Visualização normal

Hoje — 9 de Setembro de 2026Stream principal
  • ✇Cybersecurity News
  • Apache Impala Vulnerabilities Expose Big Data to Remote Code Execution Do Son
    Four Apache Impala vulnerabilities expose systems to remote code execution and authentication bypass. Upgrade to Impala 4.5.2 to secure your clusters now. Related Posts: Cisco Secure Boot Bypass Details and PoC Exploit Disclosed September 2026 Android Security Bulletin Fixes Critical System RCE Flaws CVE-2026-84372 PoC Disclosed: Predis Command Injection Flaw The post Apache Impala Vulnerabilities Expose Big Data to Remote Code Execution appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Critical Siemens Vulnerabilities Hit Industrial Edge and OIS Do Son
    Two critical Siemens vulnerabilities (CVE-2026-18963, CVE-2026-50093) allow account takeover and root access. See affected versions and fixes. Related Posts: Cisco Secure Boot Bypass Details and PoC Exploit Disclosed September 2026 Android Security Bulletin Fixes Critical System RCE Flaws Apache Impala Vulnerabilities Expose Big Data to Remote Code Execution The post Critical Siemens Vulnerabilities Hit Industrial Edge and OIS appeared first on Daily CyberSecurity.
     
Ontem — 8 de Setembro de 2026Stream principal
  • ✇Cybersecurity News
  • Public PoC Exploit Disclosed for Rclone Auth Proxy Bypass Do Son
    A critical Rclone auth proxy bypass vulnerability exposes cloud storage. A public PoC is disclosed for GHSA-xwwr-4h3p-r22c and GHSA-p569-5gjg-9cmj. Related Posts: September 2026 SAP Security Patch Day Fixes Critical Flaws ASUS Patches Control Center Express and Armoury Crate Flaws Public PoC Disclosed for ZcopyReaper Linux Vulnerability (CVE-2026-43502) The post Public PoC Exploit Disclosed for Rclone Auth Proxy Bypass appeared first on Daily CyberSecurity.
     
Antes de ontemStream principal
  • ✇Cybersecurity News
  • MikroTrick PoC: RouterOS Admin Rights Exploited In Wild Do Son
    The MikroTrick PoC is publicly disclosed. This MikroTrick RouterOS flaw is actively exploited in the wild, granting full administrative privileges. Related Posts: CVE-2026-86218 (CVSS 10): N-central Pre-Auth RCE Exploited in the Wild AI Agent Coordination: The Unprecedented OpenAI Breakout Roundcube Security Update Fixes 12 Webmail Flaws The post MikroTrick PoC: RouterOS Admin Rights Exploited In Wild appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • AiTM Phishing Campaign Targets Healthcare via Account Takeovers Do Son
    A new AiTM phishing campaign targets healthcare. Learn how this healthcare AiTM phishing campaign chains compromised accounts to bypass MFA. Related Posts: US Offers $10M for IRGC Cyber Leader Coder Registry Attack: Hijacked Cloudflare Pool Served Malicious Terraform Modules Toy Ghouls Backdoor Uses HiveMQ and Element for C2 The post AiTM Phishing Campaign Targets Healthcare via Account Takeovers appeared first on Daily CyberSecurity.
     
  • ✇Firewall Daily – The Cyber Express
  • Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk Samiksha Jain
    Two Citrix NetScaler vulnerabilities affecting Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products have prompted a patching warning for Australian organisations. The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has advised organisations using the products to assess their environments and apply available security updates as a priority. Citrix has identified two vulnerabilities affecting NetScaler ADC and NetScaler Gatew
     

Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk

4 de Setembro de 2026, 03:21

Citrix NetScaler vulnerabilities

Two Citrix NetScaler vulnerabilities affecting Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products have prompted a patching warning for Australian organisations. The Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) has advised organisations using the products to assess their environments and apply available security updates as a priority. Citrix has identified two vulnerabilities affecting NetScaler ADC and NetScaler Gateway, which are critical edge devices used in enterprise networking to securely deliver applications, data and remote access to users.

