#authbypass — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #authbypass, aggregated by home.social.
-
Hackers Exploit WordPress Sites in miniOrange Auth Bypass Attacks
Hackers are actively exploiting WordPress sites using a clever combination of two vulnerabilities, CVE-2026-61979 and CVE-2026-15981, to bypass authentication and gain administrator access. This stealthy attack uses the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and hijack user sessions.
-
Hackers Exploit WordPress Sites in miniOrange Auth Bypass Attacks
Hackers are actively exploiting WordPress sites using a clever combination of two vulnerabilities, CVE-2026-61979 and CVE-2026-15981, to bypass authentication and gain administrator access. This stealthy attack uses the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and hijack user sessions.
-
IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.
#IBM #PowerSystems #Firmware #CVE #RCE #AuthBypass #InfoSec #PatchNow
-
IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.
#IBM #PowerSystems #Firmware #CVE #RCE #AuthBypass #InfoSec #PatchNow
-
IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.
#IBM #PowerSystems #Firmware #CVE #RCE #AuthBypass #InfoSec #PatchNow
-
IBM patches two Power Systems Firmware flaws, CVE-2026-16687 and CVE-2026-16835, both CVSS 9.6, that grant full control of the managed system.
#IBM #PowerSystems #Firmware #CVE #RCE #AuthBypass #InfoSec #PatchNow
-
Researchers at Cycode disclosed a critical vulnerability in NASA/JPL's AIT-GUI, the web console of the AMMOS Instrument Toolkit. The system exposed an unauthenticated HTTP server, enabling arbitrary command and script execution on spacecraft and instrument control systems.
#CriticalVulnerability #NASASecurity #SpaceSystems #AuthBypass
https://cyberworldops.eu/en/critical-vulnerability-in-nasajpl-s-ait-gui-commands-and-scripts
-
Researchers at Cycode disclosed a critical vulnerability in NASA/JPL's AIT-GUI, the web console of the AMMOS Instrument Toolkit. The system exposed an unauthenticated HTTP server, enabling arbitrary command and script execution on spacecraft and instrument control systems.
#CriticalVulnerability #NASASecurity #SpaceSystems #AuthBypass
https://cyberworldops.eu/en/critical-vulnerability-in-nasajpl-s-ait-gui-commands-and-scripts
-
CVE-2026-19490 (CVSS 9.3) is a critical NetScaler authentication bypass in NetScaler Gateway and ADC. Patch now to block unauthenticated access.
-
CVE-2026-19490 (CVSS 9.3) is a critical NetScaler authentication bypass in NetScaler Gateway and ADC. Patch now to block unauthenticated access.
-
TP-Link patched 5 TP-Link router vulnerabilities in ISP-managed mesh, router, and modem lines, including auth bypass and command injection.
#TPLink #RouterSecurity #CVE #AuthBypass #CommandInjection #IoT #Cybersecurity
-
TP-Link patched 5 TP-Link router vulnerabilities in ISP-managed mesh, router, and modem lines, including auth bypass and command injection.
#TPLink #RouterSecurity #CVE #AuthBypass #CommandInjection #IoT #Cybersecurity
-
TP-Link patched 5 TP-Link router vulnerabilities in ISP-managed mesh, router, and modem lines, including auth bypass and command injection.
#TPLink #RouterSecurity #CVE #AuthBypass #CommandInjection #IoT #Cybersecurity
-
TP-Link patched 5 TP-Link router vulnerabilities in ISP-managed mesh, router, and modem lines, including auth bypass and command injection.
#TPLink #RouterSecurity #CVE #AuthBypass #CommandInjection #IoT #Cybersecurity
-
Bez znajomości hasła można zalogować się do SharePointa jako admin.
No więc trzymajcie się krzeseł (lub poręczy w tramwajach ;-) – pierwszym krokiem ataku jest ominięcie podpisu JWT poprzez użycie algorytmu none 😅 Czyli mówię SharePointowi, żeby zupełnie zignorował podpis kryptograficzny mojego (sfałszowanego) tokena. A SharePoint grzecznie to wykonuje. W skrócie wysyłamy token z takim nagłówkiem: {“alg”: “none”, “typ”: “JWT”}...
