#bypass


CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

Oct 1, 2026 // 13:40

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited […]

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

Sep 30, 2026 // 18:30

Attackers are exploiting a critical flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an […]

ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

Sep 26, 2026 // 22:17

The ShinyHunters extortion gang is using a URL-encoding trick to bypass web application firewall rules that mitigate the Oracle PeopleSoft CVE-2026-35273 flaw, allowing the threat […]

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Sep 26, 2026 // 14:47

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The […]

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

Sep 16, 2026 // 11:41

A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as […]

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Sep 9, 2026 // 17:29

Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create “stolen keys” that grant illicit access to tools from model providers […]

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

Sep 7, 2026 // 11:18

Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. “The payloads are protected with javascript-obfuscator, […]

Critical Citrix NetScaler auth bypass now leveraged in attacks

Sep 4, 2026 // 19:17

Attackers have begun targeting a critical-severity Citrix NetScaler flaw in the wild, according to vulnerability intelligence company Previdian. Tracked as CVE-2026-19490, this security flaw can […]

Hackers target WordPress sites in miniOrange auth bypass attacks

Aug 25, 2026 // 01:37

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used […]

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

Aug 25, 2026 // 01:37

An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that […]

1 2 3 … 9 Next