Tag: authentication bypass
112 articles

METR Exposes $600K API Credit Theft After Weeks of Undetected Breach
A shocking $600,000 theft of API credits went undetected for weeks, leaving a nonprofit reeling - here's how a brief security lapse led to the massive breach. Attackers exploited a vulnerable API key, draining credits from METR's public models account in just a few short weeks.

Attackers Exploit JFrog Artifactory Flaw to Mint Admin Tokens
A critical flaw in JFrog Artifactory, known as CVE-2026-82329, allows attackers to easily gain admin access without needing authentication or user interaction, posing a huge risk to affected instances. This near-maximum-score vulnerability has already been patched in Artifactory version 7.161.20.

Unpatched Microsoft Exchange Servers Exposed to Hijack Attacks
Thousands of Microsoft Exchange servers remain vulnerable to a high-severity flaw, leaving 21,899 internet-facing systems open to hijack attacks that could give attackers control of every mailbox. This unpatched authentication-bypass vulnerability, CVE-2026-62911, was fixed by Microsoft in August, but many servers still haven't been updated.

PaperCut Issues Second Patch as Hackers Exploit Flaws
PaperCut has released an updated emergency patch to tackle vulnerabilities that hackers are actively exploiting, working closely with security researchers to stay one step ahead. This new patch includes extra security measures to protect PaperCut NG and MF installations from attacks.

Attackers Exploit miniOrange SAML Flaws to Hijack WordPress Admin Access
A critical vulnerability in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress allows hackers to hijack admin access with just a few clicks, giving them the keys to your site's kingdom. This flaw lets unauthenticated attackers log in as any existing user, including administrators, by exploiting a weakness in signature verification.

Keycloak Flaw Exposes Accounts to Unauthenticated Takeover
A critical flaw in Keycloak, rated 9.1 by Red Hat, allows hackers to hijack any account, including admin ones, by manipulating the password reset process. This vulnerability, CVE-2026-18963, lets attackers take control without even logging in.

Microsoft patches exploited Entra ID flaw amid rising attacks
Microsoft has patched a critical vulnerability in its Entra ID platform, known as CVE-2026-69836, which allowed attackers to execute code remotely with ease, and has already been exploited in recent attacks. This flaw enabled unauthorized threat actors to gain control and wreak havoc, making swift action crucial to prevent further damage.

Citrix Flaw Exposes Authentication on NetScaler Servers
Citrix has warned of a critical authentication bypass vulnerability, CVE-2026-19490, affecting NetScaler servers, urging customers to review their configurations and prioritize patching based on exposure and deployment role.

Citrix Warns of Two New NetScaler Flaws
Citrix is urging customers to take immediate action to protect their NetScaler ADC and Gateway deployments from two newly discovered vulnerabilities, including a critical authentication bypass flaw that could allow remote attackers to gain unauthorized access. Upgrade to the recommended builds as soon as possible to safeguard your systems.

Hackers Exploit Public Wi-Fi DNS to Harvest Credentials
Beware of hackers lurking on public Wi-Fi networks at hotels, conference centers, and other hotspots, who are using a sneaky trick to steal your login credentials by hijacking the network's DNS settings. By changing just one setting, they can redirect you to fake login pages that look legit - and that's all they need to get their hands on your sensitive info.

WordPress Plugin Flaw Enables Admin Takeover on 40,000 Sites
A critical vulnerability in the popular User Profile Builder plugin has put over 40,000 WordPress sites at risk of admin takeover, with a CVSS rating of 9.8; site owners should immediately update to version 3.16.5 or later to patch the flaw.

SAP Exploits Maximum-Severity Commerce Cloud Flaw in Active Attacks
SAP Commerce Cloud has a critical vulnerability, known as CVE-2026-58231, that allows unauthenticated attackers to wreak havoc by executing arbitrary code and compromising internal components. This maximum-severity flaw, scoring a perfect 10.0 on the CVSS scale, stems from weak authorization checks and input validation.