#WBiegu #AuthBypass #Rce #Websec
https://sekurak.pl/bez-znajomosci-hasla-mozna-zalogowac-sie-do-sharepointa-jako-admin/
-
Bez znajomości hasła można zalogować się do SharePointa jako admin.
No więc trzymajcie się krzeseł (lub poręczy w tramwajach ;-) – pierwszym krokiem ataku jest ominięcie podpisu JWT poprzez użycie algorytmu none 😅 Czyli mówię SharePointowi, żeby zupełnie zignorował podpis kryptograficzny mojego (sfałszowanego) tokena. A SharePoint grzecznie to wykonuje. W skrócie wysyłamy token z takim nagłówkiem: {“alg”: “none”, “typ”: “JWT”}...
#WBiegu #AuthBypass #Rce #Websec
https://sekurak.pl/bez-znajomosci-hasla-mozna-zalogowac-sie-do-sharepointa-jako-admin/
-
Bez znajomości hasła można zalogować się do SharePointa jako admin.
No więc trzymajcie się krzeseł (lub poręczy w tramwajach ;-) – pierwszym krokiem ataku jest ominięcie podpisu JWT poprzez użycie algorytmu none 😅 Czyli mówię SharePointowi, żeby zupełnie zignorował podpis kryptograficzny mojego (sfałszowanego) tokena. A SharePoint grzecznie to wykonuje. W skrócie wysyłamy token z takim nagłówkiem: {“alg”: “none”, “typ”: “JWT”}...
#WBiegu #AuthBypass #Rce #Websec
https://sekurak.pl/bez-znajomosci-hasla-mozna-zalogowac-sie-do-sharepointa-jako-admin/
-
Bez znajomości hasła można zalogować się do SharePointa jako admin.
No więc trzymajcie się krzeseł (lub poręczy w tramwajach ;-) – pierwszym krokiem ataku jest ominięcie podpisu JWT poprzez użycie algorytmu none 😅 Czyli mówię SharePointowi, żeby zupełnie zignorował podpis kryptograficzny mojego (sfałszowanego) tokena. A SharePoint grzecznie to wykonuje. W skrócie wysyłamy token z takim nagłówkiem: {“alg”: “none”, “typ”: “JWT”}...
#WBiegu #AuthBypass #Rce #Websec
https://sekurak.pl/bez-znajomosci-hasla-mozna-zalogowac-sie-do-sharepointa-jako-admin/
-
Bez znajomości hasła można zalogować się do SharePointa jako admin.
No więc trzymajcie się krzeseł (lub poręczy w tramwajach ;-) – pierwszym krokiem ataku jest ominięcie podpisu JWT poprzez użycie algorytmu none 😅 Czyli mówię SharePointowi, żeby zupełnie zignorował podpis kryptograficzny mojego (sfałszowanego) tokena. A SharePoint grzecznie to wykonuje. W skrócie wysyłamy token z takim nagłówkiem: {“alg”: “none”, “typ”: “JWT”}...
#WBiegu #AuthBypass #Rce #Websec
https://sekurak.pl/bez-znajomosci-hasla-mozna-zalogowac-sie-do-sharepointa-jako-admin/
-
To resolve this ticket, patch vCenter to 9.1.0.0300, 9.0.2.0100, or 8.0 Update 3k; ESXi to 9.1.0.0200, 9.0.2.0100, or 8.0 Update 3k; and upgrade Workstation and Fusion to 26H1. Broadcom has separate instructions for Cloud Foundation 5.x. Is there anything else I can make catastrophically worse today?
Reward: You've received a Demonic Helpdesk Escalation Token — it does nothing, but the ticket has been marked Resolved.
#VMware #CriticalVulnerability #AuthBypass #VMEscape #vCenter (2/2)
-
To resolve this ticket, patch vCenter to 9.1.0.0300, 9.0.2.0100, or 8.0 Update 3k; ESXi to 9.1.0.0200, 9.0.2.0100, or 8.0 Update 3k; and upgrade Workstation and Fusion to 26H1. Broadcom has separate instructions for Cloud Foundation 5.x. Is there anything else I can make catastrophically worse today?