Citrix NetScaler Vulnerabilities Affect ADC and Gateway

The first flaw, CVE-2026-19489, is a memory overflow vulnerability. According to the alert, exploitation of this vulnerability requires SIP ALG, or Session Initiation Protocol Application Layer Gateway, to be enabled on a Large Scale NAT (LSN) group configuration. The second flaw, CVE-2026-19490, is an authentication bypass vulnerability. The vulnerability requires SAML actions to be enabled and/or the affected product to be configured as a VPN gateway. The conditions required for each vulnerability mean that organisations need to assess their specific Citrix configurations to determine whether affected systems are present in their environments.

Patches Released for Citrix NetScaler products

Citrix released patches for the affected products on August 19, 2026. ASD's ACSC is urging organisations to review the vendor's mitigation guidance, identify vulnerable versions of Citrix products and update affected systems to the latest versions. The advisory places particular emphasis on timely patching because critical edge devices are frequently targeted by threat actors as an entry point into sensitive environments. However, ASD's ACSC said it has no information indicating that a specific Australian industry or sector is currently being targeted in connection with these vulnerabilities.

Organisations Urged to Assess Vulnerable Versions

The mitigation guidance calls on organisations to assess their networks and environments for vulnerable versions of Citrix products and apply patches as soon as practicable. Organisations should also review the mitigation advice provided by Citrix and confirm that affected systems have been updated. Where NetScaler ADC and NetScaler Gateway products are managed by a third party, organisations are advised to contact the relevant managed service provider (MSP) or enterprise IT provider. They should confirm that the products have been patched and are being monitored for suspicious activity. This step is particularly relevant for organisations that do not directly manage their Citrix infrastructure and may rely on external providers for patching and monitoring.

Monitoring Remains Important After Patching

Alongside addressing the Citrix NetScaler vulnerabilities, organisations are advised to monitor affected environments for suspicious activity. The alert recommends notifying ASD's ACSC if suspicious activity is detected. The two vulnerabilities affect different configurations, with CVE-2026-19489 requiring SIP ALG to be enabled on an LSN group configuration, while CVE-2026-19490 requires SAML actions to be enabled and/or the product to be configured as a VPN gateway. For Australian organisations using Citrix NetScaler products, the immediate steps outlined by ASD's ACSC are to identify vulnerable versions, apply the available patches, confirm third-party-managed systems have been addressed and maintain monitoring for suspicious activity.
  • ✇Cybersecurity News
  • FreeRDP 3.31.0 Fixes Pre-Auth RCE Chain in Server Do Son
    FreeRDP 3.31.0 patches 5 server-role flaws, including a pre-auth remote code execution chain affecting GNOME Remote Desktop and KDE krdp. Related Posts: Critical Google Chrome Vulnerabilities Patched in New Update CVE-2026-80047: Hugging Face Transformers Library Vulnerability CVE-2026-68162: Linux Kernel Root Escalation PoC Public The post FreeRDP 3.31.0 Fixes Pre-Auth RCE Chain in Server appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Proxmox VE 7 Auth Bypass: PoC Public, Exploited in the Wild Do Son
    A public PoC now targets a Proxmox VE authentication bypass in EOL 7.x releases, and the pre-auth flaw is exploited in the wild for root access. Related Posts: Critical Google Chrome Vulnerabilities Patched in New Update CVE-2026-80047: Hugging Face Transformers Library Vulnerability CVE-2026-68162: Linux Kernel Root Escalation PoC Public The post Proxmox VE 7 Auth Bypass: PoC Public, Exploited in the Wild appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover Do Son
    A critical Artifactory authentication bypass flaw (CVE-2026-82329) is exploited in the wild, letting attackers obtain administrative privileges. Related Posts: CVE-2026-81934: Redis RCE PoC Exploit Now Public CVE-2026-78319: SAUTER Controller RCE Flaw Disclosed Cosmos EVM Flaw Triggers Multi-Chain Heist The post CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Apache Tomcat Patches 11 Vulnerabilities in 11.0.25 Update Do Son
    Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now. Related Posts: GitLab Updates Fix Arbitrary Command Execution Vulnerability FreeBSD Patches Eight Kernel Vulnerabilities UniFi CVE-2026-77537 (CVSS 10.0): Command Injection Flaws Hit 22 Ubiquiti Products The post Apache Tomcat Patches 11 Vulnerabilities in 11.0.25 Update appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Ebyte NE2-D11 Gateway Hit by 11 Vulnerabilities, No Patch Yet Do Son
    CISA warns of 11 Ebyte NE2-D11 vulnerabilities, four rated 9.8, that allow full device takeover. No patch is confirmed available yet. Related Posts: GitLab Updates Fix Arbitrary Command Execution Vulnerability FreeBSD Patches Eight Kernel Vulnerabilities UniFi CVE-2026-77537 (CVSS 10.0): Command Injection Flaws Hit 22 Ubiquiti Products The post Ebyte NE2-D11 Gateway Hit by 11 Vulnerabilities, No Patch Yet appeared first on Daily CyberSecurity.
     