Hackers exploit macOS flaw to deploy Monero miners
Hackers are exploiting a recently fixed macOS security flaw to secretly deploy Monero miners, and experts warn that public exploit code is now available, putting users at risk. This vulnerability, affecting macOS's built-in Screen Sharing feature, allows attackers to gain access without valid credentials.

Attackers Exploit SharePoint Flaw After Public PoC Release
Microsoft warned that a critical SharePoint flaw, patched in July 2026, could allow attackers to bypass authentication and disclose files or modify data. This vulnerability, tracked as CVE-2026-55040, has now been exploited by attackers following the public release of a proof-of-concept exploit.

Hackers Exploit New Microsoft SharePoint Vulnerability in Attacks
Hackers are already exploiting a newly discovered critical flaw in Microsoft SharePoint, with over 8,500 servers exposed online and vulnerable to attacks. This authentication bypass vulnerability, known as CVE-2026-55040, allows hackers to disclose files, modify data, and wreak havoc on your system.

OpenAI Bolsters Cybersecurity with GPT-5.6-Cyber Model, Two-Tier Access Program
OpenAI's new GPT-5.6-Cyber model is a game-changer in cybersecurity, capable of completing 95% of sensitive requests in advanced scenarios like exploit-chain development and privilege escalation. This purpose-trained model outperforms its general-access counterpart by a landslide, showcasing its potential to revolutionize cybersecurity.

Paperclip AI Flaws Expose Sensitive Data, Enable Unauthenticated Command Execution
Critical flaws in Paperclip AI's control plane have been exposed, allowing unauthenticated command execution and sensitive data breaches due to a systemic failure in handling identity boundaries. This alarming vulnerability was triggered by a simple self-registration process that was left unchecked.

CISA Flags N-able N-central Flaw as Exploited Vulnerability
A critical flaw in N-able N-central has been flagged by CISA as an exploited vulnerability, allowing attackers to bypass authentication and take over accounts. This weakness, known as CVE-2026-18577, lets hackers gain admin access to vulnerable servers and deploy malicious persistence mechanisms.

N-able Discloses Auth Bypass Flaw in N-central Exploited in Attacks
A critical authentication bypass vulnerability, CVE-2026-18577, is under active attack, putting N-able's N-central servers at risk - but a hotfix (2026.3.1.7) is now available to prevent further exploitation. This flaw is linked to an earlier, incomplete patch for CVE-2026-18576, which also threatened administrative account takeovers.

N-able Servers Compromised After Incomplete Fix
N-able's servers were compromised due to an incomplete fix for a critical vulnerability, allowing attackers to exploit an authentication bypass and gain remote administrative access to on-premises servers and customer systems. The incident highlights the importance of thorough patching, as N-able's initial fix failed to fully address the issue.

Check Point Flaw Exploited as Researchers Release Public PoC
A critical flaw in Check Point's SmartConsole, known as CVE-2026-16232, allows hackers to bypass authentication and gain full administrative privileges with a staggering CVSS score of 9.3. This vulnerability lets unauthenticated remote attackers obtain a login token and take control, potentially modifying security policies and configurations.

Check Point Discloses Zero-Day Flaw in SmartConsole Exploited in Attacks
A critical zero-day flaw in Check Point's SmartConsole has been exploited in attacks, allowing hackers to modify security policies and configurations with ease. A patch is now available to fix this authentication bypass vulnerability, tracked as CVE-2026-16232.

Check Point Disrupts Exploited SmartConsole Flaw Granting Admin Access
A critical flaw in Check Point's SmartConsole has been exploited, allowing hackers to gain admin access with a CVSS score of 9.3, and Check Point has released updates to address the vulnerability. This authentication-bypass flaw lets attackers modify security policies and configurations with full administrative rights.

Qilin Ransomware Exploits Palo Alto Networks Flaw for Initial Access
In a recent wave of attacks, hackers exploited a high-severity flaw in Palo Alto Networks' PAN-OS software to gain initial access for Qilin ransomware attacks. This vulnerability, known as CVE-2026-0257, allowed attackers to bypass authentication and establish VPN sessions without valid credentials.