Reward: You've received a Demonic Helpdesk Escalation Token — it does nothing, but the ticket has been marked Resolved.
#VMware #CriticalVulnerability #AuthBypass #VMEscape #vCenter (2/2)
-
A Konnectivity vulnerability (CVE-2026-16242, CVSS 9.4) lets unauthenticated attackers proxy and modify control-plane traffic. See the fix and mitigation.
#Konnectivity #Kubernetes #CVE202616242 #CloudSecurity #ControlPlane #AuthBypass #InfoSec #PatchNow
-
A Konnectivity vulnerability (CVE-2026-16242, CVSS 9.4) lets unauthenticated attackers proxy and modify control-plane traffic. See the fix and mitigation.
#Konnectivity #Kubernetes #CVE202616242 #CloudSecurity #ControlPlane #AuthBypass #InfoSec #PatchNow
-
Check Point confirms CVE-2026-16232, a SmartConsole authentication bypass, is exploited in the wild. Apply the July 22 jumbo hotfix now.
#CheckPoint #CVE202616232 #SmartConsole #AuthBypass #ExploitedInTheWild #InfoSec
-
Check Point confirms CVE-2026-16232, a SmartConsole authentication bypass, is exploited in the wild. Apply the July 22 jumbo hotfix now.
#CheckPoint #CVE202616232 #SmartConsole #AuthBypass #ExploitedInTheWild #InfoSec
-
Check Point confirms CVE-2026-16232, a SmartConsole authentication bypass, is exploited in the wild. Apply the July 22 jumbo hotfix now.
#CheckPoint #CVE202616232 #SmartConsole #AuthBypass #ExploitedInTheWild #InfoSec
-
Two critical RabbitMQ flaws allow authentication bypass. One forges TLS client certs; the other tricks OAuth2 JWKS to accept any JWT.
-
Two critical RabbitMQ flaws allow authentication bypass. One forges TLS client certs; the other tricks OAuth2 JWKS to accept any JWT.
-
Three Apache IoTDB vulnerabilities include a critical path traversal (CVE-2026-24014) and an authentication bypass. Upgrade to 2.0.8 now.
#ApacheIoTDB #PathTraversal #AuthBypass #CVE #IoTSecurity #InfoSec
-
Three Apache IoTDB vulnerabilities include a critical path traversal (CVE-2026-24014) and an authentication bypass. Upgrade to 2.0.8 now.
#ApacheIoTDB #PathTraversal #AuthBypass #CVE #IoTSecurity #InfoSec
-
Three Apache IoTDB vulnerabilities include a critical path traversal (CVE-2026-24014) and an authentication bypass. Upgrade to 2.0.8 now.
#ApacheIoTDB #PathTraversal #AuthBypass #CVE #IoTSecurity #InfoSec
-
Five Apache Camel vulnerabilities enable server-side request forgery and a Keycloak authentication bypass. Upgrade to 4.21.0, 4.18.3, or 4.14.8.
#ApacheCamel #SSRF #AuthBypass #Deserialization #Keycloak #InfoSec
-
Five Apache Camel vulnerabilities enable server-side request forgery and a Keycloak authentication bypass. Upgrade to 4.21.0, 4.18.3, or 4.14.8.
#ApacheCamel #SSRF #AuthBypass #Deserialization #Keycloak #InfoSec
-
APISIX authentication bypass CVE-2026-39999 lets attackers forge JWTs via algorithm confusion. APISIX 3.16.0 is affected; upgrade to 3.16.1.
#APISIX #ApacheAPISIX #JWT #AuthBypass #InfoSec
https://securityonline.info/apisix-jwt-auth-bypass/?utm_source=mastodon&utm_medium=jetpack_social
-
APISIX authentication bypass CVE-2026-39999 lets attackers forge JWTs via algorithm confusion. APISIX 3.16.0 is affected; upgrade to 3.16.1.
#APISIX #ApacheAPISIX #JWT #AuthBypass #InfoSec
https://securityonline.info/apisix-jwt-auth-bypass/?utm_source=mastodon&utm_medium=jetpack_social
-
CISA Mandates Patching of Exploited Langflow Auth Bypass Flaw
The CISA has stepped in to mandate patching of a critical Langflow Auth Bypass flaw, CVE-2026-55255, that's being exploited by financially motivated threat actors to access sensitive user data. This vulnerability allows attackers to siphon off sensitive data and hijack computing resources with just a crafted request.
