listing, with further investigation linking them to a "public GitHub repository containing instructions for a Cursor agent to create simple, vibe-coded apps that serve as fronts for the betting platforms." Ransomware Stats for Q2 2026 - The Gentlemen has become the most active ransomware group for Q2 2026, claiming 300 victims, surging past Qilin (289), DragonForce, Akira, and LockBit. Another group named Deadlock resurfaced after 11 months of silence with 75 June victims. In all, the top 11 tracked groups accounted for 1,368 of Q2's victim claims across 99 countries. "What sets The Gentlemen apart is its packaging, where affiliates receive ready-made tools that ship and update faster than most competing programs," ReliaQuest said. 2 Members of Chinese Money Laundering Network Charged with Laundering $43M in Investment Fraud - The U.S. Justice Department unsealed charges against a New York man and woman for conspiracy to launder money derived from cyber investment fraud scams. "Between 2020 and 2022, Zhuoying Chen, 27, of Brooklyn, New York, and Haojie Zhang, 38, of Queens, New York, managed a network of more than a dozen individuals based in Queens and Brooklyn, who opened 140 bank accounts in the name of approximately 45 shell companies to launder at least $43 million in proceeds of investment scams," the department said. "Then, Chen and Zhang allegedly conspired with China-based co-conspirators to transfer the funds involved in the fraud schemes abroad. The fraud schemes consist of perpetrators contacting victims via messaging services or social media applications. The perpetrators would initiate relationships with the victims and gain their trust, convincing victims to send money for lucrative investment opportunities. The perpetrators would show the victims fake profits on the purported investment and encourage the victims to invest more. The perpetrators would then steal the victim's funds." U.S. Cyber Agency Uses Mythos to Audit Government Code - Reuters reported that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is using Anthropic's AI model Mythos to audit government software for defects that could potentially offer a pathway for foreign spies and cybercriminals, citing three people familiar with the matter. 🔧 Cybersecurity Tools VisionSec → It is an open-source, self-hosted threat intelligence platform that combines domain monitoring, phishing detection, exposed-service scanning, GitHub secret discovery, breach checks, email security assessments, and Telegram alerts in a modular Docker-based deployment. The project remains at an early stage, with no published releases at the time of writing. owLSM → It is an open-source Linux security agent that uses eBPF LSM to run stateful Sigma rules inside the kernel, block malicious activity, correlate events across multiple probes, and provide detailed context for security monitoring and response. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you're doing stays on the right side of the law. Conclusion That is the week: exposed systems, weak checks, old tools, and attackers moving faster than patch cycles. Review what applies, fix the obvious gaps first, and assume anything public has already been tested.
thehackernews.comJul 20, 2026extracted
Oak Emerges From Stealth Mode With $60 Million in Funding
Israeli cybersecurity startup Oak has emerged from stealth mode with $60 million in seed funding to build an AI-powered Identity Operating System. The investment round was co-led by Accel, Greylock Partners, and CRV, with additional support from Hetz Ventures, AlphaDrive Ventures, and angel investors. Founded in late 2025, Tel Aviv- and San Francisco-based Oak has built a platform that unifies identity governance within a single, continuously updated control plane. Already generally available, Oak’s Identity Operating System aims to replace legacy identity governance and security tools with a single solution covering all human, AI, and machine identities across an organization’s environment. The platform connects to an organization’s applications across cloud, on-premises, SaaS, and homegrown systems to build connectors within hours, understanding each identity based on raw evidence instead of static records. By creating a map of each identity’s access against what it uses, Oak’s platform provides identity governance throughout the entire lifecycle, complemented by AI-driven real-time risk decisions and remediation. Oak was co-founded by Shai Morag (Chief Executive Officer), who previously founded Integrity-Project (acquired by NVIDIA’s Mellanox), Secdo (acquired by Palo Alto Networks), and Ermetic (acquired by Tenable); and Tal Marom (Chief Product Officer), who previously led product teams at Tenable and Salesforce. “We spent months speaking with more than 100 CISOs and IAM leaders, and they all share the same problems of running too many disconnected tools, being unable to see how access is used, and having no way to govern AI agents,” Marom said. “Just as CNAPP consolidated the fragmented cloud security stack, identity is now at that same inflection point, and Oak is designed to be the platform that brings it all together and turbocharges the security teams defending the enterprise,” Marom added. Related: Valarian Raises $50 Million for Sovereign Infrastructure Control Layer Related: QIZ Security Raises $17 Million for Cryptographic Governance Platform Related: 8Layers Raises $2.9 Million for Identity Security Platform Related: Keyfactor Scores $1 Billion+ Investment for AI, Post-Quantum Security
securityweek.comJul 16, 2026extracted
AI Can Find Bugs, But Human Knowledge Still Proves Them
Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs, and run repetitive testing workflows at impressive speed. That is a real advantage for security teams. It also creates a new kind of pressure, because the industry can now produce more vulnerability-looking output than ever before. The problem is that output is not the same as evidence. A generated report can sound polished, include a severity rating, and even contain a proof-of-concept that looks reasonable at first glance. None of that proves the bug exists in the deployed environment. None of it proves exploitability, impact, or risk. In offensive testing, the hard part has never been writing something that sounds like a vulnerability report. The hard part is demonstrating what is actually true. That distinction is becoming more important as AI becomes more common in security workflows. AI can accelerate discovery, but validation still depends on knowledge: knowledge of systems, protocols, application behavior, identity boundaries, memory corruption, business logic, and all the implementation details that separate a plausible theory from a real exploit. The future of offensive security will not belong to people who merely produce the largest number of findings. It will belong to people and teams that can prove what matters. The Industry Is Already Seeing the Cost of Shallow AI Output The warning signs are already visible. Bug bounty programs and maintainers have been dealing with a surge of low-quality AI-generated reports, often submitted with thin evidence, templated language, and little meaningful validation. Bugcrowd publicly addressed this pattern in its policy changes around AI-generated submissions, describing a class of reports that looked polished but created unnecessary triage burden rather than a useful security signal. This is not just a bug bounty problem. It is a preview of what happens anywhere AI is used to create security findings without enough human judgment behind them. If a tool can generate a convincing write-up in seconds, organizations will receive more reports, more alerts, and more claims. Unless those claims are validated, the result is not better security. It is a larger queue. Security teams are already overloaded with scanner output, dependency alerts, cloud configuration issues, and compliance findings. Adding AI-generated speculation on top of that does not help unless the quality bar goes up at the same time. A finding should answer basic questions clearly: what happened, how it was reproduced, what the attacker controls, which boundary was crossed, and what the demonstrated impact is. Without that, the report may be interesting, but it is not ready to drive engineering action. “Looks Vulnerable” Is Not the Same as Vulnerable One of the most dangerous habits in offensive testing is confusing a suspicious pattern with a validated vulnerability. AI can make that habit worse because it is good at explaining why something might be bad. A model may see user input near a database query and describe SQL injection. It may see a URL fetch and suggest SSRF. It may see a dangerous API in a code path and describe remote code execution. Sometimes the model is pointing at a real issue. Other times, it is missing the conditions that decide whether the issue matters. A tester still has to prove reachability. Does the attacker-controlled input actually reach the dangerous operation? Is authentication required? Is authorization enforced somewhere else? Is the vulnerable feature enabled? Does the production configuration expose the code path? Does the application normalize, encode, sanitize, or reject the payload before it matters? Does the issue cross a trust boundary or merely affect an internal-only path with no practical security impact? These questions are where real offensive security begins. They are also where shallow automation often breaks down. AI can generate hypotheses quickly, but hypotheses are not findings. A good tester treats AI output as a lead to investigate, not a conclusion to forward. Why Knowledge Still Matters The best offensive security practitioners are valuable because they understand systems, not because they can run tools. Tools have always been part of the job, but tool output has never been enough. A web scanner may identify a parameter that reflects input. A static analyzer may flag a dangerous function. A fuzzer may produce a crash. A language model may describe a plausible attack path. In every case, someone still needs to understand what the signal means. That understanding is usually earned through repetition. Senior researchers spent years doing the work manually: tracing requests, reading source, reverse engineering binaries, debugging crashes, writing exploit code, breaking authentication flows, and learning how real systems fail. That process builds memory and instinct. It teaches a practitioner when a finding is probably real, when a tool is being misled, and when a small bug may become serious if chained with something else. This kind of knowledge is hard to fake. It shows up in the questions a tester asks. It shows up in the way a report is written. It shows up in whether the tester can explain the exploit path without hiding behind generic language. Most importantly, it shows up when the first attempt fails. A person who understands the system can adapt. A person who only accepts the tool’s explanation is often stuck. AI Can Make Good Testers Faster, but Can Also Make People Rusty There is a real concern among experienced practitioners that overdependence on AI can make people rusty. This is not an anti-AI argument. It is a human learning argument. When a tool answers every question instantly, it becomes tempting to stop remembering details. When it writes the first version of every script, it becomes tempting to stop practicing. When it explains every code path, payload, crash, and error message, it becomes tempting to stop building the mental model yourself. That convenience has a cost. Offensive security rewards depth, pattern recognition, and technical recall. The hardest findings often come from recognizing that a behavior in one area violates an assumption somewhere else. They come from knowing how parsers, frameworks, allocators, identity providers, and authorization systems have failed before. They come from seeing the connection between small details that do not look important in isolation. If practitioners stop exercising those muscles, they lose some of the very skill that makes them effective. The risk is not that AI makes security professionals useless. The risk is that people let AI do too much of the thinking too early, then mistake fluency for competence. Prompting is useful, but it is not a replacement for judgment. Most AI-Assisted Testing Still Uses Familiar Techniques A lot of AI security marketing can make it sound as if machine learning is discovering vulnerabilities through some entirely new kind of reasoning. Sometimes models do surface patterns a human might miss, especially across large and unfamiliar codebases. That is useful. But in many practical offensive testing workflows, the underlying techniques are still familiar: enumerate endpoints, inspect parameters, trace data flow, compare authenticated and unauthenticated behavior, generate payloads, run fuzzers, observe responses, and determine whether the application state changed in a security-relevant way. In other words, many AI-enabled systems are orchestrating known testing techniques at scale. They can plan, execute, observe, and iterate faster than a human doing everything by hand. That is a meaningful improvement, but it does not remove the need to understand the result. If the system reports an authorization flaw, someone still has to know whether the object relationship matters. If it reports a memory corruption bug, someone still has to reason about reachability, crash context, mitigations, and exploitability. If it reports an API weakness, someone still has to determine whether the observed behavior violates the application’s trust model. The most valuable use of AI is not to replace those decisions. It is to reduce the mechanical work around them so skilled testers can spend more time on analysis and validation. What Good Validation Looks Like A validated offensive finding should be specific, reproducible, and tied to impact. It should not require the reader to guess why the issue matters. The report should make the exploit path clear enough that an engineer can reproduce it and a security leader can understand the risk. That does not mean every issue needs a dramatic exploit chain or a movie-style proof-of-concept. It means the evidence should support the claim. For AI-assisted testing, teams should draw a sharp line between leads and validated findings. A lead is something worth investigating. A validated finding is something that has been tested and proven. Mixing those categories creates confusion and wastes time. A good workflow can absolutely use AI to generate leads, but the promotion from lead to finding should require evidence. Practical Validation Checklist A practical validation standard does not need to be complicated. Before a lead becomes a reported finding, the tester should be able to answer questions like these: What specific behavior was observed, and where did it occur? What attacker-controlled input, identity, or state was required? What security boundary was crossed, such as authentication, authorization, tenancy, trust, privilege, or