LIVE · cybersecurity feed
Live wire
CVE-2026-15409 · Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterAnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodesCVE-2026-60004 · Hackers now exploit critical Gitea flaw in code injection attacksEmployee benefits platform Paylogix says hackers stole financial and health dataU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesCVE-2026-61979 · Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableCVE-2024-28224 · A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClawAustralia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical DataUS sanctions Iranian cyber actors as UK discloses power plant attack
security

RightCrowd Pass unifies mobile, physical, and biometric credentials

RightCrowd announced RightCrowd Pass, a credentialing solution that issues and manages mobile, physical and biometric access credentials from a single platform. Many large enterprises and universities rely on badge programs-built years ago. As organizations add mobile and biometric credentials, what began as a single access program can fragment into three separate systems, each with its own issuan

zeroday.news ·

RightCrowd has introduced RightCrowd Pass, a new credentialing solution designed to centralize the issuance and management of mobile, physical, and biometric access credentials from a single platform. The company states that the product aims to address the fragmentation often seen in large enterprises and universities, where legacy badge programs have expanded to include mobile and biometric options, leading to disparate systems for each credential type.

According to RightCrowd, this fragmentation can result in separate issuance and revocation processes, hindering security teams' ability to maintain a unified overview of access privileges. RightCrowd Pass consolidates these three credential types into one program, providing a unified view and management interface.

Mobile credentials within RightCrowd Pass are provisioned via a web-based API, allowing organizations to issue, suspend, and revoke them through existing systems without requiring a separate management console. RightCrowd's VP of Credential Technologies, Troy Johnston, noted that many mobile credential products necessitate deploying new applications and consoles, creating "blind spots" for security and IT teams regarding mobile users. RightCrowd Pass is designed to integrate mobile credentials into the overall access program from the outset.

The company also highlights efficiency improvements, claiming that deactivating, investigating, reissuing, and delivering a lost or damaged physical badge typically takes a security team an average of 12.2 minutes, excluding production and shipping. With RightCrowd Pass, mobile credentials can be suspended or revoked, individually or in groups, in under 60 seconds.

RightCrowd Pass mobile credentials are tied to a specific device through two-factor authentication, which RightCrowd suggests offers a lower risk profile compared to physical badges. This approach also contributes to reduced plastic card production and can count towards sustainability credits under green building frameworks such as LEED and BREEAM.

The solution is designed for compatibility with existing infrastructure, including technologies from HID, Wavelynx, and LEGIC. It integrates with various access points such as doors, elevators, turnstiles, parking systems, lockers, and secure printers, allowing organizations to deploy it without needing to standardize on a single vendor.

RightCrowd Pass is currently available to both new and existing RightCrowd customers. Organizations already using RightCrowd SmartAccess can integrate RightCrowd Pass into their current deployment. New customers starting with RightCrowd Pass also have the option to later add full Physical Identity and Access Management (PIAM) capabilities without changing vendors.

ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks. The post CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks appeared first on SecurityWeek.

CVE-2026-60004critical

Hackers now exploit critical Gitea flaw in code injection attacks

Attackers are actively exploiting a critical code injection vulnerability (CVE-2026-60004) in the self-hosted Gitea Git service. The flaw allows authenticated users with write access to execute arbitrary shell commands, and with default open registration, unauthenticated attackers can exploit it by creating an account. Gitea has released version 1.27.1 to address the issue, and CISA has ordered U.S. federal agencies to patch within three days due to active exploitation, with reports indicating cryptocurrency mining malware deployment.

mfa

The MFA Identity Trap: When Authentication Creates a False Sense of Security

Organizations are falling into an 'MFA Identity Trap' by conflating identity verification, authentication, and threat detection. This confusion can lead to a false sense of security, where systems successfully authenticate attackers instead of blocking them. A clear distinction between these processes is crucial for effective security.

security

Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests

Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by ABC News on August 10, based on chat logs and screenshots the user supplied. He had asked an

phishing

Bogus recruiters go after high-value corporate credentials on mobile

Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. Attackers are using a technique called browser-in-the-browser, or BitB, which CTM360 documented in earlier research on recruitment phishing. They scrape public profile data and use it to craft convincing scheduling flows designed to get past

vulnerability

Chrome 152 Patches Over 300 Vulnerabilities

Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities. The post Chrome 152 Patches Over 300 Vulnerabilities appeared first on SecurityWeek.