Aggregator
Please support the site operations by clicking ads.
Palo Alto Networks security advisory (AV26-905)
Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly
Threat actors are increasingly exploiting Active Directory replication mechanisms to steal password hashes without directly compromising a domain controller. This technique, known as DCSync, allows attackers with privileged domain credentials to impersonate a legitimate domain controller and request sensitive directory replication data. Unlike noisy attacks that use malware on servers or attempt to extract credentials […]
The post Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Один набор zero-day за шесть дней разошёлся по четырём шпионским группам
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
- CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
NIST-Developed Quantum Sensors Improve Nuclear Monitoring
CVE-2026-84828 | Red Hat Enterprise Linux PCS information disclosure
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
CVE-2026-88859 | Red Hat Enterprise Linux Trusted JavaScript cross site scripting
Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
Threat actors are exploiting anticipation around Grand Theft Auto VI by pushing fraudulent “leaked” game downloads that install a layered malware bundle that steals browser credentials, Discord tokens, gaming-session data, and cryptocurrency-related information. A Chaos ransomware variant used as a wiper, and an unexpected Yandex Browser installer. The campaign demonstrates how cybercriminals are turning one […]
The post Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
微软九月例行更新修复近千个 Bug
对话极壳创始人孙宽:年出货 3 万台后,外骨骼「全班第一」的成长和焦虑
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds
A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O archive parser could allow a malicious static library to crash Xcode build processes or expose process memory through build logs. This flaw affects the parser used by Apple’s newer linker, ld-prime, as well as related developer tools, including libtool, ranlib, and potentially dyld_info. Apple Xcode Integer […]
The post Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root
Palo Alto Networks has announced a high-severity buffer overflow vulnerability in PAN-OS that may allow unauthenticated, network-based attackers to execute arbitrary code with root privileges on affected PA-Series hardware firewalls. This vulnerability is tracked as CVE-2026-0310 and stems from PAN-OS XML processing. It impacts both the firewall management web interfaces and the dataplane interfaces. The […]
The post Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
Hackers Pose as Domain Controllers to Steal Active Directory Password Hashes
Threat actors are increasingly abusing Active Directory replication to impersonate domain controllers and steal password hashes from enterprise networks. This technique, known as a DCSync attack, can let attackers obtain credential data for privileged accounts without deploying malware directly on a legitimate domain controller. Active Directory domain controllers manage authentication across Windows enterprise environments. They […]
The post Hackers Pose as Domain Controllers to Steal Active Directory Password Hashes appeared first on Cyber Security News.
В космосе нашли новый класс источников, который десятилетиями выпадал из обзоров
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a network. Two FMC vulnerabilities under active attack “Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software,” the company’s researchers confirmed on Wednesday. These are the above mentioned CVE-2026-20079 and CVE-2026-20316, which Cisco flagged … More →
The post Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) appeared first on Help Net Security.