memory safety? What exact steps reproduce the behavior in the target environment? What is the demonstrated impact, not just the theoretical worst case? What evidence shows that the issue is reachable and relevant in the deployed configuration? What would a fix need to change, and how can the team confirm that the fix works? This kind of checklist helps keep AI in the right role. It can help produce candidates, suggest test ideas, and speed up reproduction. It should not be allowed to skip the step where a human verifies the claim against reality. The Human Role Is Still Technical One of the underappreciated realities of AI security platforms is that human validation remains deeply important behind the scenes. That should not be surprising. Offensive security has always required judgment, and judgment is especially important when findings become consequential. The person reviewing the evidence has to decide whether the exploit path is realistic, whether the environment matters, whether the issue is isolated or chainable, and whether the severity claim is justified. This is not just an administrative quality-control function. It is technical work. Authorization flaws often depend on business logic and object relationships. API vulnerabilities may require understanding how roles, tenants, and resources interact. Memory corruption requires reasoning about crash state, control, mitigations, and exploit primitives. Cloud findings depend heavily on identity, trust policies, and service-specific behavior. AI can assist with all of this, but it does not remove the need for someone who knows what they are looking at. The higher the impact of a finding, the more important the human role becomes. Organizations do not want a confident guess when the result may affect engineering priorities, customer trust, compliance obligations, or executive risk decisions. They need proof. Avoiding Exaggerated Impact AI-generated reports can also overstate severity. Reflected input is not cross-site scripting until script execution is demonstrated. A URL fetch is not meaningful SSRF until the tester can show access to something the attacker should not reach. A dangerous function is not remote code execution unless reachability, control, and execution can be proven. These mistakes are not just embarrassing; they erode trust between security teams and engineering teams. It happens quite often that a finding will get a rating of CVSS 9.8, when in fact it might not even be a finding at all. Experienced researchers are careful with impact because they know it has to be earned. A bug in an admin-only feature does not carry the same risk as an unauthenticated internet-facing bug. A crash may be a denial of service, a path to code execution, or simply an unexploitable reliability issue, depending on the context. A missing check in one code path may be serious, or it may be protected by a control somewhere else. The only way to know is to validate. Good validation prevents both underreporting and overreporting. It helps testers avoid crying wolf, but it also gives them the evidence needed to make a strong case when the issue is genuinely serious. Tenable also recently brought up challenges in this space, including how there are often critical contextual combinations that are also missed. How Teams Should Use AI Without Losing Skill The right goal is not to avoid AI. The technology is too useful for that. The right goal is to use it in a way that strengthens offensive testing instead of weakening the people doing it. AI should help testers move faster, explore more hypotheses, and reduce repetitive work. It should not become a substitute for learning how systems behave. Security leaders can encourage that balance by setting expectations around evidence and training. Junior testers should still learn fundamentals before they outsource too much of the process. Senior testers should use AI as a force multiplier, not as an authority. Teams should review not only whether a finding was generated, but whether the tester can explain and reproduce it. That explanation is where real understanding becomes visible. A healthy AI-assisted offensive testing program should reward validated impact over volume. It should measure signal quality, not just finding the count. It should preserve manual practice in areas like request manipulation, code review, debugging, exploit development, threat modeling, and impact analysis. It should also use AI as a teaching tool: when the model suggests an issue, the tester should ask why, test the claim, and learn from the result. The Standard Has Not Changed: Prove It AI will continue to improve. Agents will become better at navigating applications, reading code, generating payloads, and documenting results. Some of this progress will be genuinely impressive, and security teams should take advantage of it. But offensive security cannot become a volume game where every plausible theory becomes someone else’s triage burden. The core standard of the field is still simple: prove it. Prove the bug exists. Prove the attacker can reach it. Prove the impact. Prove the business risk. Prove the fix works. AI does not lower that standard. If anything, it raises the importance of enforcing it, because convincing but unproven output is now easier to produce than ever. The best researchers and teams of the next decade will not be the ones that reject AI. They will be the ones who combine automation with technical judgment, using the machine to accelerate the work without handing it the final say. Knowing when to stop, inspect, test, and think will remain a competitive advantage. Knowledge still matters because validation still matters, and in offensive security, validation is the difference between noise and truth. I will be expanding on this topic in SEC660: Advanced Penetration Testing, Exploit Writing, and Ethical Hacking at SANS Network Security 2026. Our course update blends together manual understanding of complex topics, such as exploit writing, and instructs how to leverage AI to assist in automating specific tasks. Note: This article has been expertly written and contributed by Stephen Sims, SANS Fellow.
thehackernews.comJul 16, 2026extracted
Tenable One unifies code risks with enterprise exposure data
Tenable One unifies code risks with enterprise exposure data Tenable has announced the expansion of the Tenable One Exposure Management Platform, unifying application security risks with all other exposure data. By integrating static code vulnerability data, Tenable One delivers complete, code-to-runtime visibility across the entire attack surface. Security teams have long struggled with a code security problem where vulnerable code reaches production faster than it can be reviewed. This problem is exacerbated by the use of generative AI, which empowers developers to ship code three to four times faster, while potentially introducing flaws at 10x the rate. Application security teams and developers rely on siloed solutions that lack the contextual infrastructure intelligence required to determine if a code vulnerability poses a real-world threat to the business. This disconnected approach creates a major and exploitable blind spot. Tenable One ingests, analyzes and normalizes data from relevant application development and security sources, including AI application security tools, such as Claude Security. Tenable One then connects all ingested exposure data, unifying Tenable telemetry with data from other security tools, including endpoint protection, cloud security, vulnerability management, operational technology security and more, and vital business context from repositories like configuration management databases, designed to deliver the most complete view of enterprise risk, and accelerate remediation prioritization and action. With this platform expansion, Tenable One shifts organizations from reactive application scanning to proactive risk prioritization, connecting code risks to the runtime systems, cloud workloads, identities and attack paths they put at risk. “Bringing application security data into Tenable One, we’re giving our customers the context they’ve been missing,” said Eric Doerr, Chief Product Officer, Tenable. “Security teams don’t need to wade through a sea of vulnerabilities. With Tenable One, security teams know exactly where they are exposed the moment an exposure is created – whether an agentic AI security tool discovers a new zero-day in an open-source library or a human error introduces risk. For the first time, security teams can see code flaws and prioritize remediation actions alongside all other forms of risk for more effective risk reduction,” Doerr concluded.
helpnetsecurity.comJul 16, 2026extracted
F5 Patches Multiple NGINX, BIG-IP Vulnerabilities
F5 on Wednesday announced an out-of-band security rollout that patches eight vulnerabilities in NGINX and BIG-IP. The most severe flaw is CVE-2026-42533 (CVSS score of 9.2), a critical issue in NGINX Plus and NGINX Open Source that could be exploited via crafted HTTP requests to cause a heap buffer overflow and restart the NGINX worker process. “A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map’s regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression under certain conditions,” F5 explains. An attacker can exploit the security defect without authentication, but only under conditions they cannot control. On systems with Address Space Layout Randomization (ASLR) disabled, the attacker can achieve code execution. F5’s patches also resolve several high-severity NGINX bugs, including weaknesses in the ngx_http_slice_module module and the ngx_http_ssi_module module that can be exploited without authentication. Successful exploitation of the flaws allows attackers to leak memory contents, restart the NGINX worker process, or cause a use-after-free in the NGINX worker process to modify memory or restart the process. Two high-severity vulnerabilities addressed in NGINX Ingress Controller could allow authenticated attackers to inject arbitrary NGINX configuration directives to delete files and disable services, or create or modify Ingress or TransportServer resources to cause a denial-of-service (DoS) condition. F5 also resolved a high-severity security defect in BIG-IP that could be exploited by remote, unauthenticated attackers to increase memory resource utilization when an HTTP/2 profile is configured on a virtual server, causing a DoS condition. F5 makes no mention of any of these vulnerabilities being exploited in the wild. Additional information can be found in the company’s out-of-band security notification. Related: Trend Micro, Tanium, ESET, and Tenable Patch Severe Product Vulnerabilities Related: Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell Related: Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
securityweek.comJul 16, 2026extracted
Old UEFI Shims Expose Systems to Secure Boot Bypass
Nearly a dozen Unified Extensible Firmware Interface (UEFI) shim bootloaders signed by Microsoft allow attackers to bypass Secure Boot protections, ESET warns. Small, trusted pieces of software bridge a computer motherboard’s UEFI firmware and the operating system, typically a Linux distribution, enabling the machine to boot with Secure Boot enabled. By using Microsoft-signed UEFI shim bootloaders, Linux distributions can establish a trust model without requiring individual keys to be built into the motherboard’s NVRAM. The shims allow bootloaders, kernels, and other components to run during Secure Boot. While various vulnerabilities have been addressed in the open source shim project over time, not all vendors updated their bootloaders, and these older shims remained signed and trusted within the Secure Boot chain, exposing systems to potential attacks. According to ESET, 11 such old, forgotten UEFI shims, primarily from version 0.9 and earlier, lingered around until revoked by Microsoft on June 2026 Patch Tuesday. Two CVEs were assigned, namely CVE-2026-8863 and CVE-2026-10797. The vulnerable shims, ESET says, could be exploited to “bypass UEFI Secure Boot on any UEFI-based machine that trusts Microsoft’s Microsoft Corporation UEFI CA 2011 third-party UEFI certificate authority (CA) certificate, regardless of the installed operating system (OS).” Coming from various tools and packages, these shims extend the attack surface through their trusted second-stage bootloaders. Additionally, attackers could bring their own vulnerable shims to systems that have enrolled the Microsoft third-party UEFI certificate. “Signing and compilation timestamps of the applications trusted by the shims we reported span from 2013 to 2025 – enough to confirm that a significant portion of these binaries were old and likely affected by numerous publicly known vulnerabilities, [such as] BootHole in the case of GRUB2,” ESET notes. Continuous trust in these old, vulnerable shims allows attackers to execute untrusted code during the boot process and deploy bootkits even if Secure Boot is enabled. ESET reported the findings to CERT/CC in February 2026. In June, Microsoft revoked all vulnerable applications and added them to the UEFI DBX (Forbidden Signature Database). According to CERT/CC, system admins should update the signature database (DB) before applying DBX revocations. “In practice, this means updating trusted boot applications and certificates first, followed by deployment of the revocation list. Failure to follow this order may cause systems to reject newly updated boot components. Enterprises, virtualization providers, and cloud operators managing large-scale deployments should prioritize validation and deployment of these updates to prevent the execution of vulnerable or unsigned binaries during physical or virtual machine startup,” CERT/CC notes. Since 2017, shims have been signed and documented after a vetting process, but those approved before then are not documented, and many old, still-trusted shims may remain, potentially exposing systems to attacks. Related: New Exploit Bypasses Apple’s Boot Defenses, Affects Millions of iPhones Related: Nightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day Related: Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities Related: Unpatched Cursor Vulnerability Exposes Users to Code Execution
securityweek.comJul 16, 2026extracted
Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities
