1553 resultaten gevonden

  • medium · bleepingcomputer.com

    AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

    A new phishing-as-a-service platform called AnonyMousKIT has been uncovered that leverages voice AI agents to automate the theft of iPhone passcodes. The platform targets stolen Apple devices, specifically attempting to retrieve unlock codes and disable Apple's Activation Lock feature. By using AI-driven voice agents, the service automates the social engineering process traditionally performed by human attackers. This represents an evolution in PhaaS offerings, combining voice phishing (vishing) with artificial intelligence to scale attacks. The platform lowers the barrier for criminals to exploit stolen iPhones, potentially enabling large-scale operations against Apple device owners. The Activation Lock bypass capability makes this especially concerning as it allows stolen devices to be fully unlocked and resold or reused.

    Bekijk origineel advisory →
  • medium · thehackernews.com

    U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

    The U.S. Department of the Treasury announced new sanctions against Iranian cyber actors targeting critical infrastructure. This action is described as part of an unprecedented whole-of-government economic campaign against Iran and its enablers. The objective is to sever Iran's global financial connections and cut economic lifelines sustaining the regime. The sanctions target hackers linked to breaches of critical infrastructure systems. This move reflects escalating U.S. pressure on Iranian state-sponsored cyber operations.

    Bekijk origineel advisory →
  • medium · bleepingcomputer.com

    Massive DDoS attack disrupts Norway's government digital services

    A large-scale distributed denial-of-service (DDoS) attack has been targeting Norway's shared government digital infrastructure starting Monday. The attack has disrupted services used by the public sector, affecting the availability of government digital services for citizens and public agencies. The attack targeted centralized infrastructure, meaning multiple government services were simultaneously impacted. Norwegian authorities are aware of the incident and are working to mitigate the disruption. The event highlights the vulnerability of centralized government digital infrastructure to volumetric network attacks. No specific threat actor has been attributed in the article excerpt, though DDoS attacks on government infrastructure are often politically motivated.

    Bekijk origineel advisory →
  • medium · thehackernews.com

    A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

    Oasis Security has disclosed a vulnerability in NVIDIA NemoClaw that allows an attacker-controlled webpage to take unauthenticated control of a local Ollama instance serving an AI agent. The attack vector involves a malicious webpage that can plant hidden instructions inside the AI model itself, effectively poisoning it. The vulnerability requires no authentication to exploit, making it particularly dangerous for users running local AI models via Ollama. Oasis Security responsibly disclosed the findings to NVIDIA's Product Security Incident Response Team prior to publication. The issue highlights emerging security risks associated with locally hosted AI inference systems and agent frameworks. The attack could enable persistent manipulation of AI model behavior through hidden prompt injection or instruction poisoning techniques.

    Bekijk origineel advisory →
  • medium · thehackernews.com

    Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

    A high-severity security vulnerability has been discovered and patched in Marimo notebook software. The flaw allowed an attacker to execute attacker-supplied Model Context Protocol (MCP) commands via a specially crafted notebook file. The malicious command could run as a local subprocess when the notebook is opened in edit mode, potentially before any cells execute. The vulnerability was documented by VulnCheck's CVE Numbering Authority (CNA). Marimo has addressed the issue with a fix. The flaw poses significant risk as it could enable arbitrary command execution on a victim's local system simply by opening a crafted notebook.

    Bekijk origineel advisory →
  • medium · bleepingcomputer.com

    Hackers breached over 270 Zimbra servers in ongoing attacks

    Threat actors have actively compromised over 270 Zimbra Collaboration Suite (ZCS) servers by exploiting a high-severity remote code execution vulnerability. The attacks are ongoing, suggesting a widespread and coordinated campaign targeting ZCS instances. The vulnerability allows attackers to execute arbitrary code remotely on affected servers. The scale of compromise indicates that many organizations have not yet patched their Zimbra installations. Zimbra is widely used in enterprise and government environments, making this a significant security incident. Organizations running ZCS are urged to apply patches immediately to prevent further breaches.