[Joint Cybersecurity Advisory] Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)

Por:ATCP
29 de Julho de 2026, 12:00
This technical analysis report was prepared as part of the joint cybersecurity advisory titled “Advisory on Cyberattacks Targeting Korean Citizens and Businesses by State-Sponsored Hacking Groups” issued by the Republic of Korea’s National Intelligence Service (NIS), National Police Agency (NPA), Korea Internet & Security Agency (KISA), and Financial Security Institute (FSI).   OverView AhnLab SEcurity […]
  • ✇ASEC BLOG
  • Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient) ATCP
    AhnLab SEcurity intelligence Center (ASEC) previously disclosed an attack case in which the Kimsuky group used spear phishing attacks to install the PebbleDash malware in a post titled “Analysis of the Kimsuky Group’s Latest Attacks Exploiting PebbleDash and RDP Wrapper” [1]. The same threat actors have continued their activities in 2026 and have recently been […]
     

Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)

Por:ATCP
16 de Julho de 2026, 12:00
AhnLab SEcurity intelligence Center (ASEC) previously disclosed an attack case in which the Kimsuky group used spear phishing attacks to install the PebbleDash malware in a post titled “Analysis of the Kimsuky Group’s Latest Attacks Exploiting PebbleDash and RDP Wrapper” [1]. The same threat actors have continued their activities in 2026 and have recently been […]

Google’s Gemini lets strangers send messages from your locked Android phone

17 de Julho de 2026, 19:30
Gemini, Google's AI assistant, is supposed to make life easier for Android smartphone owners. But right now it may also be making life easier for anyone anyone who happens to pick up your phone. Read more in my article on the Hot for Security blog.
  • ✇SOC Prime Blog
  • CVE-2026-50751: Check Point VPN Authentication Bypass Exploited in Targeted Attacks SOC Prime Team
    Organizations continue to face elevated risk from edge-device flaws that can hand attackers an initial foothold without valid credentials. CVE-2026-50751 is a critical authentication bypass issue in Check Point VPN Remote Access and Mobile Access that allows a remote, unauthenticated attacker to establish a VPN session without a valid user password. According to public reporting, the flaw stems from a logic-flow weakness in certificate validation and is being exploited in a limited number of re
     

CVE-2026-50751: Check Point VPN Authentication Bypass Exploited in Targeted Attacks

9 de Junho de 2026, 15:37

Organizations continue to face elevated risk from edge-device flaws that can hand attackers an initial foothold without valid credentials. CVE-2026-50751 is a critical authentication bypass issue in Check Point VPN Remote Access and Mobile Access that allows a remote, unauthenticated attacker to establish a VPN session without a valid user password. According to public reporting, the flaw stems from a logic-flow weakness in certificate validation and is being exploited in a limited number of real-world attacks.

