#authentication


Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

Sep 30, 2026 // 19:50

Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from […]

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Sep 30, 2026 // 18:30

Attackers are exploiting a critical flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an […]

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

Sep 7, 2026 // 11:18

Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. “The payloads are protected with javascript-obfuscator, […]

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

Sep 6, 2026 // 12:42

Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, […]

39 New Methods That Compromise Passkey Authentication

Sep 4, 2026 // 19:17

Passkeys were introduced with a strong security proposition. Replace passwords with public key cryptography, bind the credential to the legitimate service, keep the private key […]

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Aug 28, 2026 // 20:20

Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released […]

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Aug 20, 2026 // 16:37

Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the […]

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Aug 13, 2026 // 10:35

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is […]

Kali365 Weaponizes Microsoft Authentication Against US Companies: New Enterprise Risk

Aug 5, 2026 // 14:55

Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims […]

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Jul 29, 2026 // 14:20

Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server […]

1 2 3 Next