    Bekijk origineel advisory →
  • medium · cisa.gov

    Zoneminder

    CISA issued an ICS advisory for ZoneMinder versions 1.37.48 and 1.38.3 regarding an authenticated OS Command Injection vulnerability (CVE-2026-76060). The flaw exists in ZoneMinder's event export functionality, where the exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(). Any authenticated user with View Events permission can exploit this to execute arbitrary OS commands on the server, resulting in full Remote Code Execution (RCE) as the web server user. The vulnerability carries a CVSS v3.1 score of 8.8 (HIGH) and CVSS v4.0 score of 8.7 (HIGH). CISA discovered a public Proof of Concept (PoC) authored by 'Scriptkittens' and reported it to ZoneMinder. The vendor recommends upgrading to version 1.38.3 or later. Mitigations include minimizing network exposure, using firewalls, and employing VPNs for remote access.

    Bekijk origineel advisory →
  • medium · cisa.gov

    PayRange API

    CISA has published an ICS advisory regarding a critical Missing Authorization vulnerability (CVE-2026-18965) affecting all versions of the PayRange API. The flaw allows remote attackers, authenticated or unauthenticated, to disclose sensitive device information, cause denial of service, or alter displayed images on devices. The vulnerability carries a CVSS v3.1 score of 8.8 (HIGH) and a CVSS v4.0 score of 8.7 (HIGH). All versions of PayRange API are affected, with deployment in the United States and Canada, primarily in the Commercial Facilities critical infrastructure sector. PayRange has not responded to CISA's requests to work on mitigation. Users are advised to contact PayRange support and follow CISA's recommended defensive practices, including minimizing network exposure and using VPNs for remote access. No known public exploitation has been reported at this time. The vulnerability was reported by Tahi Wilton Geary.

    Bekijk origineel advisory →
  • medium · cisa.gov

    Rently Smart Home

    CISA published advisory ICSA-26-237-01 regarding a high-severity vulnerability in Rently Smart Home versions 20.1.0 and prior. The flaw, tracked as CVE-2026-75960, involves insufficiently protected credentials (CWE-522), allowing an attacker to retrieve pins including the Master Pin and override standard user permissions. The vulnerability carries a CVSS v3.1 score of 8.1 (HIGH) and a CVSS v4.0 score of 8.7 (HIGH). Affected critical infrastructure sectors include Commercial Facilities, Communications, and Information Technology, with deployment in the United States and India. Rently has patched the vulnerability as of late June 2026 with no user action required. The vulnerability was reported to CISA by Berk Dusunur. No known public exploitation has been reported at this time. Users are advised to minimize network exposure and use VPNs for remote access as additional precautions.

    Bekijk origineel advisory →
  • medium · cisa.gov

    FURUNO FA-50 Class B AIS Transponder

    CISA issued an advisory for FURUNO FA-50 Class B AIS Transponder affecting all versions, with two critical/high vulnerabilities. CVE-2026-59769 involves Use of Hard-coded Credentials (CVSS 9.1), allowing attackers with credential knowledge and in-vessel network access to alter device settings. CVE-2026-67578 involves Missing Authentication for Critical Function (CVSS 7.5), enabling configuration changes without authentication. Production of the FA-50 ended in October 2020 and no software patches will be provided. Mitigations include isolating devices from the internet, physically securing vessels, and using VPNs for remote access. The vulnerabilities affect the Transportation Systems critical infrastructure sector and are deployed worldwide. Souvik Kandar reported the vulnerabilities, coordinated through JPCERT/CC and CISA. No known public exploitation has been reported at this time.

    Bekijk origineel advisory →
  • medium · cisa.gov

    Ebyte NE2-D11

    CISA published an ICS advisory for the Ebyte NE2-D11 gateway device running firmware FW-9167-0-11, disclosing 11 vulnerabilities with a maximum CVSS v3 score of 9.8 (Critical). The vulnerabilities span missing authentication, cleartext transmission, insufficiently protected credentials, client-side authentication bypass, session hijacking via GET parameters, CSRF, brute-force susceptibility, clickjacking, missing authorization, and cleartext MQTT traffic. Successful exploitation could allow unauthenticated remote attackers to gain administrative access, disclose sensitive information, modify device configuration, hijack authenticated sessions, and disrupt device operation. The affected product is deployed worldwide in Critical Manufacturing and Energy sectors. Ebyte acknowledged the vulnerabilities and indicated a patch was under development but has not responded to subsequent coordination requests, leaving no vendor patch available. CISA recommends network isolation, firewall segmentation, and VPN usage as mitigations. The vulnerabilities were reported by researcher Jithin Nambiar.