The exposure is narrower than a generic “all Check Point gateways are vulnerable” headline suggests. Public reporting says the issue only applies when Remote Access VPN or Mobile Access is enabled, IKEv1 is enabled for remote access, legacy clients are accepted, and the gateway does not require a machine certificate. In that configuration, the flaw can open a path to unauthorized VPN access on affected Security Gateways and Spark firewalls.

CVE-2026-50751 analysis

For CVE-2026-50751 analysis, the most important takeaway is that the bug is an authentication bypass rather than a direct remote code execution issue. Help Net Security and The Hacker News both report that the weakness allows an attacker to connect through the VPN without a valid password, after which additional post-authentication activity is required to access internal resources or move toward privilege escalation. That makes the flaw especially dangerous on internet-facing gateways where remote access is broadly enabled for users and contractors.

Public reporting shows that CVE-2026-50751 affects Check Point deployments using deprecated IKEv1 for remote access, including certain Security Gateway releases and Spark firewall versions. The same reports say Check Point first noticed suspicious activity on June 4, 2026, while the earliest known exploitation dates back to May 7, 2026, with attacks increasing in early June. The observed campaigns were limited to a few dozen organizations globally, and one confirmed case involved a Qilin ransomware affiliate.

The post-compromise activity described in the reporting helps clarify the practical risk. Help Net Security says investigators saw suspected data exfiltration activity involving Rclone, possible Tox protocol usage, and attacker-operated VPS infrastructure hosted by providers including Kaupo Cloud HK, Shock Hosting, and Vultr Holdings. The Hacker News adds that once access was established, attackers attempted to download malicious ELF files from actor-controlled infrastructure. Those published indicators are the strongest public details for CVE-2026-50751 currently available.

At the time of writing, the cited reports do not point to a public CVE-2026-50751 PoC, but they do confirm live exploitation and targeted operational use. They also note that Check Point believes the same actor infrastructure may be probing or exploiting other VPN-related flaws across multiple vendors, which raises the urgency for organizations still running vulnerable remote-access configurations.

CVE-2026-50751 Mitigation

The most effective CVE-2026-50751 mitigation is to upgrade affected gateways and firewalls to fixed versions and immediately review environments for signs of compromise. The Hacker News lists affected Check Point Security Gateway and Spark branches, while Help Net Security says customers should begin forensic log audits and configuration reviews starting from the earliest observed exploitation period in May 2026.

If immediate patching is delayed, Check Point’s alternative mitigations are operationally important. Help Net Security says customers should disable use of deprecated IKEv1, remove support for legacy Remote Access clients, and require a machine certificate to establish connections. These measures directly reduce the conditions needed for exploitation and are especially relevant for exposed Check Point VPN Remote Access deployments that still support older client workflows.

For defenders focused on CVE-2026-50751 detection, the most practical path is to review vendor-published indicators and audit historical logs from the earliest known exploitation date. Help Net Security says Check Point provided CVE-2026-50751 IOCs and urged incident response teams to prioritize forensic review, while the broader operational guidance is to detect CVE-2026-50751 by correlating suspicious VPN connections, legacy IKEv1 use, unauthorized remote-access sessions, unusual VPS-originating access, and post-authentication activity tied to exfiltration tooling.

CHECK AVAILABLE DETECTIONS

Disclaimer: Detection content may not be available for every CVE. Check the SOC Prime Platform for current coverage. If you don’t find relevant detections now, please check back later.

FAQ

What is CVE-2026-50751 and how does it work?

CVE-2026-50751 is a critical authentication bypass flaw in Check Point Remote Access VPN and Mobile Access. It works by abusing a certificate-validation logic weakness that lets a remote attacker establish a VPN session without a valid password when vulnerable IKEv1-based configurations are in place.

When was CVE-2026-50751 first discovered?

The public reports do not provide a private discovery date. What they do confirm is that Check Point first saw suspicious activity on June 4, 2026, while the earliest known exploitation was observed on May 7, 2026.

What is the impact of CVE-2026-50751 on systems?

The main impact is unauthorized VPN access by a remote attacker without a valid password. From there, follow-on activity can include access to internal resources, downloading additional tools, data exfiltration, and ransomware-related post-compromise actions.

