LIVE · cybersecurity feed
Live wire
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to AttackersNew CSS Attacks Can Break Webmail Defenses to Steal Passwords and TokensCVE-2023-38646 · Metabase Zero-Day Exploited in Wild Allows Admin Access Without AuthenticationCVE-2026-18577 · N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and PersistCVE-2026-8037 · Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit AttemptsLiving off the coding agent: Two tales of tunnels and LaunchAgentsInside the Modern SOC: The Identity Front Door
identity securityhigh

Inside the Modern SOC: The Identity Front Door

Attackers are increasingly leveraging compromised identities and social engineering tactics to gain initial access into corporate networks, bypassing traditional security measures. This shift means security teams must focus on identity context and behavioral analysis, rather than just login credentials, to detect and respond to threats effectively. Unified security telemetry and automated correlation are crucial for SOCs to identify sophisticated, identity-driven attacks before they escalate.

zeroday.news ·

Attackers are increasingly leveraging compromised identities to gain initial access to enterprise environments, with identity weaknesses playing a role in nearly 90% of incidents investigated by Unit 42, a cybersecurity research and incident response team. This trend is highlighted in the 2026 Unit 42 Global Incident Response Report, which also indicates that 65% of initial access activities involve identity-based techniques.

The report identifies credential theft, multifactor authentication (MFA) manipulation, session hijacking, and social engineering as highly effective methods for attackers to breach systems. These tactics are often employed through phishing campaigns, social engineering calls, MFA fatigue attacks, exploitation of compromised third-party accounts, and misuse of help desk processes.

Once initial access is gained, attackers typically establish persistence, elevate privileges, and move laterally across various environments. This malicious activity often mimics legitimate administrative behavior, allowing it to remain undetected long enough for attackers to broaden their foothold before security teams fully recognize the scope of the incident.

Threat groups like Muddled Libra, also known as Scattered Spider, exemplify this approach by heavily relying on social engineering and identity abuse. The 2026 Unit 42 Global Incident Response Report notes that 87% of incidents span multiple attack surfaces, meaning an initial identity compromise can quickly escalate into a multi-domain investigation requiring defenders to correlate activity across the entire environment.

The ultimate objectives of these identity-driven compromises vary, including ransomware deployment, data theft, financial fraud, or establishing long-term persistence. Regardless of the specific goal, identity compromise frequently serves as the foundational step for broader attacker objectives.

Security controls within organizations often generate warning signs of these activities, but without automated correlation, these signals can appear as low-priority isolated events. This allows attackers to expand their access before defenders can recognize the full extent of the incident.

To counter these evolving threats, security leaders are advised to prioritize identity context by correlating identity activity with telemetry from endpoints, cloud services, SaaS applications, and networks. This provides the behavioral context necessary to differentiate legitimate user activity from compromised accounts. Reducing manual investigation by consolidating telemetry and investigations into a unified view is also crucial, as it minimizes the need for analysts to pivot between disconnected tools, enabling faster and more confident responses.

Continuous improvement of detection mechanisms is also emphasized, requiring regular refinement of detections, correlation rules, and response playbooks to adapt to evolving attacker techniques. Furthermore, dedicating time to threat hunting can help uncover credential abuse, privilege escalation, and hidden persistence before they escalate into larger incidents.

identity securitysocthreat intelligenceincident responsesocial engineering
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default

Researchers scour social media to measure developer concerns about AI coding tools

vulnerabilityhigh

Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own […]

breachcritical

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

The RovoBlast attack method identified by Varonis researchers could have been exploited to steal Confluence, Jira and SharePoint data. The post Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data appeared first on SecurityWeek.

surveillance

Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed

Flock Safety, a company known for its public safety cameras, reportedly pitched a plan to utilize dashcams from rideshare and delivery vehicles to collect license plate data. This initiative, which did not proceed, would have involved a partnership with Nexar, a dashcam manufacturer, and potentially involved drivers without their knowledge. Separately, a former Flock employee alleged the company provided direct camera access to ICE and CBP through a pilot program, contradicting internal statements.

email securityhigh

Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All

Security researchers Cory Solovewicz and Mike Sheward have inadvertently created honeypots by purchasing domains like noreply.us and deleteduser.com. Organizations are mistakenly sending sensitive data, including personal information, company secrets, and system credentials, to these domains, believing they are unmonitored. Both researchers are now working to notify affected entities and raise awareness about this widespread misconfiguration, highlighting the potential for malicious actors to exploit such vulnerabilities.

atlassianhigh

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Two security firms have identified vulnerabilities in Atlassian's Rovo assistant that could allow attackers to exfiltrate data from Jira and Confluence. One vulnerability, dubbed RovoBlast by Varonis Threat Labs, allowed attackers to trick Rovo into sending data to an external server via a malicious link. Atlassian has confirmed this issue is fixed server-side. The second vulnerability, found by PromptArmor, involved injecting malicious instructions into content Rovo processes, enabling data exfiltration without explicit user approval. The status of this second vulnerability remains unconfirmed after its initial disclosure.