Cybersecurity companies TrendAI (Trend Micro), ESET, Tenable, and Tanium released product updates this month to patch severe vulnerabilities. Tenable told customers this week that it has fixed a critical-severity path traversal in the Tenable Agent. The security hole, tracked as CVE-2026-15265, may allow an attacker to achieve remote code execution. [ Read: SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits ] ESET informed customers on Tuesday that it has discovered and patched a high-severity local privilege escalation vulnerability in Inspect Connector for Windows. “On systems with the affected ESET product installed, an attacker could send self-crafted Advanced Local Procedure Call (ALPC) requests to the vulnerable process’ interface,” ESET explained in its advisory. “Without proper authentication or origin validation in place, this message would be accepted and processed, enabling the attacker to access restricted functionality.” ESET has also published a separate advisory for a medium-severity DoS vulnerability in its security products for Linux. Tanium informed customers last week about a high-severity DoS flaw affecting Tanium Server. “This vulnerability could allow an unauthenticated, network-based attacker to perform a denial of service attack against the Tanium Server,” the company noted. Trend Micro informed Cleaner One Pro users last week of a medium-severity arbitrary file deletion vulnerability that could “allow a malicious app already running on your device to trick the cleanup process into deleting a file it shouldn’t have access to.” The vendor noted that local access is required for exploitation and the vulnerability cannot be exploited remotely. Palo Alto Networks also released patches this month, addressing over a dozen vulnerabilities in its products. While there is no evidence of exploitation for the latest vulnerabilities, it’s not uncommon for threat actors to target security products in their attacks. For instance, Palo Alto Networks and Trend Micro recently confirmed in-the-wild exploitation. *the information and the link for the Trend Micro vulnerability have been updated; it initially erroneously referenced an older vulnerability. Related: Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow Related: Vulnerabilities Patched in CrowdStrike, Tenable Products Related: Trend Micro Patches Critical Apex One Vulnerabilities
securityweek.comJul 16, 2026extracted
AI-driven bug hunting fuels record Microsoft Patch Tuesday
AI-driven bug hunting fuels record Microsoft Patch Tuesday Microsoft has released patches for 570+ vulnerabilities on July 2026 Patch Tuesday, including two that are being leveraged by attackers (CVE-2026-56155 and CVE-2026-56164), and one that was previouly disclosed (CVE-2026-50661). The release was once again followed by Nightmare Eclipse publishing a stripped down proof-of-concept exploit for an unpatched Windows elevation of privilege (EoP) vulnerability, which the researcher dubbed LegacyHive. Vulnerabilities of note CVE-2026-56155 is an EoP flaw affecting Active Directory Federation Services (ADFS), and has been spotted being exploited in the wild by Microsoft’s incident responders. Fixes for it have been bundled into Windows and Windows servers updates, and Microsoft also announced it’s started hardening the Access Control List (ACL) on the AD FS Distributed Key Manager container. “[This vulnerability] stems from insufficient access-control granularity and does require local access and low privileges to start, but AD FS is exactly the kind of identity infrastructure attackers love to pivot through once they’re in. It can also be paired with an RCE as we often see in ransomware. Test and deploy this patch quickly,” commented Dustin Childs, head of threat awareness at TrendAI’s Zero Day Initiative. CVE-2026-56164 is an EoP flaw found in Microsoft SharePoint Server that has been reported by Google’s incident responders and an anonymous researcher. It’s remotely exploitable in low-complexity attacks, and attackers are already taking advantage of it. While enabling the Antimalware Scan Interface (AMSI) feature on SharePoint servers is noted as a possible mitigation, implementing security updates is still a must, especially because they fix additional SharePoint remote code execution vulnerabilities (CVE-2026-50522 and CVE-2026-58644) and a critical security feature bypass flaw (CVE-2026-55040). “Discovered by Rapid7 Senior Principal Security Researcher Stephen Fewer, and published (…) in coordination with Microsoft, [CVE-2026-55040] is the first in a pair of exploits which, when chained together, can lead to unauthenticated remote code execution against a vulnerable SharePoint server,” commented Adam Barnett, Principal Software Engineer at Rapid7. The second vulnerability in the full RCE chain remains embargoed for now, and Microsoft is expected to publish patches for it in August 2026, he added. In other developments, the US Cybersecurity and Infrastructure Security Agency (CISA) has urged organizations running SharePoint servers to apply additional hardening measures, in light of the fact that attackers are also exploiting two recently patched vulnerabilities (CVE-2026-32201 and CVE-2026-45659). CVE-2026-50661 is a Windows BitLocker security feature bypass vulnerability that has been disclosed but not (yet) actively exploited. “While not confirmed at this time, this CVE may be the patch for GreatXML, a BitLocker bypass exploit released by the Nightmare-Eclipse persona,” Crowdstrike noted. Security patching in the age of AI-assisted vulnerability discovery The flood of new vulnerabilities was expected and pre-announced, as Microsoft recently confirmed it’s been using AI to speed up internal discovery of software vulnerabilities. The company also noted that other security researchers and attackers have been doing the same. “If you’re not delivering critical quality updates with security fixes until a couple of weeks after they’ve been issued, that’s ample time for attackers using AI to find and exploit known security gaps,” Microsoft said. “To address this, we’ve updated our recommendations for deploying Windows updates to less than three days as the deferral period for quality updates, setting deadlines for those updates to zero or one day, and the update grace period to a maximum of two days.” Satnam Narang, senior staff research engineer at Tenable, also pointed out that the state of the Exploitability Index (how likely a vulnerability is to be exploited) must shift with the machine speed of discovery. “For example, Microsoft originally tagged CVE-2026-45659, a SharePoint vulnerability, as exploitation less likely. However, the vulnerability was added to the CISA KEV on July 1,” he noted. “Anthropic’s Red Team’s own findings for known vulnerabilities (n-days) revealed how fragile this system has become, with its Mythos Preview model being able to produce proof-of-concept exploits for 13 of 14 vulnerabilities that were rated ‘Exploitation Less Likely’ or ‘Exploitation Unlikely.’ What this means is that our way of looking at Patch Tuesday has changed, because the exploitability index is centered around humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it.” Cybersecurity agencies of Five Eyes countries have recently advised organizations to integrate AI tools into their security operations so they can “detect vulnerabilities earlier, improve software quality, monitor unusual behaviour, and respond faster to incidents.” They’ve also urged them to: Reduce their attack surface by limiting access to them Accelerated the patching process and prioritise security updates according to risk Address legacy systems (i.e., decommission themm if possible) Strengthen identity and access controls Prepare for incidents before they happen. UPDATE (July 16, 2026, 02:20 a.m. ET): Microsoft has updated the security advisory for CVE-2026-58644, one of the SharePoint RCE vulnerabilities it fixed in June but for which the advisory was released only this Tuesday, to say that it is being exploited by attackers. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comJul 15, 2026extracted
Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence. Nearly 60 of the bugs quashed in July’s Patch Tuesday earned a “critical” severity rating, meaning miscreants or malware could use them to seize remote control over a Windows device with little or no help from the user. Microsoft also addressed three zero-day flaws, including two that are already being exploited in the wild. Two of the zero-day weaknesses allow an attacker to elevate their user rights on a Windows system, as do approximately 250 other elevation of privilege flaws fixed this month; they include CVE-2026-56155 — an Active Directory Federation Services bug — and CVE-2026-56164, a Microsoft Sharepoint vulnerability. CVE-2026-50661 is a security feature bypass in Windows BitLocker that could allow attackers to gain access to encrypted data if they have physical access to the device. Microsoft said this bug has been detailed publicly, but that it is not aware of any active exploitation. In a blog post on July 9, Microsoft Executive Vice President Pavan Davuluri wrote that Windows users will notice “a higher volume of security updates included in each security release” as a result of AI aiding in the discovery of vulnerabilities. “The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code, with new mechanisms that can accelerate both discovery and analysis,” Davuluri wrote. Jack Bicer, director of vulnerability research at Action1, called attention to CVE-2026-48561, a remote code execution flaw in Microsoft Copilot (with a 9.6 CVSS threat score) that allows an unauthorized attacker to execute code over the network. Microsoft says an attacker could exploit this bug by hosting a malicious website that causes Microsoft Edge for Android to automatically send crafted prompts to Copilot when a user visits the site. As AI advances the state of vulnerability discovery and remediation, it is also making it easier for attackers to quickly devise working exploits for known software flaws. Microsoft has long labeled security bugs using its “exploitability index,” which is Redmond’s best guess as to how likely it is that attackers will be able to figure out a reliable way to exploit a given vulnerability. But Satnam Narang, senior staff research engineer at Tenable, argues that Microsoft’s exploitability index needs to do a better job of shifting with the machine speed of discovery. For example, Microsoft originally gave this month’s SharePoint zero-day an exploitability rating of “less likely,” although the flaw was added to CISA’s Known Exploited Vulnerabilities list on July 1. “Anthropic’s Red Team’s own findings for known vulnerabilities (n-days) revealed how fragile this system has become, with its Mythos Preview model being able to produce proof-of-concept exploits for 13 of 14 vulnerabilities that were rated ‘Exploitation Less Likely’ or ‘Exploitation Unlikely,'” Narang said. “What this means is that our way of looking at Patch Tuesday has changed, because the exploitability index is centered around humans, not AI tools, and as these tools continue to improve, defense needs to improve alongside it.” Chris Goettl at Ivanti observed that the record patch numbers from Microsoft come as a number of other major software makers are increasing their patch cadence, including Adobe which announced today it is moving to twice-monthly security bulletins published on the 2nd and 4th Tuesday of each month (Adobe also cited AI for accelerating their patch cycles). Cisco, Mozilla and Oracle also are shipping updates more frequently, while Google’s patch batches in June 2026 totaled more than 900 security fixes, Goettl noted. Backing up your Windows system and/or data is always a good idea before applying operating system updates. Given the volume of patches addressed this month it may be wise for end users to wait a few days before applying these fixes. It’s not uncommon for security patches to introduce system stability issues, and those chances probably increase quite a bit with the gigantic patch count released today. Further reading:
krebsonsecurity.comJul 14, 2026extracted
Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days
Microsoft on Tuesday announced patches for a record-breaking 622 vulnerabilities, including two bugs in Active Directory and SharePoint Server that have been exploited in the wild as zero-days. Tracked as CVE-2026-56155, the exploited AD flaw affects Federation Services (AD FS) and could allow attackers to elevate their privileges locally to administrator. Also leading to privilege escalation, the SharePoint Server flaw is tracked as CVE-2026-56164 and can be exploited over the network without authentication. Another security defect that Microsoft drew attention to is CVE-2026-50661, a BitLocker security feature bypass issue that can be exploited by physical attackers and which was publicly disclosed before the July 2026 Patch Tuesday. “We surmise that this could be related to a flurry of zero-day vulnerabilities disclosed by the researcher known as Nightmare-Eclipse or Chaotic-Eclipse, though no official confirmation was made,” Tenable senior staff research engineer Satnam Narang commented. According to Microsoft’s release notes, Windows received fixes for 416 vulnerabilities this month, while the Office suite received patches for 164 of them. Some of the security defects that deserve special attention include critical flaws in Windows VMSwitch, tracked as CVE-2026-57092 (CVSS score of 9.9), and SharePoint, tracked as CVE-2026-50522 (CVSS score of 9.8), ZDI says. An XSS in Exchange Server (CVE-2026-55008) and remote code execution (RCE) bugs in the Remote Desktop Protocol (CVE-2026-56190), Windows DHCP Server (CVE-2026-50518), Windows Server Network driver (CVE-2026-56188), and Minecraft Bedrock Dedicated Server (CVE-2026-55010) also deserve increased attention. Microsoft’s massive round of security updates resolves security weaknesses across several other products, including Azure, Defender, Developer Tools, Exchange Server, Edge, and SQL Server. With 622 vulnerabilities, the July 2026 Patch Tuesday rollout pushes Microsoft’s year-to-date CVE count above totals from other years, but it is not a surprise. Last week, Windows executive VP Pavan Davuluri announced that AI is speeding up vulnerability discovery and that Microsoft is using multi-model agentic scanning harness (MDASH) to surface bugs faster across the Windows codebase. “We continue to evolve our internal systems and practices so that vulnerability discovery is not treated as a separate activity, but as part of how we build, review, and improve Windows before new features or updates are released,” Davuluri said. On the July 2026 Patch Tuesday, Adobe released fixes for 88 vulnerabilities, including critical bugs in ColdFusion, Commerce, Experience Manager, and Illustrator. Related: SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud Related: Microsoft Patches Defender ‘RoguePlanet’ Vulnerability Related: Palo Alto Networks Patches 13 Vulnerabilities
securityweek.comJul 14, 2026extracted
Google told researcher 'Nice catch!' Then denied bug bounty for flaw it still hasn't fixed