-
WSO2 patched seven flaws across API Manager and gateways, led by a CVSS 10 JWT auth bypass (CVE-2026-5430). Update WSO2 API Manager now.
-
WSO2 patched seven flaws across API Manager and gateways, led by a CVSS 10 JWT auth bypass (CVE-2026-5430). Update WSO2 API Manager now.
-
WSO2 patched seven flaws across API Manager and gateways, led by a CVSS 10 JWT auth bypass (CVE-2026-5430). Update WSO2 API Manager now.
-
Python fixed a python.org authentication bypass in its release metadata API. The flaw, dormant since 2014, let attackers alter download URLs.
#Python #CyberSecurity #AuthBypass #SupplyChain #InfoSec
https://securityonline.info/python-org-authentication-bypass -
Python fixed a python.org authentication bypass in its release metadata API. The flaw, dormant since 2014, let attackers alter download URLs.
#Python #CyberSecurity #AuthBypass #SupplyChain #InfoSec
https://securityonline.info/python-org-authentication-bypass -
Check Point Discloses Zero-Day Auth Bypass Bug Under Active Exploitation
A critical authentication flaw, CVE-2026-50751, has been discovered in Check Point's Remote Access VPN and Mobile Access solutions, allowing attackers to bypass user authentication and establish a remote access VPN connection without a valid password. This severe vulnerability, scoring 9.3 on the CVSS scale, affects deployments using the…
-
Threat Actors Exploit PraisonAI Auth Bypass Within Hours of Disclosure
Within hours of a security flaw being disclosed, threat actors were exploiting it - a stark reminder of the risks of a legacy Flask API server that ships with authentication disabled by default. This gaping hole allowed attackers to access sensitive endpoints and trigger workflows without a token, putting systems at risk.
#AuthBypass #Praisonai #Cve202644338 #FlaskApi #EmergingThreats
-
RE: https://mastodon.thenewoil.org/@thenewoil/116521854644786619
Those of you still using #MOVEit might want to take note of this new Auth Bypass 😕🤦♂️
-
RE: https://mastodon.thenewoil.org/@thenewoil/116521854644786619
Those of you still using #MOVEit might want to take note of this new Auth Bypass 😕🤦♂️
-
RE: https://mastodon.thenewoil.org/@thenewoil/116521854644786619
Those of you still using #MOVEit might want to take note of this new Auth Bypass 😕🤦♂️
-
RE: https://mastodon.thenewoil.org/@thenewoil/116521854644786619
Those of you still using #MOVEit might want to take note of this new Auth Bypass 😕🤦♂️
-
RE: https://mastodon.thenewoil.org/@thenewoil/116521854644786619
Those of you still using #MOVEit might want to take note of this new Auth Bypass 😕🤦♂️
-
Barguest Research Group found a critical no-interaction remote RCE in Android's Wireless Debugging ADB functionality.
https://barghest.asia/blog/cve-2026-0073-adb-tls-auth-bypass/
-
Barguest Research Group found a critical no-interaction remote RCE in Android's Wireless Debugging ADB functionality.
https://barghest.asia/blog/cve-2026-0073-adb-tls-auth-bypass/
-
Barguest Research Group found a critical no-interaction remote RCE in Android's Wireless Debugging ADB functionality.
https://barghest.asia/blog/cve-2026-0073-adb-tls-auth-bypass/
-
Barguest Research Group found a critical no-interaction remote RCE in Android's Wireless Debugging ADB functionality.
https://barghest.asia/blog/cve-2026-0073-adb-tls-auth-bypass/
-
Barguest Research Group found a critical no-interaction remote RCE in Android's Wireless Debugging ADB functionality.
https://barghest.asia/blog/cve-2026-0073-adb-tls-auth-bypass/
-
cPanel Rushes Emergency Update to Fix Auth Bypass Bug
A critical security vulnerability in cPanel software has been discovered, allowing unauthorized access to the control panel, prompting immediate action from providers like Namecheap to protect customers. cPanel has since rushed out an emergency update to fix the authentication bypass bug affecting all currently supported versions.