Can CVE-2026-50751 still affect me in 2026?

Yes. Systems can still be exposed in 2026 if they continue to run affected versions and keep the vulnerable combination of Remote Access or Mobile Access, IKEv1, legacy client support, and no machine-certificate requirement.

How can I protect myself from CVE-2026-50751?

Patch affected Check Point products, disable deprecated IKEv1 where possible, remove legacy client support, require machine certificates, and review the vendor’s published indicators and forensic guidance to confirm whether your gateways were targeted before remediation.



The post CVE-2026-50751: Check Point VPN Authentication Bypass Exploited in Targeted Attacks appeared first on SOC Prime.

  • ✇ASEC BLOG
  • May 2026 Dark Web Issue Trend Report ATCP
    Notes the May 2026 Dark Web Issue Trend Report summarizes the Major Issues that occurred on the deep web and dark web. it stated that due to the nature of the sources, some of the information cannot be fully verified for factual accuracy. Major Issues Hasan’s BreachForums experienced a moderator split, with HasanBroker being ousted […]
     

May 2026 Dark Web Issue Trend Report

Por:ATCP
8 de Junho de 2026, 12:00
Notes the May 2026 Dark Web Issue Trend Report summarizes the Major Issues that occurred on the deep web and dark web. it stated that due to the nature of the sources, some of the information cannot be fully verified for factual accuracy. Major Issues Hasan’s BreachForums experienced a moderator split, with HasanBroker being ousted […]
  • ✇SOC Prime Blog
  • CVE-2026-41940: Critical cPanel & WHM Authentication Bypass Exposes Hosting Servers to Admin Takeover SOC Prime Team
    A newly disclosed CVE-2026-41940 vulnerability in cPanel & WHM has put internet-facing hosting infrastructure under urgent scrutiny. The flaw carries a CVSS score of 9.8 and can let an unauthenticated remote attacker bypass authentication and gain administrative access, while cPanel’s advisory says the issue affects cPanel software, including DNSOnly, across all versions after 11.40. For defenders, CVE-2026-41940 detection should focus on exposed control panel instances, emergency patch val
     

CVE-2026-41940: Critical cPanel & WHM Authentication Bypass Exposes Hosting Servers to Admin Takeover

30 de Abril de 2026, 09:47

A newly disclosed CVE-2026-41940 vulnerability in cPanel & WHM has put internet-facing hosting infrastructure under urgent scrutiny. The flaw carries a CVSS score of 9.8 and can let an unauthenticated remote attacker bypass authentication and gain administrative access, while cPanel’s advisory says the issue affects cPanel software, including DNSOnly, across all versions after 11.40.

For defenders, CVE-2026-41940 detection should focus on exposed control panel instances, emergency patch validation, and session-file triage rather than malware hunting. Hosting provider KnownHost said the flaw was being actively exploited in the wild, and that a public technical analysis plus exploit code had already been released by watchTowr, raising the likelihood of broader opportunistic abuse.

The business risk is substantial because successful exploitation can give attackers control over the cPanel host, its configurations and databases, and the websites it manages. A simple Shodan query returned roughly 1.5 million exposed cPanel instances, underscoring how much attack surface may be available to both targeted and mass scanning activity.

CVE-2026-41940 analysis

The bug is describes as an authentication bypass rooted in CRLF injection during the login and session-loading process in cPanel & WHM. According to its technical overview, cpsrvd writes a new session file to disk before authentication completes, and an attacker can manipulate the whostmgrsession cookie so attacker-controlled values avoid the expected encryption path and are written into the session file unsanitized.

In practical terms, the vulnerability in CVE-2026-41940 lets an attacker inject arbitrary properties such as user=root into a session file, then trigger a reload so the application treats the session as administrative. That is why this issue is especially dangerous for shared hosting environments and server operators: it is not merely a login bug, but a route to privileged control over the management plane itself.