EXCLUSIVE Google has a security hole in a Kubernetes operator that could allow attackers to bypass Google Cloud Platform (GCP) identity and access protections and gain full control over any organization's cloud environment. Or it has a serious communication and transparency problem when it comes to its bug bounty programs. Maybe both. Researcher and frequent cloud bug hunter Justin O'Leary told us that he found and reported to Google a major flaw that allows any Kubernetes namespace user to bypass GCP's Identity and Access Management (IAM) controls and therefore gain root access to managing an organization's cloud resources. Google initially rated the bug high priority and high severity, with a rep telling O'Leary, "Nice Catch!" Then, the cloud giant changed course and told O'Leary and The Register that there's no vulnerability, so no fix and no reward payout. The bug report, however, is still marked high-priority and accepted. O'Leary spoke exclusively with The Register about the vulnerability, which he named ConfigConfusion, and what has happened since he reported it to Google on March 8. He is also releasing a blog post with more details. It stems from an issue in Config Connector, an open source Kubernetes add-on that lets users manage Google Cloud resources through Kubernetes. According to O'Leary, Config Connector doesn't perform an authorization check, and this allows any Config Connector service account with org-level permissions to bypass Identity and Access Management (IAM) authorization and gain the highest level of control (roles/owner) to an entire GCP Organization – the root node of all of a company's resources within Google Cloud. On March 27, a Google security engineer accepted O'Leary's report and told him: "Nice catch!" The employee said that they filed a bug based on O'Leary's report with the relevant product team and assured him the Chocolate Factory's security squad would work with relevant Google Cloud people to fix the flaw. "We'll work with the product team to ensure this issue is addressed. We'll let you know when the issue was fixed," the engineer said. "In the meantime, review the payment option selected in your bughunters.google.com profile." Google assigned the bug P1 priority and S1 severity, signifying a flaw worthy of urgent repair because it affects a large percentage of users and can disrupt core organizational functions. "I figured that was the end of that," O'Leary said in a phone interview with The Register. Eleven days later, on April 7, he received a new message from a Google Security Bot reversing the earlier decision. The Reg viewed the email, and O'Leary included a screenshot in his Thursday writeup. The message said that the Cloud Vulnerability Reward Program panel decided that the "security impact of this issue does not meet the criteria to qualify for a reward." After reviewing the bug report, Google determined the software "is working as intended," the message continued. It also noted that the program's decision not to pay a bounty "does not mean that the product team won't fix the issue." Nearly three months later, the case remains P1/S1 with the status "in progress (accepted)." Google hasn't assigned a CVE or issued a fix. O'Leary didn't receive any reward for his research. This isn't the first time this has happened to O'Leary – or other security researchers submitting bug bounty reports. O'Leary had a similar experience with Microsoft earlier this year. In a story that has become all too familiar among bug hunters, O'Leary disclosed a privilege escalation vulnerability in Azure Backup for AKS. Microsoft rejected his report – and then silently patched the flaw without assigning a CVE or publishing a security advisory. "This is a pattern," O'Leary told us. "This is just how these trillion-dollar companies deal with people like me. In my day job, we use GKE, and it's incredibly frustrating on my end, when I find a critical vulnerability in the system that's being widely used, and I can't even get the vendor to patch their own stuff." Google's response When The Reg asked Google about O'Leary's situation, the company told us that it didn't issue a bug bounty reward because there's no vulnerability. “The issue reported does not qualify for a reward because the GCP IAM authorization bypass is only exploitable if an attacker has access to a Config Connector Service Account that’s been granted the Organization Admin role by the organization (i.e., it is privileged)," a Google spokesperson said in an email to The Register. "Additionally, an attacker would first need to gain entry to an organization's environment (e.g., an exposed container) in order to leverage the privileged Config Connector instance and execute commands with administrative authority, such as the IAM bypass," the spokesperson continued. "Granting this level of access to the Config Connector Service Account goes against Google Cloud’s publicly shared best practices and the principle of least privilege." Google did not answer The Register's questions about why the bug report case remains marked in progress – and not closed – on its end of things. O'Leary told us this is the same explanation he received. And he doesn't buy it. Yes, the Config Connector service account does need org-level permissions to manage resources across multiple GKE clusters. But Google's own documentation instructs users how to do this, he noted. We confirmed this as well. Moreover, "having those permissions doesn't mean any namespace user should be able to abuse them," O'Leary posited. "A developer with kubectl access to one namespace – and zero GCP IAM permissions – should not be able to become Organization Owner. They also shouldn't be able to impersonate any service account in the project with no audit trail." According to O'Leary: "The vulnerability is the missing authorization check. Config Connector executes privileged operations on behalf of users without verifying those users are authorized." Three lines, five seconds, full admin control In a video demonstrating ConfigConfusion, O'Leary shows how an attacker can write three lines of YAML to achieve full administrative control of a GCP Organization in about five seconds. "Config Connector has these missing validation checks," he said. "Config Connector is basically a Google-managed Kubernetes operator, and I found that having these missing validation checks creates these confused deputies, which means there's no validation of who's asking for what." Confused deputies pose a major security challenge because they allow an entity that doesn't have permission to perform an action to force a more-privileged entity to perform the action. To exploit this issue, a user with kubectl access to one namespace – and no GCP permissions – submits a malicious IAMPolicyMember, which escalates the attacker's privileges. Config Connector passes the user-controlled organization ID directly to the GCP IAM API without performing an authorization check, making the user a GCP Organization owner. This gives the attacker full admin control over everything in the environment – projects, secrets, billing, and Gmail accounts. "And there's no record of it," O'Leary said. This is because "the attacker's Kubernetes identity never touches GCP IAM," he wrote in the disclosure. "Config Connector executes the request using its own elevated credentials." 'Jenga' vulnerabilities According to O'Leary, Google has fixed this confused-deputy issue twice before in different services that access GCP. Tenable Research documented those issues and reported them to Google. One, called ImageRunner, abused permissions in Google Cloud Run to pull private Google Artifact Registry and Google Container Registry images in the same account. The second, ConfusedComposer, allowed an identity with edit permissions inside a Cloud Composer environment to escalate privileges to the default Cloud Build service account. "This privilege-escalation vulnerability in GCP builds upon a broader attack class of vulnerabilities in cloud services that we call 'Jenga,'" Tenable security researcher Liv Matan said at the time. ConfusedComposer "exploits the somewhat-hidden cloud provider misconfigurations related to cloud services permissions to escalate privileges beyond intended access levels," Matan explained. "This variant highlights how attackers can abuse interconnected services the cloud provider automatically deploys behind the scenes, as part of a service-orchestration process." Google ultimately added authorization checks to both Cloud Run and Cloud Composer. O'Leary says he doesn't understand why Google can't also add that check to Config Connector. Or perhaps he does. "It's just me versus Google," he said. "They can't do that same level of gaslighting to Tenable because they have PR teams and legal teams to fight them. I'm just a guy saying I don't understand how this is true" – that is, how something can be both a high-severity, high-priority bug and also working as intended. "And they just say: 'Well, it is true.'" ®
theregister.comJun 18, 2026extracted
ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories
It's been one of those weeks. You expect the usual noise: recycled malware, sloppy attacks, another easy target getting hit. Instead, there's a supply chain attack kit in a public repo, a $5,000-a-month RAT that clones browsers, and research showing AI agents can be tricked into leaking real credentials. The bigger problem is how polished this all looks now. Mule networks run like SaaS. Deepfake KYC bypass is sold as a feature. Endpoint tools can be quietly weakened using built-in OS settings, with no exploit needed. Here's the full list of threats, tools, flaws, and updates worth knowing. 3.3B identity records exposedA new analysis from Flashpoint has revealed that "more than 11.1 million devices were infected with infostealers last year, fueling a supply of over 3.3 billion stolen credentials, session cookies, cloud tokens, and other forms of identity data now circulating across illicit markets." There are over 30 unique infostealer strains actively listed for sale across illicit marketplaces, forums, and underground communities, indicating the "scale and accessibility of the modern malware-as-a-service ecosystem." Lumma, Acreed, Rhadamanthys, Vidar, and StealC were the most prolific stealers in 2025. India, Brazil, Indonesia, Vietnam, the Philippines, and the U.S. were the top six countries affected by stealer malware during the same period. MaaS RAT targets credentialsA threat actor named "o1oo1" has advertised an advanced remote access trojan (RAT) named SilabRAT that's sold under a malware-as-a-service (MaaS) model for $5,000 a month on darknet forums since September 2025. "SilabRAT is heavily focused on financial gain through credential theft," Group-IB said. "It offers stability and is capable of bypassing existing security measures." Delivered via ClickFix campaigns using Hijack Loader, the malware uses Hidden Virtual Network Computing (HVNC) to facilitate remote control capabilities, employs techniques like Browser Profile Cloning to replicate a user's browser profile (user agent, extensions, storage, and other fingerprinting attributes) to the attacker's system, and can identify wallet addresses or extract cryptocurrency-related artifacts. The Russian-speaking malware developer and vendor, "o1oo1," has been active since late 2020, previously launching a service called AsmCrypt. 47% of tech intrusionsCrowdStrike has revealed that a North Korean threat actor known as Famous Chollima, which is behind the long-running IT worker and Contagious Interview campaign, accounted for 47% of all state-sponsored hands-on-keyboard operations against the tech sector between April 2025 and March 2026. Hands-on intrusions refer to cyber attacks in which a human operator controls and interacts with a system rather than relying solely on malware. "In their IT worker infiltration campaigns, they sought fraudulent employment at tech companies across North America, Europe, and Asia," the cybersecurity company said. 13 domains seizedThe U.S. Department of Justice has announced the seizure of 13 internet domains masquerading as consulting companies used to target U.S. persons, including current and former security clearance holders with access to classified and sensitive U.S. government information. "These domain seizures offer a glimpse at how foreign actors can use promises of easy money to lure Americans into revealing sensitive or classified information that they are duty-bound to protect," said Assistant Attorney General for National Security John A. Eisenberg. "Anyone approached online with offers of easy income for vague 'consulting' work should treat those overtures with extreme caution and remain vigilant for warning signs of malicious targeting." These sham companies advertised generic consulting or analyst jobs on platforms like Upwork, Expertia AI, Hubstaff Talent, Wellfound, and Post Job Free that sought to recruit current or former U.S. government and U.S. military employees to lend their expertise to unspecified clients. The recruiters then pressured candidates to part with confidential information and reports from "insider" sources in exchange for cryptocurrency payments. The operation is assessed to have commenced in November 2023. The operation is assessed to have commenced in November 2023.. The announcement comes after the Five Eyes intelligence alliance countries warned of China aggressively using job platforms to target people for information. In a statement shared with Reuters, the Chinese Embassy in Washington condemned the allegations and called them fabricated. Supply-chain toolkit exposedThe Miasma credential-stealing attack framework was briefly made available for free on GitHub, after multiple repositories with the name "Miasma-Open-Source-Release" began appearing since June 8, 2026. According to SafeDep, the source code has been published through compromised developer accounts. "The Miasma codebase appears to be larger than a supply chain worm," SafeDep said. "It is a full supply chain attack toolkit that allows the operator to execute various attacks via stolen credentials against arbitrary or targeted packages on public registries (PyPI, npm, RubyGems), JFrog Artifactory, GitHub repositories and GitHub Actions, AI coding tools config poisoning, SSH-based lateral movement, and other attack vectors." As opposed to relying on conventional command-and-control (C2) infrastructure, the malware employs three independent C2 channels using GitHub commit search, each with a different search string and crypto key: "DontRevokeOrItGoesBoom" to discover attacker-controlled personal access tokens (PATs) for data exfiltration, "TheBeautifulSandsOfTime" to deliver JavaScript, and "firedalazer" to deliver Python script URLs that act as a remote code execution backdoor. Miasma is assessed to be a variant of the Shai-Hulud worm. The campaign has since morphed into a Python variant called Hades, which represents the latest evolution of the sustained software supply chain campaign. As of last week, a total of 304 components have been impacted by Miasma. Search uploads retainedGoogle has revealed that it intends to save the images, files, audio, and video users upload to Search under a new "Search Services History" setting. This can include images, files, and audio/video recordings, such as Google Lens images, content you upload, and recordings from Search Live, Translate speaking practice, and voice searches, per Google. The tech giant said the Search Services History setting will be used to "provide, develop, and improve its services," including its AI models, as well as offer personalized suggestions and ads if the new "Personalized