    Bekijk origineel advisory →
  • medium · cisa.gov

    Siemens SIMATIC IoT2050 Advanced

    Siemens SIMATIC IoT2050 Advanced devices running Industrial OS with Node-RED installed contain a critical missing authentication vulnerability (CVE-2026-58115) in the Node-RED HTTP interface. An unauthenticated remote attacker can exploit this flaw to create malicious flows and execute arbitrary code on the underlying server with maximum privileges. The vulnerability received a CVSS v3.1 base score of 10.0 (CRITICAL) with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Affected versions are SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) running versions prior to V4.3.4.1. The vulnerability affects critical infrastructure sectors including Chemical, Critical Manufacturing, Energy, and Transportation Systems worldwide. Siemens has released version V4.3.4.1 as a fix, and interim mitigations include hardening the Node-RED installation or uninstalling Node-RED entirely. The vulnerability was reported by Siemens ProductCERT to CISA.

    Bekijk origineel advisory →
  • medium · thehackernews.com

    Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

    The Mirage2FA campaign has been active from 2024 to 2026, targeting Microsoft 365 accounts across thousands of companies in the US and EU. The campaign leverages a commercial phishing-as-a-service (PhaaS) toolkit that abuses legitimate Microsoft 365 login flows to bypass two-factor authentication. According to ANY.RUN research, approximately 4,500 companies have been affected, with 48% of targeted email addresses potentially compromised. The majority of affected organizations are US-based. Mirage2FA represents a significant threat due to its ability to circumvent MFA protections, a security control widely relied upon by enterprises. The commercial nature of the toolkit suggests it is being offered to multiple threat actors, amplifying its reach and impact.

    Bekijk origineel advisory →
  • medium · unit42.paloaltonetworks.com

    The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

    Unit 42 from Palo Alto Networks published a comprehensive state-of-the-art report on AI-enabled malware as of August 2026. The report covers the evolution of AI-authored malicious code, ranging from brand abuse tactics to agentic execution frameworks. It examines how threat actors are leveraging AI tools to generate, obfuscate, and deploy malware at scale. The research highlights how existing behavioral detection systems and endpoint analytics can identify and stop AI-generated code before it executes. The article represents a significant industry analysis of the intersection between generative AI capabilities and malware development, signaling a notable shift in the threat landscape.

    Bekijk origineel advisory →
  • medium · thehackernews.com

    Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

    Attackers are actively exploiting critical vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin. The flaws allow unauthenticated attackers to bypass authentication and sign in as any WordPress user, including administrators. CVE-2026-61979 carries a CVSS score of 8.1 and is classified as an unauthenticated privilege escalation vulnerability. The vulnerabilities were disclosed by Patchstack. Active exploitation attempts have been observed in the wild, making this a high-priority patching concern for WordPress site administrators using this plugin. The flaws are particularly dangerous as they require no prior authentication to exploit, lowering the barrier for attackers significantly.

    Bekijk origineel advisory →
  • medium · thehackernews.com

    Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

    CISA has added CVE-2026-21962, a maximum-severity vulnerability (CVSS 10.0) affecting Oracle HTTP Server and Oracle WebLogic Server, to its Known Exploited Vulnerabilities catalog. The flaw allows unauthenticated attackers with network access via HTTP to access critical data. Active exploitation has been confirmed in the wild. The vulnerability requires no authentication, making it especially dangerous for internet-facing deployments. Organizations using Oracle WebLogic or Oracle HTTP Server are urged to apply patches immediately per CISA's guidance.