Unlike a malware dropper, the CVE-2026-41940 payload is a crafted authentication request that abuses newline injection and malformed session values to poison pre-auth session data. A public CVE-2026-41940 poc was already available through third-party research.

Official details for CVE-2026-41940 are broader than the exploit mechanics alone. cPanel says the issue affects cPanel software including DNSOnly, while patched builds were issued for 11.86.0.41, 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.130.0.19, 11.132.0.29, 11.134.0.20, and 11.136.0.5, alongside WP Squared 136.1.7. TheCyberExpress also highlighted that administrators must verify the installed version and restart cpsrvd after updating.

Just as importantly, CVE-2026-41940 affects not only directly exposed cPanel & WHM systems but also operational workflows that rely on pinned builds or disabled automatic updates. That matters because cPanel warned that such servers will not auto-update and must be manually remediated as a priority, while unsupported versions may also remain exposed until organizations move to supported release tracks.

Explore Detections

CVE-2026-41940 Mitigation

The vendor’s primary guidance is straightforward: update immediately to one of the fixed versions using /scripts/upcp –force, confirm the installed build with /usr/local/cpanel/cpanel -V, and restart the service with /scripts/restartsrv_cpsrvd. cPanel also says administrators should manually identify systems where updates are disabled or version pinning prevents automatic remediation.

When patching cannot happen right away, cPanel recommends temporary containment steps that include blocking inbound traffic on ports 2083, 2087, 2095, and 2096 at the firewall or stopping cpsrvd and cpdavd. TheCyberExpress echoed the same short-term advice and noted that some providers restricted panel access while broader patch rollout was underway.

To detect CVE-2026-41940, defenders should use the vendor’s filesystem-based detection script and review suspicious entries under /var/cpanel/sessions. cPanel’s script looks for session artifacts such as token_denied appearing together with cp_security_token, authenticated attributes inside pre-auth sessions, suspicious tfa_verified states, and malformed multi-line password values. Those published checks effectively act as CVE-2026-41940 iocs for post-exploitation triage.

If the script flags likely compromise, cPanel says defenders should purge affected sessions, force password resets for root and all WHM users, audit /var/log/wtmp and WHM access logs, and look for persistence such as cron entries, SSH keys, or backdoors. In other words, CVE-2026-41940 mitigation should be handled as both patching and incident response, not just a routine version upgrade. When patching cannot happen right away, cPanel recommends temporary containment steps that include blocking inbound traffic on ports 2083, 2087, 2095, 2096 and http ports 2082, 2086 at the firewall.

FAQ

What is CVE-2026-41940 and how does it work?

It is a critical cPanel & WHM authentication bypass flaw that stems from session handling and CRLF injection in the login/session-loading flow. Attackers can manipulate pre-auth session data and ultimately create administrator-level access without valid credentials.

When was CVE-2026-41940 first discovered?

The private discovery date has not been publicly disclosed in the sources reviewed. Publicly, cPanel acknowledged the issue in a security advisory published on April 28, 2026.

What is the impact of CVE-2026-41940 on systems?

Successful exploitation can give an unauthenticated attacker administrative access to cPanel & WHM, which can translate into control over the host system, configurations, databases, and hosted websites. In shared hosting environments, that can turn a panel compromise into a full platform compromise.

Can CVE-2026-41940 still affect me in 2026?

Yes. Any exposed system that has not been updated to a fixed build can still be at risk in 2026, especially if automatic updates are disabled, the server is pinned to a vulnerable version, or it is running an unsupported release that has not yet been moved to a supported patched branch.

How can I protect myself from CVE-2026-41940?

Apply the vendor’s patched build immediately, restart cpsrvd, run the detection script against /var/cpanel/sessions, review for suspicious session artifacts, and treat any confirmed hit as a possible compromise requiring session purges, password resets, and log review. Short-term firewall restrictions can reduce exposure, but cPanel make clear that patching is the priority.



The post CVE-2026-41940: Critical cPanel & WHM Authentication Bypass Exposes Hosting Servers to Admin Takeover appeared first on SOC Prime.

❌
❌