#Cpanel #AuthBypass #Vulnerability #EmergingThreats #WebHosting
-
Gruba afera. Ktoś od 3+ lat infekował na całym świecie firmy o wysokim znaczeniu strategicznym oraz infrastrukturę krytyczną.
Chodzi o podatność CVE-2026-20127 w Cisco SD-WAN (Software Defined WAN) – coś, co służy do bardziej sprytnego / tańszego budowania sieci WAN w dużych firmach. Wykorzystanie luki następowało z poziomu Internetu, nie wymagało uwierzytelnienia, a hackerzy uzyskiwali dostęp na wysoko uprawnionego użytkownika. Następnie robili downgrade oprogramowania i wykorzystywali kolejną, starą...
-
Gruba afera. Ktoś od 3+ lat infekował na całym świecie firmy o wysokim znaczeniu strategicznym oraz infrastrukturę krytyczną.
Chodzi o podatność CVE-2026-20127 w Cisco SD-WAN (Software Defined WAN) – coś, co służy do bardziej sprytnego / tańszego budowania sieci WAN w dużych firmach. Wykorzystanie luki następowało z poziomu Internetu, nie wymagało uwierzytelnienia, a hackerzy uzyskiwali dostęp na wysoko uprawnionego użytkownika. Następnie robili downgrade oprogramowania i wykorzystywali kolejną, starą...
-
Gruba afera. Ktoś od 3+ lat infekował na całym świecie firmy o wysokim znaczeniu strategicznym oraz infrastrukturę krytyczną.
Chodzi o podatność CVE-2026-20127 w Cisco SD-WAN (Software Defined WAN) – coś, co służy do bardziej sprytnego / tańszego budowania sieci WAN w dużych firmach. Wykorzystanie luki następowało z poziomu Internetu, nie wymagało uwierzytelnienia, a hackerzy uzyskiwali dostęp na wysoko uprawnionego użytkownika. Następnie robili downgrade oprogramowania i wykorzystywali kolejną, starą...
-
Gruba afera. Ktoś od 3+ lat infekował na całym świecie firmy o wysokim znaczeniu strategicznym oraz infrastrukturę krytyczną.
Chodzi o podatność CVE-2026-20127 w Cisco SD-WAN (Software Defined WAN) – coś, co służy do bardziej sprytnego / tańszego budowania sieci WAN w dużych firmach. Wykorzystanie luki następowało z poziomu Internetu, nie wymagało uwierzytelnienia, a hackerzy uzyskiwali dostęp na wysoko uprawnionego użytkownika. Następnie robili downgrade oprogramowania i wykorzystywali kolejną, starą...
-
Gruba afera. Ktoś od 3+ lat infekował na całym świecie firmy o wysokim znaczeniu strategicznym oraz infrastrukturę krytyczną.
Chodzi o podatność CVE-2026-20127 w Cisco SD-WAN (Software Defined WAN) – coś, co służy do bardziej sprytnego / tańszego budowania sieci WAN w dużych firmach. Wykorzystanie luki następowało z poziomu Internetu, nie wymagało uwierzytelnienia, a hackerzy uzyskiwali dostęp na wysoko uprawnionego użytkownika. Następnie robili downgrade oprogramowania i wykorzystywali kolejną, starą...
-
Petlibro – jak urządzenia do karmienia zwierząt udostępniały dane
W redakcji staramy się przyzwyczajać Czytelników do pewnych truizmów. W przypadku IoT, będzie to oczywiście kiepska implementacja funkcji bezpieczeństwa (o ile w ogóle producent postanowi przejmować się takimi bzdurami). W związku ze świątecznym rozprężeniem, przybliżamy absurdalnie trywialne do wykorzystania i całkiem niebezpieczne podatności w… automatycznym dozowniku do karmy dla zwierząt....
#Aktualności #Authbypass #Enum #Iot #Petlibro #Smart #Websec
https://sekurak.pl/petlibro-jak-urzadzenia-do-karmienia-zwierzat-udostepnialy-dane/