News Archive
1923 stories · page 24 of 81Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

How MSPs can catch phishing attacks email filters miss
AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attacks that make it past the inbox. [...]

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
A critical vulnerability has been discovered in the isolated-vm Node.js library, allowing sandboxed JavaScript code to escape and potentially execute arbitrary code on the host system. The flaw, found in the ExternalCopy component, enables memory corruption and control-flow hijacking. While the isolation primitive itself remains sound, the C++ binding layer that facilitates data transfer across boundaries was found to be vulnerable. Patches are available in versions 6.2.0 and 7.0.1.

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers
Citrix has released critical security updates for NetScaler ADC and NetScaler Gateway to address two vulnerabilities. The most severe, CVE-2026-19490 (CVSS 9.3), allows for authentication bypass on specific configurations, including those acting as Gateways or AAA servers with SAML actions. A second flaw, CVE-2026-19489 (CVSS 8.8), is a memory overflow leading to potential denial-of-service when the SIP ALG is enabled.

The push to designate AI as the next critical infrastructure sector
The designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security. The post The push to designate AI as the next critical infrastructure sector appeared first on CyberScoop.

'Grandoreiro' Malware Resurfaces With Mexico Campaign
The banking Trojan, post-law enforcement takedown, is sprucing itself up with features that make detection and analysis harder.

Twitch wants your content for Amazon AI training. Here’s how to opt out
Twitch added an option to opt out of training Amazon AI with your content—two years after it confirmed that training had begun.

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution
Attackers are actively exploiting a critical vulnerability in Zimbra Collaboration (ZCS) that allows for unauthenticated remote code execution. The flaw, identified as CVE-2026-73570 with a CVSS score of 8.9, stems from improper input sanitization in the SNMP notification processing. Exploitation can lead to the execution of arbitrary operating system commands as the Zimbra user. Zimbra has released version 10.1.20 to patch this vulnerability, and CERT Polska is urging users to check their logs for signs of compromise.

Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia
Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks. The post Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia appeared first on SecurityWeek.

Using Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th)
Building on the last diary on Using MS Graph and Powershell, let&#;x26;#;39;s look at "Risky" logins.

BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 – without exploits, vulnerabilities, or memory corruption? In this publication, we present the first full […] The post

Grok chat duped into swallowing injected instructions
A spoonful of encryption helps the malware go down

Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)
Microsoft Graph is a newer API that is meant to replace several others.&#;x26;#;xc2;&#;x26;#;xa0; OK, it&#;x26;#;39;s at version 2.3.9, so it&#;x26;#;39;s not all that new, but it&#;x26;#;39;s new enough that lots of folks (and commercial tools) aren&#;x26;#;39;t using it yet.&#;x26;#;xc2;&#;x26;#;xa0; &#;x26;#;xc2;&#;x26;#;xa0;It allows you to Get and Set info from/to M365, Entra Users and Entra

NCSC Urges Stronger Controls for Agentic AI Systems
NCSC urged sandboxing, oversight and tight access controls for autonomous AI agents

Your Mac already has a built-in firewall. Here’s how to get more from it
Malwarebytes Firewall gives you a clearer, more intuitive way to manage your Mac's inbuilt firewall.

US Defense Contractors Admit Their Rising CMMC Scores May Not Be Accurate
Defense contractors in the US are doubting their own self-assessment scores under CMMC Phase I, even as those scores hit an all-time high

French tax authority says break-in exposed data of 600K, including some private messages
Stolen details range from contact information to household finances and withholding rates

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities
The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. The post Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities appeared first on SecurityWeek.

Citrix urges admins to patch new NetScaler flaws as soon as possible
Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. [...]

MLflow Vulnerability Exploited for Cloud Credential Theft
The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information. The post MLflow Vulnerability Exploited for Cloud Credential Theft appeared first on SecurityWeek.

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
Researchers have developed a 'Zombie Card' attack that can enable the use of expired Visa contactless cards for in-store payments. The attack involves a man-in-the-middle relay that rewrites the expiration date read by the point-of-sale terminal, while leaving the card's cryptography intact. This method was successful against some major US banks, though not universally, and highlights potential vulnerabilities in how expiration dates are handled during transactions.

Managing the cyber risk of agentic AI
Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the unintended activity.

9 million images of people’s faces exposed by reverse lookup service
A researcher found an exposed database containing 9 million images that belonged to people finder service ClarityCheck.

Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities
The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks. The post Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities appeared first on SecurityWeek.

Why "Shady AI" is Security's Next Big Governance Problem
A recent incident at Meta involving an approved AI agent exposing sensitive data highlights the growing challenge of "shady AI." Unlike "shadow AI" (unapproved tools), shady AI involves approved tools being used in unexpected or poorly governed ways within an organization's visibility. This presents a significant governance problem for security teams, as traditional methods struggle to keep pace with the rapid evolution of AI capabilities and usage patterns.