Recommendations" option is switched on. These two settings are separate from Google's Web & App Activity. Cross-platform RAT emergesIru has analyzed a new cross-platform RAT called SStar Agent that's designed for both Windows and macOS systems. "The macOS builds are heavily instrumented surveillance tools focused on recon and exfiltration, while the Windows build layers on a keyboard hook, clipboard monitor, and remote mouse/keyboard control," the company said. "Notably, the malware includes a large POST request via endpoint /api/telemetry/report that constantly monitors and exfiltrates the entire directory tree to monitor files of interest. The gap between the Windows and macOS versions indicates this is still a work in progress." The malware is delivered by means of a poisoned npm package named "tw-style-utils." The lure is a bogus Web3 engineering take-home assessment, a GitHub repository ("star45674/smart-contract-engineer-role") that's likely distributed to targets. While the repository itself is clean, the payload resides in the npm dependency. Although it's not clear who is behind the malware, the activity overlaps with previously observed social engineering attacks mounted by North Korean hacking groups. Fake npm popularityTenable has detailed a technique dubbed download pumping, where attackers artificially inflate npm package download counts in order to make malicious packages appear legitimate and trustworthy to developers. This approach has been observed in a package named "ambar-src," which reached more than 50,000 downloads in three days after attackers published hundreds of benign versions of the package before introducing the actual malicious payload. "Every time a new version was published, automated systems like repository mirrors and analysis bots automatically downloaded it," Tenable said. "Because the attackers systematically uploaded hundreds of versions, they artificially generated a massive wave of automated traffic, inflating the package's download count to more than 50,000 downloads in just three days." Exchange spoofing riskA weakness in certain configurations of Microsoft Exchange could be abused by attackers to send emails masquerading as any user to a vulnerable organization. The technique has been codenamed Ghost-Sender. "Using Exchange Online (or on-premises Exchange in hybrid mode) in combination with an external MX record, such as a third-party email server or spam protection solution, can allow the spoofing of emails from any sender to any recipient in the target tenant," InfoGuard Labs said. "This is regardless of the configured SPF, DKIM, and DMARC policies of the spoofed sender's domain, and the emails are delivered without any further warning. It is possible to send emails from anyone, including external and internal email addresses. For internal senders, Outlook even resolves the sender's profile picture." Russia-focused phishing wavesA previously unknown group known as SiribClone has targeted Russian military personnel using bait applications for "safe photo exchange" to distribute malicious files for desktop and mobile devices. In some cases, members of the group have posed as women seeking romantic relationships to infect smartphones, computers, and Telegram accounts. The group has been active since early 2025. Attacks targeting Android devices lead to the deployment of a spyware called SafeLoveStealer that can steal photographs, videos, documents, and location data. Windows systems, on the other hand, are infected by a stealer known as SiribGrabber. The malware is distributed via phishing emails containing ZIP archives disguised as military-themed documents. In addition, the group operates phishing sites mimicking Telegram login pages to trick targets into entering their phone numbers, verification codes, and two-factor authentication passwords, allowing them to seize control of the accounts. Also linked to the threat actor is a tool called Kontur that stores stolen Telegram sessions and allows operators to review captured messages. Russian maritime universities, energy facilities, diplomatic missions, and government agencies have also been targeted through phishing campaigns by an unidentified group since at least July 2024. Recent attack waves have employed a C2 framework called Ravage, although two distinct phishing campaigns observed in 2024 have used Cobalt Strike. The third hacking group to single out Russia (along with Belarus) is Cloud Atlas, which has resorted to sending phishing emails with ZIP archives containing malicious shortcuts that launch PowerShell scripts, paving the way for malware like VBShower and PowerShower, the latter of which is used to drop a credential grabber. Lateral movement via RDP, SSH, and RevSocks is achieved via PAExec or PsExec as part of a framework known as PowerAdmin. Furthermore, the attacks involve two new tools: PowerCloud, which collects user data with administrator privileges and writes it to Google Sheets, and Browser checker, a PowerShell script that checks whether browser processes (Chrome, Edge, Firefox, and others) are running. ClickFix backdoor expandsA ransomware-related threat actor has put to use a new malware family called MLTBackdoor that's delivered via ClickFix. "MTLBackdoor supports a set of commands like downloading and uploading files from the victim's system," Zscaler ThreatLabz said. "However, one of the most powerful features is the ability to load Beacon Object Files (BOFs) to expand its capabilities." The malware was discovered in May 2026. In recent months, ransomware and data extortion attacks involving DragonForce and World Leaks have employed backdoors like VIPERTUNNEL, a Python malware previously linked to RansomHub, and RustyRocket, a custom-built Rust tool to facilitate covert data exfiltration and persistent access. "Once an attacker runs it, RustyRocket can securely connect back to an attacker-controlled server using heavily encrypted and layered traffic that blends in with normal internet activity, making it very hard for defenders to detect," Accenture's T. Ryan Whelan said. "This malware is an integrated communications architecture built for persistence and obfuscation." WooCommerce card theftA new skimmer campaign is targeting WooCommerce sites to steal card details from checkout pages. "The skimmer impersonates the real Stripe payment element, validates cards in real time so the victim never suspects anything," CloudSEK said. "The most 'professional' aspect of this sample is how hard it works to feel legitimate. It re-implements the same client-side checks a real checkout performs." 33,000 users targetedA new Go-based loader named GoFlateLoader is being used to deliver multiple infostealers, including Amatera, Remus, Lumma, Vidar, StealC, and SvitStealer. "GoFlateLoader appears both in x86 (32-bit) and x86-64 (64-bit) variants, matching the bitness of the payload it is supposed to execute," Gen Digital's Avast said. "The loader is designed for in-memory payload execution and is deliberately inflated with a massive PE overlay to hinder detection." The malware is delivered via cracked software and a malicious Traffic Distribution System (TDS) that has been used to deliver Remus Stealer, AnimateClipper, and the SessionGate framework. Since the beginning of April 2026, more than 33,000 unique users have been targeted, with the most affected countries including Brazil, India, Argentina, Mexico, Turkey, and Spain. $862K damage caseMaxwell Schultz, 36, of Columbus, Ohio, has been sentenced to 24 months in federal prison for hacking into his employer's network after his contract was terminated in May 2021. Impersonating another contractor, Schultz obtained login credentials, accessed the former employer's systems, and executed a malicious PowerShell script that reset roughly 2,500 passwords, locking out employees and contractors and causing more than $862,000 in losses. Schultz pleaded guilty to the crime in November 2025. Fake banking updatesA new phishing campaign impersonating Italian and European banking brands is being used to distribute an Android malware called NFCShare. The attacks use phishing sites that aim to trick users into entering their credentials, after which they are prompted to update the banking application by downloading an APK file hosted on GitHub ("antoniocastaldo1998/app-scuola"). The end goal is to guide the user through a fake card verification flow: bring the card near the phone, keep it close while "authenticating," and enter the card PIN. Under the hood, the app reads NFC card data (ISO-DEP) and exfiltrates it to a remote WebSocket endpoint. The activity shares tactical overlaps with other NFC relay malware, such as SuperCardX and RelayNFC. The presence of Chinese text suggests a China-linked operator or tooling lineage. AI agent phishing riskFour phishing simulations on an OpenClaw email agent codenamed Pinchy have revealed it to be susceptible to tactics commonly used to deceive human users. "In some cases, Pinchy not only failed at spotting the phishing attacks, it also performed risky actions that could potentially compromise a real-world organization," Varonis said. "In one notable case, a casual email from 'Dan' asking the agent to share staging credentials was enough to forward AWS IAM keys, database passwords, and SSH access to an external Gmail." This agent phishing is different from indirect prompt injection. While the latter embeds malicious instructions inside data the model consumes to trigger unintended actions or responses, agent phishing operates above the application surface. "A believable request arrives through a normal communication channel, reads like a legitimate business message, and succeeds when the agent acts on it before verifying who asked," Varonis added. AI fixes weak passwordsApple has revealed that its upcoming version of Apple Intelligence, the company's generative artificial intelligence (AI) system, will support capabilities to update its weak and compromised passwords with a single tap via the Passwords app. "Building on its ability to alert users about weak and compromised passwords, Passwords can now automatically fix these for users with just a tap," Apple said. "Using Apple Intelligence and Safari to agentically take action on a user's behalf, Passwords securely navigates through websites to sign in and upgrade their accounts to strong passwords." EDR telemetry throttledA new technique called EDRChoker that interferes with the client-server connection of Endpoint Detection and Response (EDR) software to sidestep defenses. "EDRChoker uses policy-based Quality of Service (QoS) to throttle EDR agents to the lowest bandwidth; when agents attempt to connect, they will consistently time out due to the extremely low bandwidth," a security researcher who goes by the name Zero Salarium said. "It takes a list of common EDR process names and creates QoS policies that limit those processes to 8 bits per second. At that bandwidth, an EDR agent becomes effectively isolated from its server." Earlier this January, the researcher also demonstrated EDRStartupHinder, which prevents an EDR program from starting. "EDRStartupHinder aims to exploit Windows Bindlink to redirect a DLL from System32 to another location, alongside taking advantage of the function that only loads DLLs signed by a program protected with Protected Process Light (PPL) to prevent AV/EDR services from starting," the researcher said. Another technique devised by Binary Defense involves disabling critical security services, such as Windows Defender and Sysmon, without triggering traditional malware alerts. It modifies Windows Access Control Lists (ACLs) to add "Deny" Access Control Entries (ACEs) against core system libraries like "kernel32.dll." Because these services rely on the DLL to function, the dependency chain is broken. Upon a system reboot, the protected services fail to start, leaving the endpoint without any defenses. STX RAT supply chain growsThe supply chain attack targeting CPUID to deliver STX RAT is broader in scope than previously thought, with a new analysis from Cyderes uncovering seven additional trojanized packages tied to the same campaign. "All packages follow the same delivery mechanism," the cybersecurity company said. "The actor, operating under the alias Leda Elacoate (pufferfish11@firemail[.]cc), built and maintained a Bitbucket repository of trojanized installers over approximately one month, targeting a wide range of user demographics." Among the impacted packages is X-VPN, a consumer VPN with over 100 million reported users. Users who installed X-VPN from official channels are not affected. "The actor began with cryptocurrency exchange and trading software as lures, targeting users with likely access to financial accounts, and progressively expanded that lure portfolio across a social engineering decoy and VPN software," Cyderes added. Agent Tesla via ZIP luresPhishing emails masquerading as legitimate payment advice messages are being used to deliver ZIP archives, opening which triggers a multi-stage infection chain that leads to the deployment of Agent Tesla. "In simple terms, the victim opens what looks like a harmless file, but behind the scenes, a heavily obfuscated Batch script silently launches PowerShell, which then pulls and executes additional malicious code directly in memory," Point Wild said. "From there, the attack escalates into a staged execution chain involving shellcode decoding, persistence setup, and process injection into legitimate Windows applications like charmap.exe." Agent, Tesla is designed to steal browser credentials, log keystrokes, capture screenshots, and extract sensitive data from the system. The collected information is then exfiltrated using SMTP-based communication, allowing malicious traffic to blend with normal-looking email activity. AI video lures spread malwareTwo social engineering campaigns are using AI-generated TikTok videos and Instagram Reels to direct users to sketchy sites that deploy Vidar Stealer and other dubious programs, in some cases requiring visitors to complete surveys before they could access the promised downloads. "One methodology involves fake tutorials for software installs, with professional-sounding voice-overs and clean graphics," ReversingLabs said. "The second approach relies on posts demonstrating how to use premium software for free, spanning multiple videos, with a centralized tutorial being introduced after the account gains traction." Routers turned into C2 nodesA suspected China-nexus intrusion set has been identified conducting a large-scale campaign targeting edge network devices across Southeast Asia. "The adversary deploys a custom Linux ELF implant (router.elf) directly onto compromised border routers, establishing persistent command-and-control (C2) via DNS over HTTPS (DoH) while simultaneously weaponizing the router's iptables subsystem to hijack downstream DNS traffic at scale," a security researcher named Y4er said. "Correlated Windows-side tradecraft leverages a cracked Cobalt Strike 4.4 Beacon delivered via DLL sideloading (version.dll), sharing identical C2 