    Bekijk origineel advisory →
  • medium · cisa.gov

    Gitea Code Injection Vulnerability

    CVE-2026-60004 is a code injection vulnerability in Gitea, a self-hosted Git service. An attacker with repository write access can exploit the diffpatch API endpoint by sending a malicious patch that plants an executable Git hook. This allows the attacker to execute arbitrary shell commands as the Gitea service account, potentially leading to full server compromise. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog under BOD 26-04, which mandates prioritizing security updates based on risk. Federal agencies are required to remediate this vulnerability per BOD 26-04 directives. Forensics triage requirements are also outlined in CISA's implementation guidance. The issue is tracked at NVD and has a dedicated GitHub security advisory.

    Bekijk origineel advisory →
  • high · nvd.nist.gov

    GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook execution.

    GitPython versions before 3.1.59 contain a vulnerability where the --separate-git-dir option is omitted from the unsafe_git_clone_options list. This oversight allows attackers to pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() methods, redirecting repository metadata to an attacker-controlled filesystem path. The flaw enables arbitrary directory creation outside the intended clone destination, and could potentially lead to hook execution if the attacker can place malicious git hooks in the redirected directory. The vulnerability is a path traversal-class issue affecting Python projects that use GitPython for git operations. A fix was introduced in GitPython version 3.1.59, and users are advised to upgrade immediately. The issue has been documented in the official GitHub security advisory and tracked by VulnCheck.

    Bekijk origineel advisory →
  • high · nvd.nist.gov

    Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly improbable. CWE: CWE-415: Double Free Description: In order to validate initial packet, OpenSSL QUIC stack default packet handler (port_default_packet_handler()) creates a so-called QRX object. If the initial packet validates successfully with QRX object, the default packet handler proceeds to channel (connection object) creation. The QRX object used for packet validation is passed to port_bind_channel(), so it becomes part of the newly created connection. If port_bind_channel() fails, then it also frees the QRX object. Once port_bind_channel() returns, the port_default_packet_handler() detects the failure and proceeds to the error branch, where the same QRX object is freed for the second time. The failure in port_bind_channel() function can be induced with a relatively low effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the packet carries DCID (destination connection ID) which is shorter than 8 bytes, then port_bind_channel() jumps to the error path after ossl_quic_lcidm_enrol_odcid() detects that the DCID has invalid length. FIPS impact: no The FIPS module is not affected, as the QUIC implementation is outside of the OpenSSL FIPS module boundary.

    CVE-2026-18798 is a double free vulnerability (CWE-415) in the OpenSSL QUIC stack affecting QUIC server implementations. The flaw occurs in port_default_packet_handler() where a QRX (QUIC record layer RX) object is freed twice when port_bind_channel() fails during initial packet processing. This leads to heap corruption and typically results in termination of the QUIC server process, causing Denial of Service. The vulnerability can be triggered with relatively low effort by sending a malformed INITIAL packet with a DCID (destination connection ID) shorter than 8 bytes. While heap corruption is confirmed, remote code execution is considered highly improbable based on current analysis. The FIPS module is not affected as the QUIC implementation resides outside the OpenSSL FIPS module boundary. Patches have been issued via multiple commits to the OpenSSL repository.

    Bekijk origineel advisory →
  • high · nvd.nist.gov

    GitPython before 3.1.59 fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives. Attackers can craft a malicious .gitmodules file with include directives pointing to sensitive files; when repo.submodules is accessed, GitConfigParser raises MissingSectionHeaderError embedding the target file's first line verbatim in the exception message.

    GitPython versions before 3.1.59 contain a vulnerability where the library fails to disable merge_includes when parsing .gitmodules files. This allows attackers to craft malicious .gitmodules files containing [include] directives that point to arbitrary local files. When repo.submodules is accessed, GitConfigParser raises a MissingSectionHeaderError that embeds the first line of the targeted file verbatim in the exception message, causing unintended local file content disclosure. The vulnerability can be exploited to expose sensitive files on the host system. A fix is available by upgrading to GitPython 3.1.59 or later. The issue has been documented in both the GitHub Security Advisory and VulnCheck advisories. It is classified as a high-severity information disclosure vulnerability affecting applications that use GitPython to process potentially untrusted repositories.

    Bekijk origineel advisory →