infrastructure and malleable C2 profiles with the router implant - confirming unified operational control. RMM abused in BrazilAn active phishing campaign has been observed targeting Brazilian organizations with fake business-document lures, resulting in the download of a NinjaOne Remote Monitoring and Management (RMM) agent. "The campaign begins with phishing emails that redirect victims to Portuguese-language landing pages impersonating familiar Brazilian workflows, including SEFAZ-related fiscal documents, Reclame Aqui-style complaint processes, and secure document-delivery portals," Cato Networks said. "After completing a fake verification process, victims are prompted to download what appears to be a protected business document. Instead, the download delivers a legitimate NinjaOne RMM agent configured to provide remote access to attacker-controlled infrastructure, highlighting a previously undocumented abuse of NinjaOne in the Brazilian threat Landscape." The development once again highlights how threat actors no longer need to rely on bespoke malware to infiltrate organizations. Money laundering goes MaaSCybersecurity company KELA has shed light on money mule networks, which play a crucial role in modern cybercrime and financial fraud ecosystems, enabling threat actors to launder and monetize proceeds through ransomware, scams, and Business Email Compromise (BEC), and other illicit schemes. "In recent years, traditional mule recruitment has increasingly evolved into professionalized Mule-as-a-Service (MaaS) ecosystems that provide scalable laundering infrastructure to cybercriminals," KELA said, adding "mule operations increasingly rely on stolen identities, synthetic identities, compromised accounts, and AI-assisted onboarding techniques rather than solely recruiting human participants." Threat actors have also been found to rely on forged documentation, deepfake-enabled KYC bypass methods, account takeover techniques, and automated account "warming" activity to set up resilient laundering infrastructures across multiple financial platforms. AI chats exposedG DATA said it has witnessed a growing number of Google Chrome extensions that impersonate legitimate productivity tools while stealthily hijacking users' conversations with AI chatbots. Some of these include Urban VPN, Smart Sidebar: ChatGPT, Claude & DeepSeek, and Chat AI, the last of which exhibits traits consistent with a campaign dubbed AiFrame. "User data generated through AI conversations may still be vulnerable to theft by threat actors utilizing plug-ins that pose as legitimate tools," G DATA said. 507 Meta repos exposedA public Meta IP address running an open Grafana instance acted as a pathway for read-write access to 507 private Meta repositories, netting the Sectricity Security Team a bug bounty of $157,000. "The pivot was a wildcard SAN on the TLS certificate: *.llm-playground.aws.metafb.cloud, which exposed a quiet shadow estate behind metafb.cloud," the cybersecurity company said. "By parsing JavaScript bundles across that estate, we uncovered references to a previously unseen domain: api.haloworld.xyz, which became the next pivot point. Slight (AI built wordlist given JS bundles, context, etc) fuzzing against api.haloworld.xyz then exposed /_api/gcp-token, an unauthenticated endpoint that handed out a valid GCP OAuth2 token." The GCP token, in turn, granted read access to the project's Secret Manager that contained a Vercel token. The Vercel token exposed 85 environment variables across Meta's projects, including multiple GitHub personal access tokens (PATs) and other secrets. One of those GitHub tokens had read/write access to 507 private repositories. 7M seniors’ data soldTroy Murray, 57, of Hickory, North Carolina, has been sentenced to more than 10 years in prison for selling the personal information of over 7 million elderly Americans to Jamaican lottery fraud scammers. He has also been ordered to pay a forfeiture in the amount of $5,214,688.48. Murray "devised a scheme where he organized, maintained, and sold lists containing the names, phone numbers, physical addresses, and, in some cases, ages and email addresses, of elderly Americans to individuals in Jamaica involved in lottery fraud schemes," the U.S. Justice Department said. "From 2016 to 2023, Murray sold these lists to Jamaican scammers, who perpetrated lottery fraud on elderly American consumers, earning Murray hundreds of thousands of dollars each year." Each of these lists was sold for $500. One-packet crash bugSecurity researcher Marcus Hutchins has released details and a proof-of-concept (PoC) exploit for ComoDoS, an integer underflow vulnerability residing in Comodo Internet Security's firewall driver, Inspect.sys (CVE-2026-49494, CVSS score: 7.5). "Although the vulnerability can be used to remotely trigger both an out-of-bounds (OOB) read and out-of-bounds write in the Windows kernel, the limitations on both primitives lead me to believe it's unlikely this bug could be weaponized into RCE," Hutchins said. "The bug does, however, enable you to remotely crash the target system with a single TCP/IP packet, even if the firewall is configured to block all ports." The vulnerability remains unpatched as of writing. CI/CD secrets exposedMicrosoft said it discovered an issue in the Claude Code GitHub Action that could be exploited to expose CI/CD workflow secrets when AI agents process untrusted GitHub content, including issue bodies, pull request descriptions, and comments. "While Claude Code Action supported environment scrubbing for subprocess execution paths such as Bash, the Read tool was not subject to the same sandboxing model," the Windows maker said. "It was eventually authorized to access /proc/self/environ, reading the workflow's ANTHROPIC_API_KEY and potentially other credentials available to the runner." Following responsible disclosure on April 29, 2026, the issue was fixed on May 5 with the release of Claude Code version 2.1.128. The patch strengthens the Read tool by unconditionally rejecting a number of files in /proc/ in order to protect those files from exfiltration. Fake $200K job lureThe Iranian hacking group known as Nimbus Manticore approached an employee via LinkedIn by impersonating a headhunter, luring them with a salary offer of $200,000 per year. Per Nextron Systems, the interaction is said to have redirected the victim to a fake hiring portal branded as Ebix Recruitment that prompted them to enter temporary credentials received from the recruiter to log in to the website. "After authentication, the portal prompted the victim to download a two-factor authentication application for 'additional security,'" the company said. "The advertised 2FA application was delivered as a ZIP archive and contained the malware payload." The attack culminates with the deployment of a custom implant with data exfiltration and remote control capabilities. Backdoor with wiper modulesCybersecurity researchers have flagged a new Golang backdoor called BLUERABBIT that routes C2 through RabbitMQ for tasking, Redis for state management, and MinIO for S3-compatible data exfiltration. "It is a full-spectrum intrusion tool: remote access, system profiling, file encryption with a .candy extension, and two distinct disk-wiping modules capable of rendering systems permanently unrecoverable," Binary Defense said. The backdoor is assessed to be the work of an Iran-nexus threat actor. It was first observed in mid-to-late March 2026, and is likely used for targeting entities in Israel. BLUERABBIT is "related to the same likely Iran-nexus activity cluster that previously leveraged BLUEWIPE and SEWERGOO in June 2025," it added. The throughline is simple: attackers do not always need exploits. They need patience, stolen credentials, trusted tools, and one policy setting nobody has checked since the last reorg. The perimeter is not the real problem anymore. The problem is everything inside it that still trusts by default. Same old lesson: audit what your agents can access, treat every identity in the pipeline as a risk, and check what your browser extensions are sending home. See you Thursday.
thehackernews.comJun 11, 2026extracted
Hackers Exploit Langflow Vulnerability for Remote Code Execution
Threat actors have begun exploiting a high-severity vulnerability in the popular low-code AI development platform Langflow, according to VulnCheck. Tracked as CVE-2026-5027 (CVSS score of 8.8), the security defect is described as a path traversal issue that allows attackers to write files to arbitrary locations on the system. “The ‘POST /api/v2/files’ endpoint does not sanitize the ‘filename’ parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences (‘../’),” a NIST advisory reads. Successful exploitation of the bug, VulnCheck VP of security research Caitlin Condon warns, allows unauthenticated attackers to execute arbitrary code on vulnerable instances. “The flaw can enable remote code execution (RCE), and because Langflow enables unauthenticated auto-login by default, attackers can reach the vulnerable endpoint without credentials,” VulnCheck told SecurityWeek. Threat actors can send a single unauthenticated request to obtain a valid session token and then proceed to exploit CVE-2026-5027, it says. According to VulnCheck, the observed in-the-wild exploitation attempts successfully leveraged the path traversal to drop test files on victim systems. The potential attack surface appears broad, with approximately 7,000 Langflow instances accessible from the internet, most of them in North America. “The activity underscores a growing trend of attackers targeting the infrastructure and tooling that organizations use to build and deploy AI applications,” VulnCheck said. CVE-2026-5027 was disclosed publicly on March 27 by Tenable, after a series of failed disclosure attempts. SecurityWeek has emailed Langflow for a statement and will update this article if it responds. Related: ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker Related: Critical Langflow Vulnerability Exploited Hours After Public Disclosure Related: Splunk, Palo Alto Networks Patch Severe Vulnerabilities Related: ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
securityweek.comJun 11, 2026extracted
Path traversal flaw in AI dev platform Langflow exploited in attacks
Attackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in the AI development platform Langflow, to write arbitrary files on exposed servers. Langflow is an open-source visual platform for building AI applications, AI agents, Retrieval-Augmented Generation (RAG) systems, and MCP-based workflows using a drag-and-drop interface instead of traditional coding. AI development teams widely use the project, and it has accumulated more than 149,000 stars and 9,200 forks on GitHub. CVE-2026-5027 is a high-severity path traversal flaw in Langflow's file upload functionality that fails to properly sanitize user-supplied filenames. "The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../')," explains Tenable, which discovered the flaw at the start of the year. Tenable publicly disclosed the issue on March 27, 2026, more than two months after initially reporting it to the Langflow team without receiving a response. Although Tenable did not mention a fix in its advisory, Snyk Security reported on March 30, 2026, that the issue was fixed in the langflow-base package version 0.8.3, while the Langflow application itself received a patch in version 1.9.0. According to VulnCheck security researcher Caitlin Condon, their honeypots have now detected attackers exploiting the vulnerability to drop test files on vulnerable instances. "Because Langflow enables unauthenticated auto-login by default, no credentials are required to reach the vulnerable endpoint, and a single unauthenticated request is sufficient to obtain a valid session token before proceeding with exploitation," reads the researcher's post on LinkedIn. Condon added that Censys scans identified roughly 7,000 publicly exposed Langflow instances. However, Censys data includes historical scan results from the previous 12 months and may not accurately reflect the number of systems currently exposed. Exploitation of CVE-2026-5027 comes shortly after similar activity targeting other Langflow vulnerabilities earlier this year, including CVE-2026-0770, CVE-2026-21445, and CVE-2026-33017. Last year, the U.S. Cybersecurity & Infrastructure Security Agency (CISA) also warned about active exploitation of CVE-2025-3248, for which Condon says VulnCheck continues to observe activity, including activity linked to the Iranian threat group MuddyWater. Langflow users are recommended to upgrade to the latest release, version 1.10.0, published earlier today. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 10, 2026extracted
Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE
A high-severity security flaw in Langflow, an open-source low-code platform to build artificial intelligence (AI) applications, has come under active exploitation in the wild, according to findings from VulnCheck. The vulnerability in question is CVE-2026-5027 (CVSS score: 8.8), a case of path traversal that could allow an attacker to write files to arbitrary locations. "The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path traversal sequences ('../')," Tenable, which discovered the flaw, said in an alert released in late March 2026. The cybersecurity company said it attempted to contact the project maintainers three times in January and February 2026, before disclosing details of the issue on March 27. Caitlin Condon, vice president of security research at VulnCheck, said in a LinkedIn post that the vulnerability enables remote code execution. "Because Langflow enables unauthenticated auto-login by default, no credentials are required to reach the vulnerable endpoint, and a single unauthenticated request is sufficient to obtain a valid session token before proceeding with exploitation," Condon added. Exploitation efforts so far appear to weaponize the bug to write test files on victim systems. Data from Censys shows that there are about 7,000 Langflow instances publicly exposed on the internet, with a majority of them located in North America. The attack effort follows a flurry of exploitation activity targeting other Langflow vulnerabilities this year, including CVE-2026-0770, CVE-2026-33017, CVE-2026-21445, and CVE-2025-34291, the last of which has been weaponized by the Iranian state-sponsored group known as MuddyWater. "The activity underscores a growing trend of attackers targeting the infrastructure and tooling that organizations use to build and deploy AI applications," the company said in a statement shared with The Hacker News. Update When reached for comment regarding the patch status, Tenable told The Hacker News via email that the project maintainer of the langflow-base package confirmed the vulnerability was addressed in Langflow version 1.9.0 released on April 15, 2026. Users are advised to update to the latest version for optimal protection. (The story was updated after publication to include details of the patch availability.)
thehackernews.comJun 10, 2026extracted
Microsoft ships largest Patch Tuesday on record, with one bug under active attack
Microsoft ships largest Patch Tuesday on record, with one bug under active attack Microsoft on Tuesday released fixes for more than 200 security flaws, the largest Patch Tuesday in the program's history in the latest sign of how artificial intelligence is reshaping vulnerability discovery. Microsoft's monthly release for June listed 206 of its own CVEs, though the company does not promote a single headline figure for the monthly total and trackers apply different methods for deciding what to count. Trend Micro's Zero Day Initiative (ZDI) counted 208 CVEs from Microsoft and said it was by far the largest monthly release it had ever seen, eclipsing a previous record of 177 set last year. Tenable counted 198, omitting several CVEs they said were resolved through servicing or disclosed by other vendors, but likewise called it the largest release since the program began. The release day marks the start of a regular cycle for cybersecurity defenders. Once a patch is out, attackers pick it apart in an attempt to reverse-engineer the holes it plugs and then race to break into machines that haven't updated yet. Microsoft’s security leadership acknowledged last month that AI tools are driving a surge in vulnerability discovery across the industry. Tom Gallagher, vice president of engineering at Microsoft’s Security Response Center, said in a blog post that the company expects Patch Tuesday releases to continue trending larger. Alongside its May release, Microsoft disclosed an internal system, codenamed MDASH, that it said had independently found 16 of that month's vulnerabilities before any human researcher flagged them. This month, ZDI said one of the publicly disclosed flaws appeared to have been found the same way. The surge echoes a warning issued in April by Britain's National Cyber Security Centre, which cautioned that organizations should prepare for a wave of urgent updates driven by AI-assisted discovery. ZDI noted that the number of CVEs Microsoft has shipped so far in 2026 already exceeded the total for all of 2018. The one that could spread on its own The flaw many researchers find most alarming is yet to be observed in the wild. Tracked as CVE-2026-45657, and rated 9.8 out of 10 in terms of severity, the bug sits deep in the Windows core and would let a remote attacker take full control of a machine with no action from the user. ZDI described it as “wormable,” meaning an attack could jump from one computer to the next across a network on its own — the same self-spreading quality behind global outbreaks like the 2017 WannaCry attack, which crippled hospitals and businesses worldwide. Microsoft itself rated the flaw “less likely” to be exploited, but ZDI said that offered little reassurance. The bug lies in how the Windows kernel, the most privileged layer of the operating system, processes network traffic, which is what makes it reachable over a network in the first place. Researchers and exploit developers were already pulling the patch apart to reconstruct the underlying flaw, ZDI said, urging organizations to install the fix without delay. One bug under attack One flaw that has been exploited in the wild is tracked as CVE-2026-41091 and rated 7.8 out of 10. The issue affects Microsoft Defender, the antivirus built into Windows. The elevation-of-privilege bug would hand an attacker who already has a foothold on a system the keys to the entire machine. Microsoft said an attacker could trick Defender into writing a malicious file to a protected location, granting them the highest level of control over the system. The U.S. Cybersecurity and Infrastructure Security Agency had added the bug to its catalog of actively exploited flaws on May 20. Three zero-day flaws were also disclosed, including a BitLocker bypass tracked as CVE-2026-50507. The issue means that the feature — intended to encrypt the contents of a Windows laptop so a thief who steals it can't read the drive — can be bypassed. Both of those CVEs are tied to a researcher who goes by the name Nightmare Eclipse and has been locked in a months-long standoff with Microsoft. The pseudonymous researcher began posting working exploit code for unpatched Windows flaws to GitHub in April, citing grievances that Microsoft had deleted their bug-reporting account — a claim which Microsoft denies — withheld bounty payments and stripped their name from at least one advisory. Microsoft initially condemned the releases as “never justifiable” and said its Digital Crimes Unit would keep pursuing those who enable cybercrime, before walking back the apparent threat after a backlash from the security community. Nightmare Eclipse has said more is coming, threatening a fresh release of Windows exploit code on July 14 — the date of the next Patch Tuesday. Alexander Martin is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and a fellow at the European Cyber Conflict Research Initiative, now Virtual Routes. He can be reached securely using Signal on: AlexanderMartin.79
therecord.mediaJun 10, 2026extracted
Record Microsoft Patch Tuesday, fresh zero-day
Record Microsoft Patch Tuesday, fresh zero-day Microsoft marked its largest-ever Patch Tuesday this month, by shipping fixes for nearly 200 vulnerabilities. Within hours, “Nightmare Eclipse”, the researcher behind weeks of escalating Windows exploit releases, dropped a proof-of-concept exploit for a new zero-day: “RoguePlanet”, which abuses a race condition in Windows Defender to spawn a command shell running with SYSTEM-level privileges. Various researchers have confirmed that the PoC exploit works to achieve local privilege escalation. “In initial development, it was confirmed that this vulnerability was a remote code execution,” Nightmare Eclipse noted, but said that a Windows Defender patch Microsoft pushed out in May might have made remote code execution impossible. Priorities in a record-breaking release This month’s Patch Tuesday releases address vulnerabilities in a wide variety of Microsoft’s products, but some require more immediate attention than others, especially in this age of AI-powered security research: CVE-2026-42897, an actively exploited Microsoft Exchange Server vulnerability, now has a fix. “As part of our ongoing efforts to strengthen security and improve defenses across environments, we continue to enhance protections for cross-site scripting attacks. We recommend that customers keep CVE-2026-42897 mitigation in place,” Microsoft’s Exchange Team advised. “The mitigation provides an additional layer of defense and helps ensure continuous protection as further improvements are released. Additional updates will be shared as they become available.” CVE-2026-45586, a privilege escalation vulnerability in Windows Collaborative Translation Framework (CTFMON), may allow authenticated attackers to gain SYSTEM privileges. The vulnerability is publicly disclosed and Microsoft deems it “more likely” to be exploited. (This is believed to be the vulnerability exploited by Nightmare Eclipse’s “GreenPlasma” exploit.) CVE-2026-49160, a remotely exploitable vulnerability that affects HTTP.sys, the Windows kernel-mode driver responsible for intercepting and handling network requests over HTTP and HTTPS, may lead to denial of service condition and is also publicly disclosed. Dustin Childs, head of threat awareness at Trend Micro’s Zero Day Initiative, pointed out that systems using the default MaxRequestBytes registry value used by the Windows HTTP stack are not affected by this flaw. “You can edit your registry settings if you need protection while you test and deploy the patch. The bulletin includes instructions and even a PowerShell script for doing this action. Microsoft lists this as ‘Exploitation more likely’, so I would definitely check your registry settings,” he opined. CVE-2026-50507 is a Windows BitLocker bypass that can only be exploited by attackers who have physical access to target devices. CVE-2026-45585, another Windows BitLocker bypass, has also received a fix. Microsoft acknowledged in the security advisory that this is the fix for the vulnerability exploited by Nightmare Eclipse’s “YellowKey” exploit. (Microsoft shared mitigation advice for it in May 2026.) Childs also singled out as priority patches two unauthenticated code execution flaws that can be exploited remotely without user interaction: CVE-2026-44815, in the DHCP Client Service, which is present and active on every OS. CVE-2026-45657, a wormable Windows Kernel bug that stems from how the kernel handles TCP/IP. “This was listed as ‘Exploitation Less Likely’ by Microsoft, but rest assured that every researcher and bug shop on the planet is reversing this patch right now trying to create an exploit. Test and deploy this patch quickly,” he advised. The AI-driven patch flood isn’t going away “Last month, Microsoft published a blog noting the increase in reporting volume over several years and that both its engineers and the security community are ‘increasingly using AI’ to find bugs,” Satnam Narang, senior staff research engineer at Tenable, told Help Net Security. With this in mind, and as more advanced AI models become available, a large (and increasing) volume of patches may become the norm, and not just for Patch Tuesday. “With nearly 200 CVEs patched this month, I would be remiss not to call out recent reporting by the Anthropic Frontier Red Team, which highlighted the threat posed by N-days – known vulnerabilities that have not been fully remediated across systems,” he added. “As part of its analysis of N-days, Anthropic’s Frontier Red Team analyzed 21 Windows kernel elevation of privilege vulnerabilities included in the January and February 2026 Patch Tuesday releases. Models including Sonnet, Opus and Mythos Preview were able to produce proof-of-concept (PoC) exploits by performing patch diffs to identify what changed between the previous and the latest release. Mythos Preview even produced PoCs for 13 of the 14 vulnerabilities that were labeled as ‘Exploitation Less Likely’ or ‘Exploitation Unlikely’ according to Microsoft’s Exploitability Index, an assessment system designed for humans, not advanced AI models. As Anthropic prepares to release Mythos, and other AI companies release models on par with Mythos, rapidly closing the patch gap is critical for organizations.” Tyler Reguly, Associate Director, Security R&D at Fortra, also noted that widespread AI use is making CVSS scores a poor indication of real risk. “How many of [vulnerabilities with high CVSS scores] are turned into exploits and how many of those exploits are the thing we really need to pay attention to. For the next few weeks, while teams are testing the patches and preparing for deployments across their organizations, I’ll be watching CISA KEV to see if any of these get added,” he commented. “Right now, I’m guessing that all three publicly disclosed vulnerabilities will end up on the list – CVE-2026-45586 (CFTMON), CVE-2026-50507 (Bitlocker), and CVE-2026-49160 (HTTP.sys).” Trend Micro’s Childs pointed out that this “inflation” of patches raises concerns: “How many patches were generated using AI to assist in coding or testing? What quality issues may exist in these patches?” Also: “Should sysadmins adjust their processes for prioritization and patch deployment based on this new volume of updates? Unfortunately, Microsoft is not providing those answers right now. Hopefully that changes in the future.” UPDATE (June 11, 2026, 05:10 a.m. ET): A comment from the Microsoft Exchange Team was added. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comJun 10, 2026extracted
Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs
Microsoft on Tuesday released fixes for a record 206 security vulnerabilities impacting its software portfolio, including three flaws that have been publicly disclosed at the time of release. Of the 206 flaws, 39 are rated Critical, and 167 are rated Important in severity. This includes 63 privilege escalation, 56 remote code execution, 30 information disclosure, 27 spoofing, 20 security feature bypass, seven denial-of-service, and three tampering vulnerabilities. The patches also include two non-Microsoft CVEs, a privilege escalation vulnerability impacting Windows Kernel (CVE-2025-10263) and a UEFI Secure Boot security feature bypass (CVE-2026-8863). They are in addition to more than 350 security flaws that Google has addressed in Chromium, which is used in Microsoft's Edge browser. Topping the list of fixes is CVE-2026-45657 (CVSS score: 9.8), a use-after-free flaw affecting Windows Kernel that could result in remote code execution. "An attacker could exploit this vulnerability by sending specially crafted network traffic to a vulnerable Windows system," Microsoft said. "If successful, the malicious network packets could trigger a flaw in how the Windows kernel processes certain TCP/IP data, potentially allowing the attacker to run code with system-level privileges without needing to sign in or interact with a user." Other important vulnerabilities of note are listed below - CVE-2026-47291 (CVSS score: 9.8) - An integer overflow or wraparound flaw in Windows HTTP.sys that allows an unauthorized attacker to execute code over a network. CVE-2026-44815 (CVSS score: 9.8) - A stack-based buffer overflow vulnerability in Windows DHCP Client that allows an unauthorized attacker to execute code over a network. "This flaw needs no credentials or user action and can turn network traffic into a full system compromise," Alex Vovk, CEO and co-founder of Action1, said about CVE-2026-44815. "An attacker could send specially crafted network traffic to a system configured for DHCP services." "Successful exploitation could allow unauthorized code execution over the network with high impact to confidentiality, integrity, and availability. This vulnerability creates serious risk because DHCP is a core network function. Successful exploitation could lead to server compromise, malware deployment, data theft, service disruption, and movement deeper into the network. Systems handling DHCP traffic should be treated as high-priority patch targets." Microsoft has also released patches to address CVE-2026-45585 (CVSS score: 6.8), a Windows BitLocker security feature bypass vulnerability for which a proof-of-concept (PoC) exploit called YellowKey was released by security researcher Chaotic Eclipse (aka Nightmare-Eclipse) last month. CVE-2026-45585 is one of several security feature bypasses that the Windows makers has addressed this month - CVE-2026-45655 (CVSS score: 5.3) CVE-2026-45658 (CVSS score: 7.8) CVE-2026-50507 (CVSS score: 6.8) "A successful attacker could bypass the BitLocker Device Encryption feature on the system storage device," Microsoft said in its advisories for the three issues. "An attacker with physical access to the target could exploit this vulnerability to gain access to encrypted data." According to security researcher Will Dormann, CVE-2026-50507 is assessed to be a fix for a BitLocker bypass dubbed bitskrieg that grants full access to encrypted data. It's worth noting that CVE-2026-50507, along with CVE-2026-49160 and CVE-2026-45586, are listed as publicly disclosed zero-days. CVE-2026-45586 (CVSS score: 7.8) - Windows Collaborative Translation Framework (CTFMON) privilege escalation vulnerability CVE-2026-49160 (CVSS score: 7.5) - HTTP.sys denial-of-service vulnerability CVE-2026-49160 is related to HTTP2/Bomb, an attack technique that can be used to knock web servers offline in seconds. In tests conducted by Calif, an IIS server was found to exhaust 64 GB RAM in about 45 seconds. To mitigate the attack, Microsoft has introduced a new "MaxHeadersCount" registry setting to limit the number of headers in HTTP/2 and HTTP/3 requests. "Limiting HTTP headers can help protect systems and servers from excessive memory use, high CPU consumption, and denial-of-service attacks," Microsoft said. "Because HTTP/2 (HPACK) or HTTP/3 (QPACK) header compression is used and more complex protocol processing, enforcing a header limit such as MaxHeadersCount can help maintain performance and reliability." On the other hand, CVE-2026-45586 is suspected to be a fix for a zero-day privilege escalation exploit that Chaotic Eclipse released under the name GreenPlasma. Lastly, the June 2026 update also plugs MiniPlasma, a separate vulnerability disclosed by Chaotic Eclipse as an incomplete fix for CVE-2020-17103, which was originally addressed by Microsoft in December 2020. "To comprehensively address the vulnerability identified by CVE-2020-17103 and recently publicly referred to as 'MiniPlasma,' Microsoft recommends installing the June 2026 updates for your Windows operating systems," the tech giant said in an update to its advisory. The increasing number of patches has been attributed to the use of artificial intelligence (AI)-assisted vulnerability discovery approaches, a trend that Microsoft said will continue in the foreseeable future. "Pandora's proverbial box has been opened, and as more advanced AI models become available, we expect the norm to continue upward across the board, not just for Patch Tuesday," Satnam Narang, senior staff research engineer at Tenable, said in a statement. Dustin Childs, head of threat awareness at TrendAI's Zero Day Initiative (ZDI), described the massive set of Microsoft vulnerabilities as a testament to how AI is supercharging flaw discovery at an uncontrollable scale. "The current number of CVEs shipped by Microsoft this year exceeds the total number of CVEs shipped in all of 2018," Childs said. "It is extraordinary that Microsoft can produce so many patches in a single month, and I expect many testers are wondering what quality issues may exist." The patches come as Chaotic Eclipse released a PoC exploit for yet another Microsoft Defender zero-day named RoguePlanet, characterizing it as a race condition that could be used to spawn a Windows command prompt with SYSTEM privileges.
thehackernews.comJun 10, 2026extracted
A Record-Breaking Patch Tuesday for June 2026
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company’s monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft’s most dire “critical” rating, and exploit code for at least three of the weaknesses is now publicly available. The software giant said in a blog post last month that both its engineers and the security community are increasing using artificial intelligence tools to find bugs, meaning this month’s heavy Patch Tuesday may start to become the norm, said Satnam Narang, senior staff research engineer at Tenable. “Some surveys put AI usage among security professionals generally at 90%, so it’s unsurprising that this volume of patches may be the norm,” Narang said. “Pandora’s proverbial box has been opened, and as more advanced AI models become available, we expect the norm to continue upward across the board, not just for Patch Tuesday.” June’s zero-day bugs include CVE-2026-49160, a denial of service vulnerability affecting a range of web servers, including Microsoft Internet Information Services (IIS). Microsoft says the flaw was reported by OpenAI’s Codex. Two of the zero-days addressed this month appear to stem from recent vulnerability disclosures by Nightmare Eclipse, the nickname chosen by a security researcher who has been dropping exploits for various Windows flaws. One of those, dubbed “GreenPlasma,” leverages an elevation of privilege weakness in the Windows Collaborative Translation Framework, the same framework patched today in CVE-2026-45586. Nightmare Eclipse also last month released “YellowKey,” an exploit for a Windows BitLocker vulnerability that allows an attacker with physical access to view encrypted data, and CVE-2026-50507 is a patch for an elevation of privilege bug in BitLocker. Microsoft received heavy blowback on social media last month after it said in a blog post that it was considering taking legal action against the security researcher. The company later clarified on Twitter/X that while it has no intention of pursuing legal actions against researchers, it would report them to authorities if they break the law. The advisories for CVE-2026-49160 and CVE-2026-50507 do not credit any researchers in the acknowledgement section, saying only that “Microsoft recognizes the efforts of those in the security community who help us protect customers through coordinated vulnerability disclosure.” Nightmare Eclipse claims to be a former employee of Microsoft, although Microsoft has not responded to questions about this claim. Rapid7 notes that a recent blog post by Nightmare Eclipse included an image of Albert Wesker, a character from the Resident Evil video game series who formerly worked as a researcher for a technology company before going rogue. Nightmare Eclipse has pledged to release even more zero-day exploits for Windows in what they called a “bone shattering” drop planned for July 14 (the same day as next month’s Patch Tuesday). Immediately following the release of Microsoft patches today, the researcher published an exploit for what they claimed was a zero-day bug in Windows Defender. While 200 vulnerabilities may be a record for Patch Tuesday, the actual number of security flaws Microsoft addressed this month is far higher, said Rapid7’s Adam Barnett. “So far this month, Microsoft has provided patches to address 360 browser vulnerabilities, which is an order of magnitude more than has been typical in any given month over the past few years,” Barnett wrote. “As usual, browser [flaws] are not included in the Patch Tuesday count above. Indeed, the vast, and presumably sustained, uptick in the number of browser vulnerabilities has led to Microsoft no longer enumerating Chromium CVEs in the Security Update Guide.” Microsoft also patched a zero-day vulnerability in Visual Studio Code that allows attackers to steal GitHub tokens with a single click. The company was forced to push a stopgap fix for the flaw on June 3, after a researcher published instructions showing how to exploit it. The researcher said they opted not to work with Microsoft because of a recent experience wherein Redmond silently patched a flaw they reported without offering credit or recognition. Microsoft battled its own internal zero-day emergencies last week, after at least 72 of the company’s public code repositories were infected with a variant of the Shai-Hulud worm. Researchers found that all of the affected packages were connected to Microsoft official Azure Durable Task SDK, which got hit by the same Shai-Hulud worm in May. Other major software makers are also shipping outsized update bundles this month. Adobe has released updates to fix a massive number of critical vulnerabilities across a range of products, including Adobe Experience Manager, Acrobat Reader and Cold Fusion. On June 3, Google resolved a whopping 429 vulnerabilities in its latest Chrome browser update (Chrome automatically downloads updates but installing them usually requires a complete restart of the browser). As ever, please consider backing up your data before applying operating system updates, and drop a note in the comments if you run into any problems with this month’s patches. Further reading:
krebsonsecurity.comJun 9, 2026extracted
Anthropic Launches Claude Fable 5: Mythos-Class AI With Cybersecurity Guardrails
Anthropic on Tuesday announced the general availability of Claude Fable 5, a powerful Mythos-class AI model engineered with new safeguards that specifically restrict its use in high-risk domains, including cybersecurity. The AI giant says this marks the first time a model of this capability class has been deemed safe enough for widespread public and developer access. While Fable 5 demonstrates good performance — surpassing prior models in software engineering, knowledge work, vision, and long-running tasks — the company prioritized safety by implementing targeted blocks. In sensitive areas such as cybersecurity and biology, the model automatically falls back to the less capable Claude Opus 4.8 to prevent potential misuse. Early usage data indicates that at least 95% of sessions run entirely on Fable 5’s capabilities without triggering any fallback. “The uplift from Mythos-level capabilities is valuable to many adversaries — for instance, those who could financially gain from cyberattacks — and we therefore expect them to be motivated to try to circumvent our safety measures,” Anthropic noted. The company emphasized the rigor of its safety measures. It conducted extensive internal red-teaming of its classifiers, followed by an external bug bounty program spanning over 1,000 hours that yielded no universal jailbreaks. Independent external red-teaming also failed to uncover critical bypasses, underscoring the robustness of the safeguards against adversarial attempts to achieve restricted outputs. Project Glasswing partners gain upgraded Mythos 5 Anthropic also announced on Tuesday that trusted users, including its cybersecurity partners in Project Glasswing, are being upgraded from Claude Mythos Preview to Claude Mythos 5. The company plans to gradually expand this high-privilege access through a structured trusted-access program. Anthropic announced recently that it’s expanding Project Glasswing to add roughly 150 new organizations. The AI giant has not listed the new additions, but several cybersecurity and tech companies have since announced their participation in the project, including Dragos, Tenable, TrendAI (Trend Micro), Netskope, BeyondTrust, Rubrik, BT, Intercontinental Exchange, and Hitachi. Both Fable 5 and Mythos 5 are priced at $10 per million input tokens and $50 per million output tokens, with the former available immediately via the Claude API for developers. Related: Claude Mythos Turns N-Days Into N-Hours With Rapid Exploit Creation Related: New Platform Uses Cryptographic Invisibility to Protect AI-Built Applications
securityweek.comJun 9, 2026extracted
Loading 40 more…